MediaClone SuperImager Plus 8" T3 Forensic Field Unit

More Views

MediaClone SuperImager Plus 8" T3 Forensic Field Unit

Availability: In stock

SuperImager Plus 8" T3 Forensic Field unit with 4 SAS/SATA3 ports, 8 USB3.0 ports, and Thunderbolt 3.0 port: The unit includes Thunderbolt 3.0 to PCIe 3.0 Expansion Box and with M.2 NVMe controller that enables capturing NVMe SSD at 65GB/min. It is a top performance Field Computer Forensic Imaging tool and Complete Digital Forensic Investigation platform. The user can run multiple parallel simultaneous forensic imaging from many devices, with 3 HASH values, and with encryption on the fly. As a platform, the unit can be used to perform:





The SuperImager® Plus 8” T3 Forensic Field Unit is a mobile, compact, easy to carry, versatile, and extremely fast Forensic Imaging unit that can serve as a complete Field Computer Forensic Investigation platform. The unit is running under Linux Ubuntu OS with a dual boot to Windows 8.1. The unit has a built-in extremely fast Thunderbolt 3.0 port (40 Gigabit/s) and it supplied with Thunderbolt 3.0 PCIE 3.0 Expansion Box that allows the user to plug any storage controller (SCSI, 1394, NVMe..) and capture data from almost any source. 
The unit can be used to perform: 
  1. Multiple parallel simultaneous Forensic Capture using bit by bit, DD, E01/Ex01(with full compression) formats
  2. Run Quick Copy (Targeted Imaging) of files and folders
  3. Erase data from Evidence drive using DoD (ECE, E), or Security Erase, or Enhanced Security Erase protocols
  4. View the CAPTURED data directly on Ubuntu Desktop Screen or Windows
  5. Encrypt the data while capturing (AES256)
  6. HASH the data while capturing (SHA-1, SHA-2, MD5)
  7. Run Cellphone/Tablets data Extraction and Analysis
  8. Prepare Forensic Triage keys and view the captured targeted data
  9. Run a full Forensic Analysis application like Encase/Nuix/FTK
  10. Run a Virtual Drive Emulator (Option is enabled on this unit)
  11. Use the Remote Capture application to capture data from un-opened Laptops with Intel based CPU, Tablets and PC (Supplied with this unit)
  12. Use the Thunderbolt port to capture data from Mac via Thunderbolt 2/3 port or 1394 port
Case Study: Some example of the unit’s performances: 
Complete HASH verification operation with SHA-1 enabled on SSD @ 31GB/min, on WD 1TB Blue @10GB/min.
Complete Forensic Imaging 1:2 with SHA-1 enabled on 3 SanDisk Extreme II 120GB SSD @ 29GB/Min.
Complete Forensic E01 Imaging from 2TB WD2003FZEX with compression level 9, SHA-1 and MD5 are enabled, HASH the Evidence and compare is enabled @ 11GB/min 

The unit built-in: 8” Touchscreen color LCD display, 4 native SAS/SATA ports in drive slots, 8 native USB3.0 ports, e-SATA port, 2 Generic USB2.0 ports, 1Gigabit/s Ethernet ports, eSATA port, Display port, Thunderbolt 3.0 port and audio ports. The unit is supplied with slim and compact Thunderbolt PCIE 3.0 Expansion Box where the user can plug many different kinds of storage devices and capture data from (SCSI, 1394, NVMe, FC, and more). The Expansion Box has in addition USB 3.1 port that supports capture of USB3.1 storage devices.

The SuperImager Plus 8” T3 Rugged Forensic Field Unit as Forensic Imaging Tool: In one read pass from the "Suspect" Hard Disk Drive, the SuperImager Plus application can run the following operations simultaneously: Forensic Imaging with E01 format and with full compression, Encryption with AES256, simultaneously calculate 3 HASH Verification and Authentication values (MD5, SHA1, SHA2), and saving the captured Forensic Images to 2 “Evidence” drives, to a local network, and to external compact USB3.0/e-SATA TB RAID encrypted storage. The basic Forensic Imaging mode can be 1:1, 1:2, 1:3, 2:2 for SAS/SATA and 2:6 for USB3.0 storage devices 

The Unit as Complete Forensic Platform: 
In addition, the unit can serve as a platform for a Forensic investigator to run a complete investigation and to perform:
1) Cellphones and Tablets Data Extraction and Analysis 
2) Forensic Triage Data Collection
3) A complete Computer Forensic investigation Analysis with applications such as Nuix, FTK, EnCase 
4) Virtual Drive Emulator: Mount a Suspect drive or it's DD/E01 images, simulate in its native Windows Environment, and extract important files 

