Forensic acquisition isn’t the known quantity that it was. With new storage devices like SSD’s and NVMe, new filesystems like APFS, and computers increasingly become locked down, the old techniques and assumptions will only get you so far. This session will examine where the old techniques fail or are a poor choice for today’s evidence sources; teach forensically sound techniques for acquiring modern computer, mobile, and cloud evidence; and identify new techniques for accelerating forensic workflow.