The SuperImager® Plus Desktop XL Forensic Lab Unit - is a heavy-duty, industrial, and extremely fast Forensic Imaging unit that captures data from multiple sources to multiple target drives. The unit is running under Linux Ubuntu OS. It easy to use with many built-in features that help the user to automated imaging or uploading. The advantage of this unit that it has the ability to have a wide range of expansion. A fully loaded unit with optional hardware can be configured with additional 4 Fiber Channel ports, 1 SCSI port, 8 SAS Expander ports
The user can use the unit to:
- Forensic Imaging with E01/Ex01 format and with full compression, DD, Mirror, Mixed_format DD/E01, Selective Imaging of files and folders using file extension filters (run E01 4 multiple parallel sessions using 8 SAS/SATA drives and with 16 E01 compression engines)
- Perform Forensic Imaging from 7 Suspect drives to one large Evidence drive, in append mode
- View the CAPTURED data directly on Ubuntu Desktop Screen
- Upload 8 Forensic images to a network (SMB, CIFS, NFS)
- Erase data from many drives simultaneously using DoD(ECE, E), Security Erase, Enhanced Security, Sanitize erase modes
- View the captured data directly on Ubuntu Desktop
- Run Virtual Drive Emulator to boot, mount and view the Suspect drive in its native environment (mount the raw drive or DD/E01 drive image), and extract important files into Evidence drive or any external storage
- Perform Encryption and Decryption of drives that contain sensitive information
- Use third-party applications to run Multiple Cellphone/Tablets Data Extraction and Analysis
- Use the unit as a Full Forensic Analysis station running Encase/Nuix/FTK applications
- Easily reconfigure the unit's ports, where each of the target port can be configured as source or target for running 4:4 sessions, ot to run upload 8 to network
- Convert the unit's 8 USB3.0 ports to SATA ports and run more parallel sessions (with the use of some USB3.0 to SATA adapters)
- Expand with optional PCIE 3.0 expansion slots to support NVMe, SCSI, 1394, USB3.1, FC storage devices.
- Optional: Configure the unit with 40Gigabit/s dual ports Ethernet controller for a faster forensic Images Network loader.
- Use the two 1Gigabit/s native network ports to increase upload speed of DD/E01 images
The unit is designed to help expedite the forensic imaging process, especially in facilities where there is a large backlog in imaging hard disk drives by performing many parallel forensic imaging in a true optimized multiple session's application.
The Unit Built-in:
8 native SAS/SATA ports (SAS 3.0) in an 8 open tray drive caddie, 10 native USB3.1 ports, e-SATA port, 1Gigabit/s Ethernet port, HDMI port.
The Unit as a Forensic Imaging Tool:
In one read pass from the "Suspect" drive, the application can run the following operations simultaneously: Forensic Imaging with E01 format and with full compression, Encryption with AES 256, simultaneously calculate 3 HASH Verification and Authentication values (MD5, SHA1, SHA2), and Saving the captured Forensic Images to many destinations such us 1) Two “Evidence” drives 2) Network 3) External compact USB3.0/e-SATA TB RAID encrypted storage 4) NAS. In addition, the user can run (optional) Virtual Drive Emulator to browse the Suspect drive under Windows, transfer and copy important files from the Suspect drive to any destination drives
The Unit as Complete Forensic Platform:
In addition, the unit can serve as a platform for a forensic investigator to run a complete investigation and to perform: Cellphones and Tablets data Extraction and Analysis A complete Computer Forensic investigation Analysis with applications such as Nuix, FTK, EnCase, ProDiscovery, A Triage application on the captured drive
The Unit as Data Eraser:
Supports DoD and Security Erase, Enhanced Security erase protocols that are NIST 800-88 compliance.
Dual Boot: The unit is configured as a dual boot unit (Linux and Windows 10 PRO). The Linux OS to be used for Forensic Imaging purpose where the performance of the Forensic Imaging under Linux is faster, more efficient, and more secure operation. The Windows 10 Pro OS to be used for running third-party applications to perform data analysis, Cellphone data extraction capture, Triage data extraction, and other tasks
Multiple Forensic Images Network Loader - Unique feature solves the 1 Gigabit/s Ethernet Port Upload Bottleneck. The user can upload up to 8 Forensic images directly to a network using 8 equivalent 1 Gigabit/s Ethernet network streams
SuperImager Plus unit with i7 CPU, 16GB Memory, and S/W Version 1.4.52 |
|
HASH Verification/ Authentication Only (Reading Speed) |
Avg Speed GB/Min |
HASH single drive, in a single session (Samsung 850 EVO SSD) |
|
SHA-1 |
30.6 |
MD5 |
30.6 |
SHA-1+ MD5 |
30.6 |
HASH 2 drives in 2 separate sessions (2 Samsung 850 EVO SSD) |
|
SHA-1 + MD5 drive 1 |
26.2 |
SHA-1 + MD5 drive 2 |
26.6 |
HASH single drive, in a single session (SanDisk Extreme II 128GB) |
|
SHA-1 |
30.8 |
SHA-1 + MD5 |
30.8 |
Wipe Drives (Write Speed) (Samsung 850EVO SSD) |
|
Security Erase Mode |
577.2 |
Single Pass - User Erase Mode |
28.8 |
Forensic Imaging |
|
100% bit by bit Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD |
|
with SHA-1+ MD5 HASH on |
28.5 |
DD Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS) |
|
with SHA-1 + MD5 HASH on |
29.1 |
DD Imaging SanDisk Extreme II SSD to Samsung 850 EVO SSD 2 GB file Chunks and NTFS) |
|
with SHA-1 + MD5 HASH on |
28.5 |
E01 Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS) |
|
with SHA-1 + MD5 HASH on |
24.2 |