The SuperImager® Plus 12” NVMe SATA Rugged Forensic unit is a Portable forensic imager with the ability to serve as a complete Field Computer Forensic Investigative platform, allowing the user to capture data in the field from multiple sources to multiple targets simultaneously and extremely fast. It also enables the user to perform a full Forensic analysis using a third-party application like Encase. Additionally, the unit can also capture data from multiple cellphones and run cellphone analyses. The unit is durably built and easy to carry, comprising of a full-blown Desktop CPU, enabling the unit to have a high performance (this is different from laptops and other mobile solutions). The unit is built with 2 NVMe U.2, 2 SATA, and 4 USB3.1 ports that supports NVMe, SATA, and USB Flash drives. The unit’s fast Thunderbolt 3.0 port (40Gigabit/s) enables the user to capture data directly from Macbooks laptops. With the use of the optional TB3.0 Expansion Box it also enable the user to capture data from other interfaces such SAS/SCSI/FC. The user also can also use the TB port to connect to 10Gigabit/s networks and do a fast upload of the captured images to a network.
Some speed test:
SATA to SATA Linux-DD copy max speed 32.7GB/min.
NVMe to NVMe Linux DD copy max speed 98.5GB/min. (see pictures)
The SuperImager’s main application (the unit’s software) supports many imaging operations. Some of the tasks that the unit can be used for includes:
1) Multiple Parallel Forensic Capture: Mirror (bit by bit), Linux-DD, E01/Ex01 (with full compression) formats, Mixed-Format DD/E01, and Selective Capture (files and folders with the use of file extension filters). Select a single partition to capture.
2) Erase data from Evidence drive - using DoD (ECE, E), Security Erase, NVMe, and Sanitize erase protocols.
3) View the data directly on Ubuntu Desktop screen.
4) Encrypt the data while capturing (AES256).
5) HASH the data while capturing – run all the three, SHA-1, SHA-2, and MD5 HASH engines, at the same time.
6) Run a quick Keyword Search on the Suspect drive prior to capture.
7) Run Multiple Cellphone/Tablets data Extraction and Analysis.
8) Run Forensic Triage application.
9) Run a full Forensic Analysis application like Encase/Nuix/FTK.
10) Run Virtual Drive Emulator.
11) Run Remote Capture from unopened laptops (Intel Based CPU).
Additional operations that are available include erase verification on a drive that was previously erased, Full or Quick Format, HASH a drive, drive diagnostics, and scripting. The application supports forensic imaging of multiple drives, in multiple sessions, in simultaneous forensic imaging runs. The Optional TB expansion box enables the user to connect to a 10Gigabit/s network, or to an External HDMI monitor, or to plug additional optional storage controllers (SAS, SCSI, 1394, and FC) to support erase from more storage devices.