The Unit as Data Eraser: 
Supports erase protocols that are NIST 800-880 compliance: 
  1. DoD 5220-22M (ECE, E),
  2. Security Erase, and Enhanced Security
  3. Erase User Mode
Dual Boot: The unit is running Ubuntu OS for forensic imaging and virtual drive emulator purpose. The unit is supplied with dual boot to Windows 8.1 when user intend to install and use third-party applications to perform data analysis, cellphone data extraction and more 

Network Multiple Forensic Images Loader
- Besides the ability of the application to upload forensic images (DD, E01) to the network via the 1Gigabit/s network port, there is also a unique feature/solution that can solve the streaming bottleneck by using a single port. With this solution, the user can upload many Forensic images directly to a local network using 7 equivalent 1Gigabit/s network streams
    SuperImager Plus 8" T3 unit with i7 CPU, 16GB Memory, and S/W Version 1.6.73
    Hash Verification/ Authentication Only (Reading Speed) Avg Speed GB/Min
    Hash single drive, in a single session (Samsung 850 EVO SSD)
    SHA-1 30.6
    MD5 30.6
    SHA-1+ MD5 30.6
    Hash 2 drives in 2 separate sessions (2 Samsung 850 EVO SSD)
    SHA-1 + MD5 drive 1 26.2
    SHA-1 + MD5 drive 2 26.6
    Hash single drive, in a single session (Intel 750 NVMe 400GB)
    SHA-1 64.0
    SHA-1 + MD5 64.0
    Wipe Drives (Write Speed) (Samsung 850EVO SSD)
    Security Erase Mode 30.0
    Single Pass - User Erase Mode 28.8
    Forensic Imaging
    100% bit by bit Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD
    with SHA-1+ MD5 Hash on 28.5
    DD Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
    with SHA-1 + MD5 Hash on 29.1
    DD Imaging SanDisk Extreme II SSD to Samsung 850 EVO SSD 2 GB file Chunks and NTFS)
    with SHA-1 + MD5 hash on 28.5
    E01 Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
    with SHA-1 + MD5 Hash on 24.2
      Main Hardware Features:
          • Case: Mobile, easy to carry
          • CPU: i7 6th Generation
          • Display: 8" (800x600) LED backlight Touchscreen color LCD display
                    Hardware: Very high quality high performing components
                        Hardware upgrade: The unit can be upgraded at time of purchasing for additional cost, to a large internal SSD
                            OS: Linux Ubuntu 64 Bit
                                Writes Block: Using “device driver” blocking mechanism based on Maxim Suhanov Mechanism (https://github.com/msuhanov/Linux-write-blocker)
                                    Application Updates: Application can be easily updated via USB thumb drives and special update screen
                                      Application Settings:
                                          • HPA/DCO Automatic Supports: The application has the ability to automatically open HPA and DCO areas, and resize the "Suspect" hard drive to its full native capacity, in order to capture any “hidden data” (HPA/DCO are special areas on the drive that support this feature)
                                          • Bad Sectors Handling: The user can select to skip bad sectors, a block of bad sectors, or to abort the operation when it encounters bad sectors on the "Suspect" drive
                                                    • Forensic Images - Destination: The user can save Forensic Images to a local network shared folder for easy access and analysis, or save images to external USB3.0 RAID (encryption is optional) storage in a very good speed
                                                    • Captured Storage Protocols and Interfaces: SAS, SATA, e-SATA enclosures, IDE, USB2.0, USB3.0, MMC, M.2 NGFF(SATA or PCIE base), SCSI*, FC*, 1394*, NVMe*, and USB3.1* t*
                                                    • Form Factors: Capture data from various form factor devices: 3.5", 2.5", ZIF, 1.8", Micro-SATA, Mini-SATA, PCIE*, Mini PCIE*, M.2 NGFF
                                                    • Cross Copy from Ports and Interfaces: The user can choose to capture from one type of port with storage protocol and with storage interface and save the forensic Images into a different port, with different storage protocol or different storage interface. The cross copy of data can be done between SAS/SATA/IDE/USB/SCSI/1394 interfaces
                                                                  Application Features:
                                                                      • GUI: The application is built with large icons and is very simple and easy-to-navigate. In a few clicks, the user can set the operation, and it will be quickly up and running
                                                                      • Speed: Extremely fast

