Home > Line of Products ↓ >

SuperImager Plus Complete Forensic Kit for 8" T3 - i7 Edition with Dual Boot Enabled

SuperImager Plus 8"  T3 Field Forensic Complete Kit with 8"  Touchscreen color LCD display and SAS/SATA-3 and USB3.0 and i7 CPU
Rolling Carry Case with customized foam


 
Alternative Views:


SuperImager Plus 8" T3 Field Forensic Complete KIT includes the SuperImager Plus 8" T3 Forensic Field unit with Thunderbolt 3.0 port, PCIe 3.0 x4 Expansion Box, Dual Boot Linux/Win 8.1, with Virtual Drive Emulator enabled, Selective Capture of Files and folder feature, Remote Capture KIT, all in a rolling hard carry case, and includes accessories and adapters.
A complete platform for field forensic investigator. Imaging, Selective capture, Emulate, HASH, Encrypt, Erase, View, Remote Capture, Network Capture, Cellphone Extraction, Triage Data Collection, Full Forensic Analaysis

Product Code: SIK-0007-00A
Please call for pricing

Description Technical Specs Extended Information
 
    SuperImager Plus 8” T3 Forensic Field Complete Kit - i7 Edition (250GB) consists of:
    A) SuperImager Forensic 8" T3 Field Forensic Dual Boot unit - i7 Edition with Thunderbolt 3.0 port (i7 CPU, 250GB SSD, 16GB internal memory SAS 3.0), an extremely fast Forensic Imaging device (Run HASH authentication @ 65GB/min on NVMe SSD), and a mobile forensic platform unit. Built-in with 8" Touchscreen color LCD display, 4 SAS/SATA-3 ports, 8 USB3.0 ports, 1Gigabit Ethernet port, e-SATA port, DP, Audio Ports, and Thunderbolt 3.0 port. In one read pass over the "Suspect" drive, the SuperImager application can achieve: Forensic Imaging with E01 compress, Encryption with AES256, 3 parallel HASH Authentication (MD5, SHA1, SHA2), and Saving Images to 2 external drives, external compact mobile USB3.0/eSATA TB RAID storage devices, and to a local Network. The unit supplied and pre-configured with Dual boot Linux/Windows and with Virtual Drive Emulator enabled. The application also supports Selective Capture mode where the user can select files and folder for a quick copy, and keyword search to run prior of the capture.
    B) Thunderbolt 3.0 to PCIE 3.0 Expansion Box with M.2 NVMe controller installed
    C) 1394 Kit - Support capture from Firewire storage devices include Mac (Include 1394 controller and 1394 cables)
    D) SCSI Kit - Supports capture data from SCSI Hard Disk Drives (include SCSI controller, cables,and adapters)
    E) NVMe complete kit (supports M.2 and 2.5" NVMe SSD)
    F) Virtual Drive Emulator option enabled
    G) Remote Capture KIT(Intel based CPU)
    H)
    Rugged and rolling IM2500i case, customized foam, with a lid organizer
    I) Essential Accessories
SuperImager Plus unit with i7 CPU, 16GB Memory, and S/W Version 1.4.52
Hash Verification/ Authentication Only (Reading Speed) Avg Speed GB/Min
Hash single drive, in a single session (Samsung 850 EVO SSD)
SHA-1 30.6
MD5 30.6
SHA-1+ MD5 30.6
Hash 2 drives in 2 separate sessions (2 Samsung 850 EVO SSD)
SHA-1 + MD5 drive 1 26.2
SHA-1 + MD5 drive 2 26.6
Hash single drive, in a single session (Interl NVMe 750)
SHA-1 65.0
SHA-1 + MD5 65.0
Wipe Drives (Write Speed) (Samsung 850EVO SSD)
Security Erase Mode 30.0
Single Pass - User Erase Mode 28.8
Forensic Imaging
100% bit by bit Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD
with SHA-1+ MD5 Hash on 28.5
DD Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
with SHA-1 + MD5 Hash on 29.1
DD Imaging SanDisk Extreme II SSD to Samsung 850 EVO SSD 2 GB file Chunks and NTFS)
with SHA-1 + MD5 hash on 28.5
E01 Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
with SHA-1 + MD5 Hash on 24.2
Features
    • Main Hardware Features:
    • Case: Mobile and easy to carry
    • CPU: i7 7th Generation
    • Display: 8" (800x600) LED backlight Touchscreen color LCD display
    • Hardware: Very high quality high performing components
    • The Unit’s Port:
    • o 4 SAS/SATA native ports (2 source and 2 targets)
    • o 8 USB3.0 – (2 source and 6 targets- Also all those ports can be used as a host to plug and use keyboard, mouse and other peripherals)
    • o 1 Thunderbolt 3.0 Port – can be used for USB3.1, TB monitor, Thunderbolt Expansion Box
    • o 1 e-SATA port (connected directly to the motherboard)
    • o 1 Gigabit/s Port
    • o 1 Display Port
    • o 1 HDMI port – Shared between internal display and an external use
    • Hardware Upgrade: The unit can be upgraded at time of purchasing for additional cost, to a larger internal SSD, or the memory can be upgraded to 32GB
    • OS: Ubuntu 64 Bit and Win 8.1 Professional 64 Bit in a dual boot. The open Ubuntu OS allows for easy application modification to include new features, easy adaptation to new hardware and ease of adding third-party Ubuntu applications.
    • Writes Block: Using “device driver” blocking mechanism based on Maxim Suhanov Mechanism (https://github.com/msuhanov/Linux-write-blocker)
    • Application Updates: The application can be easily updated by using USB thumb drives and by using the “Update Software from USB” icon in the application tools screen
    • Application Settings:
    • HPA/DCO Automatic Supports: The application has the ability to automatically open HPA and DCO areas, and resize the "Suspect" hard drive to its full native capacity, in order to capture any “hidden data” (HPA/DCO are special areas on the drive that support this feature)
    • Bad Sectors Handling: The user can select to skip bad sectors, a block of bad sectors, or to abort the operation when it encounters bad sectors on the "Suspect" drive.
