The SuperImager Plus Desktop XL Forensic Lab Unit is a heavy duty, industrial, and extremely fast Forensic Imaging unit that captures data from multiple sources to multiple target drives. The unit is running under Linux Ubuntu OS. It easy to use with many built-in features that help the user to automated imaging or uploading. The advantage of this unit that it has ability to have a wide range of expansion. A fully loaded unit with optional hardware can be configured with additional 4 Fiber Channel ports, 1 SCSI port, 8 SAS Expander ports.
The unit hardware: i7 – 7th generation CPU, 32GB Memory, 250GB SSD internal storage, SAS 3.0, with 8 SAS/SATA ports, 6 USB3.0 ports, 2 Thunderbolt 3.0 ports, Ubuntu 18.04LTS OS with a dual boot of Linux and Win8,1 Prof. (The top speed reading from SATA SSD is 31GB/min).
The advantage of the unit: It has a wide expansion capability with additional expansion option that can support most of the usable interfaces. Optional fully loaded configuration: 1 NVMe ports, 2 Fiber Channel ports, 1 SCSI port, 8 SAS Expander ports for external SAS storage array.
The application is using Ubuntu open OS: Multi-tasks, truly simultaneous multiple forensic imaging from one or many source ports to one or many target ports with different interfaces and options. Like imaging 1:7, 4:4, 8 to a network of SAS/SATA drives using a mirror image, DD, E01 compressed, mix mode and more. Also, the user can select to run in one imaging session 3 HASH engines (SHA1, SHA2, MD5), AES256 encryption and a quick keyword search on the fly at amazing speeds.
Usage: Under the Linux OS: Full Forensic imaging, HASH, Erase and Format, Drive Diagnostics, Virtual Emulator, Remote Capture, Encrypt, Decrypt, Keyword Search before or while the imaging, Scripting.
Under Windows 8.1 Pro: Load and use any third-party applications to perform: Full Forensic analysis (EnCase, Nuix, Magnet), Multiple Cellphone data extractions (Cellebrite, MSAB, Paraben) using the unit’ fast USB ports.
The user can use the unit to:
- Forensic Imaging with E01/Ex01 format and with full compression, DD, Mirror, Mixed_format DD/E01, Selective Imaging of files and folders using file extension filters (run E01 4 multiple parallel sessions using 8 SAS/SATA drives and with 16 E01 compression engines).
- Perform Forensic Imaging from 7 Suspect drives to one large Evidence drive, in append mode.
- View the CAPTURED data directly on Ubuntu Desktop Screen.
- Upload 8 Forensic images to a network (SMB, CIFS, NFS).
- Erase data from many drives simultaneously using DoD(ECE, E), Security Erase, Enhanced Security, Sanitize erase modes.
- View the captured data directly on Ubuntu Desktop.
- Run Virtual Drive Emulator to boot, mount and view the Suspect drive in its native environment (mount raw drive or DD/E01 drive image), and extract important files into Evidence drive or any external storage.
- Perform Encryption and Decryption of drives that contain sensitive information.
- Use third-party applications to run Multiple Cellphone/Tablets Data Extraction and Analysis.
- Use the unit as a Full Forensic Analysis station running Encase/Nuix/FTK applications.
- Easily reconfigure the unit’s ports, where each of the target port can be configured as source or target for running 4:4 sessions, ot to run upload 8 to network.
- Convert the unit’s 8 USB3.0 ports to SATA ports and run more parallel sessions (with the use of some USB3.0 to SATA adapters).
- Expand with optional PCIE 3.0 expansion slots to support NVMe, SCSI, 1394, TB, USB3.1, FC storage devices.
- Optional: Configure the unit with 40Gigabit/s dual ports Ethernet controller for a faster forensic Images Network loader.
- Use the unit’ 2 Thunderbolt 3.0 ports (USB-c 10gigabit/s) to connect TB3.0 to PCIE 3.0 compact expansion box and use 2 NVMe Kit to capture data from NVMe 2.5″ SSD or NVMe M.2 SSD.
- Use the two 1Gigabit/s and one 5Gigabit/s native network ports to increase upload speed of DD/E01 images.
The unit is designed to help expedite the forensic imaging process, especially in facilities where there is a large backlog in imaging hard disk drives by performing many parallel forensic imaging in a true optimized multiple session’s application.
The Unit Built-in: 8 native SAS/SATA ports (SAS 3.0) in a 8 open tray drive caddie, 8 native USB3.0 ports, 2 USB 3.1 ports, e-SATA port, 1Gigabit/s Ethernet port, HDMI port.
The Unit as Forensic Imaging Tool: In one read pass from the “Suspect” drive, the application can run the following operations simultaneously: Forensic Imaging with E01 format and with full compression, Encryption with AES 256, simultaneously calculate 3 HASH Verification and Authentication values (MD5, SHA1, SHA2), and Saving the captured Forensic Images to many destinations such us 1) Two “Evidence” drives 2) Network 3) External compact USB3.0/e-SATA TB RAID encrypted storage 4) NAS. In addition, the user can run (optional) Virtual Drive Emulator to browse the Suspect drive under Windows, transfer and copy important files from the Suspect drive to any destination drives.
The Unit as Complete Forensic Platform: In addition the unit can serve as a platform for a forensic investigator to run a complete investigation and to perform: Cellphones and Tablets data Extraction and Analysis A complete Computer Forensic investigation Analysis with applications such as Nuix, FTK, EnCase, ProDiscovery, A Triage application on the captured drive.
The Unit as Data Eraser: Supports DoD and Security Erase, Enhanced Security erase protocols that are NIST 800-88 compliance.
Dual Boot: The unit is configured as a dual boot unit (Linux and Windows 10 PRO). The Linux OS to be used for Forensic Imaging purpose where the performance of the Forensic Imaging under Linux is faster, more efficient, and a more secure operation. The Windows 10 Pro OS to be used for running third-party applications to perform data analysis, Cellphone data extraction capture, Triage data extraction and other tasks.