The SUPERIMAGER PLUS 8″ T3 FORENSIC FIELD UNIT – LINUX FORENSIC IMAGER WITH I7 AND THUNDERBOLT PORT is a mobile, compact, easy to carry, versatile, and extremely fast Forensic Imaging unit that can serve as a complete Field Computer Forensic Investigation platform. The unit is running under Linux Ubuntu OS with a dual boot to Windows 8.1. The unit has a built-in extremely fast Thunderbolt 3.0 port (40 Gigabit/s) and it supplied with Thunderbolt 3.0 PCIE 3.0 Expansion Box that allows the user to plug any storage controller (SCSI, 1394, NVMe..) and capture data from almost any source.
The unit can be used to perform:
1) Multiple parallel simultaneous Forensic Capture using bit by bit, DD, E01/Ex01(with full compression) formats
2) Run Quick Copy (Targeted Imaging) of files and folders
3) Erase data from Evidence drive using DoD (ECE, E), or Security Erase, or Enhanced Security Erase protocols
4) View the CAPTURED data directly on Ubuntu Desktop Screen or Windows
5) Encrypt the data while capturing (AES256)
6) HASH the data while capturing (SHA-1, SHA-2, MD5)
7) Run Cellphone/Tablets data Extraction and Analysis
8) Prepare Forensic Triage keys and view the captured targeted data
9) Run a full Forensic Analysis application like Encase/Nuix/FTK
10) Run a Virtual Drive Emulator (Option is enabled on this unit)
11) Use the Remote Capture application to capture data from un-opened Laptops with Intel based CPU, Tablets and PC (Supplied with this unit)
12) Use the Thunderbolt port to capture data from Mac via Thunderbolt 2/3 port or 1394 port
Case Study: Some example of the unit’s performances:
Complete HASH verification operation with SHA-1 enabled on SSD @ 31GB/min, on WD 1TB Blue @10GB/min.
Complete Forensic Imaging 1:2 with SHA-1 enabled on 3 SanDisk Extreme II 120GB SSD @ 29GB/Min.
Complete Forensic E01 Imaging from 2TB WD2003FZEX with compression level 9, SHA-1 and MD5 are enabled, HASH the Evidence and compare is enabled @ 11GB/min
The unit built-in: 8” Touchscreen color LCD display, 4 native SAS/SATA ports in drive slots, 8 native USB3.0 ports, e-SATA port, 2 Generic USB2.0 ports, 1Gigabit/s Ethernet ports, eSATA port, Display port, Thunderbolt 3.0 port and audio ports. The unit is supplied with slim and compact Thunderbolt PCIE 3.0 Expansion Box where the user can plug many different kinds of storage devices and capture data from (SCSI, 1394, NVMe, FC, and more). The Expansion Box has in addition USB 3.1 port that supports capture of USB3.1 storage devices.
The SuperImager Plus 8” T3 Rugged Forensic Field Unit as Forensic Imaging Tool: In one read pass from the “Suspect” Hard Disk Drive, the SuperImager Plus application can run the following operations simultaneously: Forensic Imaging with E01 format and with full compression, Encryption with AES256, simultaneously calculate 3 HASH Verification and Authentication values (MD5, SHA1, SHA2), and saving the captured Forensic Images to 2 “Evidence” drives, to a local network, and to external compact USB3.0/e-SATA TB RAID encrypted storage. The basic Forensic Imaging mode can be 1:1, 1:2, 1:3, 2:2 for SAS/SATA and 2:6 for USB3.0 storage devices
The Unit as Complete Forensic Platform:
In addition, the unit can serve as a platform for a Forensic investigator to run a complete investigation and to perform:
1) Cellphones and Tablets Data Extraction and Analysis
2) Forensic Triage Data Collection
3) A complete Computer Forensic investigation Analysis with applications such as Nuix, FTK, EnCase
4) Virtual Drive Emulator: Mount a Suspect drive or it’s DD/E01 images, simulate in its native Windows Environment, and extract importan
The Unit as Data Eraser:
Supports erase protocols that are NIST 800-880 compliance:
1) DoD 5220-22M (ECE, E),
2) Security Erase, and Enhanced Security
3) Erase User Mode
Dual Boot: The unit is running Ubuntu OS for forensic imaging and virtual drive emulator purpose. The unit is supplied with dual boot to Windows 8.1 when user intend to install and use third-party applications to perform data analysis, cellphone data extraction and more.
Network Multiple Forensic Images Loader- Besides the ability of the application to upload forensic images (DD, E01) to the network via the 1Gigabit/s network port, there is also a unique feature/solution that can solve the streaming bottleneck by using a single port. With this solution, the user can upload many Forensic images directly to a local network using 7 equivalent 1Gigabit/s network streams.