                                                                      • Tested with HASH verification operation with SHA-1 enabled the recorded top speed was 30GB/min with Solid State Drive, and 10GB/min with 1TB WD Blue SATA-3 Hard Disk Drive
                                                                      • Tested with Forensic Imaging operation of 1 to 2 with SHA-1 enabled the recorded sustained top speed was 29GB/min with 3 SSD of SanDisk 120GB Extreme II
                                                                              Extreme Speeds when performing Forensic capture with E01/Ex01 formats and with full Compression:
                                                                                  • The new Linux-based SuperImager Plus application utilizes and optimizes multiple CPU cores to achieve one of the most efficient operations while performing at incredibly high speeds with E01/Ex01 formats with full compression. The application allows users to manually select and adjust the number of hyperthreads and the level of compression used during each session
                                                                                      • Forensic data capture with Encase E01/Ex01 formats with full compression is widely used operation in the forensic industry, and generally requires a trade-off between speed, space, and time of decompressing by the EnCase application
                                                                                          • Comparative tests show a 20% increase in speed when using the SuperImager Plus Linux-based application over the SuperImager Windows-based application. Tests were performed with the same hardware and the same hard disk drives (filled with 43% of random data), and the same level 1 of compression. The Linux-based application was set to use 16 compression threads
                                                                                              HASH Authentication: Simultaneously calculates on-the-fly up to 3 HASH Authentication values MD5/SHA-1/SHA-2
                                                                                                  Encryption: On-the-fly AES256 encryption of the "Suspect" drive, saving the encrypted data on "Evidence" drive in 100%, DD, E01/Ex01 formats.
                                                                                                      Decryption: The user can perform decryption on a drive, previously encrypted by any of the SuperImager units. Alternatively, the user can use a standalone MediaClone Linux decryption utility application to perform decryption on that drive using any PC. The supplied standalone decryption utility application can be burned onto a USB flash drive that later can be used to boot the PC to the Linux utility, where the encrypted drive and a blank destination drive were attached to the PC. (The user needs to supply to the utility application the saved encryption key)
                                                                                                          Forensic Images can be saved in those Formats: 100% Bit by Bit, Linux DD Format, Encase E01/Ex01 formats include options for optimized compression
                                                                                                              Evidence Drive Formats: exFAT/FAT/NTFS/HFS+/EXT4
                                                                                                                  Log Files: Audit trail in PDF formats with ability to customize the reports and adding company Logo
                                                                                                                      Drive Spanning: Supports spanning the captured data onto many “Evidence” drives, when the Evidence drives are not large enough (Also supports restore from spanned multiple drives)
                                                                                                                        Main application Features:
                                                                                                                          • Forensic Imaging Mode
                                                                                                                          • Forensic Selective Capture Mode
                                                                                                                          • Forensic Restore back data to original
                                                                                                                          • Erase data from drives and Quick Format
                                                                                                                          • HASH calculation authentication and verification
                                                                                                                          • Virtual Drive Emulator
                                                                                                                                            Main Forensic Imaging Mode Features:
                                                                                                                                              • Forensic Imaging Modes: Mirror image(100% or any % of the drive), DD, E01/Ex01 – with optional compression
                                                                                                                                              • HASH while capture: MD5, SHA-1, SHA-2 (all 3 can be selected simultaneously)
                                                                                                                                              • Erase Reminder of the drive
                                                                                                                                              • Encryption/Decryption
                                                                                                                                                            Parallel operations:
                                                                                                                                                                • Parallel Forensic Imaging - Multiple Session Operations: The user can run multiple efficient parallel operations, since many ports are available. The user can mix different type of operations, and each operation is set as a new independent session. An example of operations: erase data from a drive on one port, hash verify on second port, while forensic imaging 1 to 1 on the remaining ports. The number of sessions also depends on the CPU: i5 -4 sessions, i7- 8 sessions
                                                                                                                                                                • Basic Parallel Forensic Imaging: The supported modes are:
                                                                                                                                                                  Native SAS/SATA: 1 to 1, 1 to 2, 1 to 3, 2 to 2, 2 to 3. The 2 to 3 imaging mode uses the e-SATA port with the need to supply external power to the e-SATA plugged device and the 1:3 imaging mode need to be configured at time of purchasing of the main unit.
                                                                                                                                                                    USB3.0: 1 to 1, 1 to 2, 2 to 2 and up to 2:6
                                                                                                                                                                        More Ports for Forensic Imaging:
                                                                                                                                                                          With the use of USB3.0 to SATA fast adapters and with the combination of e-SATA port, the unit can support up to 2 to 7 and up to 4 to 7 Forensic Imaging of SATA drives.
                                                                                                                                                                              Parallel operation – Linux Elaborated:
                                                                                                                                                                                  Detection Application Screen: All hard disk drives and storage devices that are connected to the units will be scanned and displayed in one application screen called “the detection screen”. The user can tap on each drive to get its detailed info, as well as selecting it for the desired operation they are planning to use
                                                                                                                                                                                      Parallel Forensic Imaging: It depends on the number and the kind of ports that each model has. The application is very flexible in running multiple sources to multiple destinations, all in simultaneous operations. The user has the flexibility to change a role of a port from been Evidence port to be Suspect port, and is not limited by the pre assigned "Suspect" ports. The session control application screen provides the user with a very comprehensive information and control over the running sessions, including all the setting of the session, and ability to abort the session
                                                                                                                                                                                            Network Capture: Data from network folder can be captured and saved into “Evidence” drives via iSCSI storage protocols (SMB, NFS, CIFS)
                                                                                                                                                                                                Saves Forensic Images to Network: Upload multiple Forensic images to a local network (DD, E01), simultaneously by using up to 8 parallel 1Gigabit/s network streams
                                                                                                                                                                                                    Remote Capture - Capture Data from the Internal Drives of a Computer: Using USB or 1Gigabit Ethernet ports of the laptop/computer, enables capture without the needs to remove the drive from the Laptop/computer (Speed is restricted to performance of the Laptop/PC CPU and the 1Gigabit/s connection)
                                                                                                                                                                                                      Erase and Quick Format Operation:
                                                                                                                                                                                                          Drive Erase Protocols: DoD 5220-22M, Security Erase, Enhanced Security Erase, or user can define the final data filling pattern and the number of iterations (Security Erase, Enhanced Security Erase, and DoD erase protocols are NIST 800-88 compliance)
                                                                                                                                                                                                              Quick Format: NTFS, FAT, HFS+, EXT4, and exFAT
                                                                                                                                                                                                                  Logs and Erase Certification: The application generates extensive erase log files and erase certification (option to save to NIST 800-88 format) that are easy to export to USB thumb drive
                                                                                                                                                                                                                    Unit as a Platform:
                                                                                                                                                                                                                        File Preview: Browse and preview captured data on the Internal Display
                                                                                                                                                                                                                            High Performances: As a platform, a forensic investigator can, in addition to imaging and capturing data, load and run third-party applications to analyze the captured data:
                                                                                                                                                                                                                              • Cellphone/Tablet data extraction and analysis: Cellebrite, Oxygen, BlackBag, MPE+, Paraben applications
                                                                                                                                                                                                                              • Triage data collection: Nuix/Encase portable applications
                                                                                                                                                                                                                              • Full computer forensic analysis: Encase, Nuix, and FTK applications
                                                                                                                                                                                                                                        The units have very firm hardware that enables those said applications to run with excellent performance.
                                                                                                                                                                                                                                          Expansion capabilities and the main hardware options:
                                                                                                                                                                                                                                              Express Card Port Option: PCIE Express card controller that enables the user to plug and capture the data from PCIE memory cards like Sony SXS
                                                                                                                                                                                                                                                  USB3.0 to SATA Adapters and Kits Option: Today USB3.0 technology is extremely fast and can run read data from SSD drives up to 20GB/min.
                                                                                                                                                                                                                                                    With the use of USB3.0 to SATA 4 channel Kit, the user can convert 4 USB3.0 ports to 4 SATA ports on any of MediaClone units. The optional Kit is supplied with one external PS, and it includes all the cabling to power and connects the 4 USB3.0 to SATA adapters.The tested performance when running 4 adapters in parallel was measured at a very high speed, with a very little speed degradation
                                                                                                                                                                                                                                                        SCSI KIT Option: This option includes SCSI PCIE X1 single port controller, 2 channel SCSI LVDS cable (68 pins connectors), SCSI terminator, and VHDCI to 68 pins SCSI adapter
                                                                                                                                                                                                                                                            1394 Option: This option is supplied with 1394A/B PCIE 1x controller
                                                                                                                                                                                                                                                                NVMe KIT: This option is supplied with PCIE NVME controller and with NVMe (M.2 and 2.5") adapters that enable the user to capture data from any NVMe SSD

                                                                                                                                                                                                                                                                    Warranty: One-year warranty for the main unit. (It does not include cables and accessories)

                                                                                                                                                                                                                                                                    Built-in the USA: The units are built and tested in the USA