    • The skipped bad sectors will be reported in the log file in detailed or in summary
    • Forensic Images - Destination: The user can save Forensic Images to any attached storages to the SuperImager unit, or to any connected network using the unit 1Gigabit/s port or the 10Gigabit Option, or to any external USB3.0 RAID (encryption is optional) or external NAS storage in a very good speed.
    • Captured Storage Protocols and Interfaces: SAS, SATA, e-SATA enclosures, IDE, USB2.0, USB3.0, MMC, M.2 NGFF(SATA or PCIE base), Thunderbolt 2.0, Thunderbolt 3.0, USB3.1, SCSI*, FC*, 1394*, NVMe*
    • PCIe Supports: Supported M.2 and 2.5” PCIE SSD, PCIE Express cards and PCIE express Memory using the SuperImager T3 port and the TB3.0 to PCIE Expansion Box and with the NVMe Kit or PCIE Express card reader
    • Form Factors: Capture data from various form factor devices: 3.5", 2.5", ZIF, 1.8", Micro-SATA, Mini-SATA, Slim SATA, Ultra Slim SATA, PCIE*, Mini PCIE*, M.2 NGFF, CF-30
    • Cross Copy from Ports and Interfaces: The user can choose to capture from one port with one type of storage protocol and interface, and save the forensic Image into a different storage protocol and interface using destination ports. The cross copy of data can be done between any of those SAS/SATA/IDE/USB/SCSI/1394/TB interfaces
      Application Features:
    • GUI: The application is built with large icons and is very simple and easy-to-navigate. In a few clicks, the user can set an operation, and it will be quickly up and running
      Speed:
    • Extremely fast – One of the fastest Forensic Imaging solution available in the market today achieving a speed of above 30GB/min
    • • Tested with HASH verification operation with SHA-1 enabled the recorded top speed was 30GB/min with Solid State Drive, and 10GB/min with 1TB WD Blue SATA-3 Hard Disk Drive
    • • Tested with Forensic Imaging operation of 1 to 2 with SHA-1 enabled the recorded sustained top speed was 29GB/min with 3 SSD of SanDisk 120GB Extreme II
    • Extreme Speeds when performing Forensic capture with E01/Ex01 formats and with full Compression:
    • • The new Linux-based SuperImager Plus application utilizes and optimizes multiple CPU cores to achieve one of the most efficient operations while performing at incredibly high speeds with E01/Ex01 formats with full compression. The application allows users to manually select and adjust the number of hyperthreads and the level of compression used during each session
    • • Forensic data capture with Encase E01/Ex01 formats with full compression is widely used operation in the forensic industry, and generally requires a trade-off between speed, space, and time of decompressing by the EnCase application
    • • Comparative tests show a 20% increase in speed when using the SuperImager Plus Linux-based application over the SuperImager Windows-based application. Tests were performed with the same hardware and the same hard disk drives (filled with 43% of random data), and the same level 1 of compression. The Linux-based application was set to use 16 compression threads
    • HASH Authentication: Simultaneously calculates on-the-fly up to 3 HASH Authentication values MD5/SHA-1/SHA-2 at the same session
      Encryption: On-the-fly AES256 encryption of the "Suspect" drive, saving the encrypted data on "Evidence" drive in 100%, DD, E01/Ex01 formats.
    • Decryption: The user can perform decryption on a drive, previously encrypted by any of the SuperImager units. Alternatively, the user can use a standalone MediaClone Linux decryption utility application to perform decryption on the encrypted drive using any PC. The supplied standalone decryption utility application can be burned onto a USB flash drive that later can be used to boot the PC to the MediaClone Linux decryption utility, where the encrypted drive and a blank destination drive were attached to the PC. (The user needs to supply to the utility application the saved encryption key). MediaClone developed its own decryption utility in order to make sure that the user can always decrypt the drives that were encrypted via the MediaClone units, and not to relay on TruCrypy or other third-party application that might not be supported in the future
      Forensic Images Formats: Multiple Image Formats 100% Bit by Bit Mirror copy, Linux DD Format, Encase E01/Ex01 Formats (include
      options for optimizing the compression by adjusting the compression level and the number of compression parallel engines) and Mix-Format of E01/E01/DD. Mix-Format is where the user can capture from one source drive and save the images into multiple destination ports, each target port can be selected to be one of the 3 E01/EX01/DD formats. In addition, the user can use a file-based copy to copy files and folders, by using selective imaging with file extension filters
    • Evidence Drive Formats: exFAT/FAT/NTFS/HFS+/EXT4
    • Audit trail and operation Log Files: Generated automatically by the application and saves on the Evidence/Target drive (PDF).
    • enerated automatically by the application and saves on the
    • Drive Spanning: Supports spanning the captured data onto many “Evidence” drives, when the Evidence drives are not large enough (Also supports restore images from spanned over multiple drives)
    • Main application Features:
    • Supports spanning the captured data onto many “Evidence” drives, when the Evidence drives are not large enough (Also supports restore from spanned multiple drives)
      Main application Features:
    • • Forensic Imaging Mode
    • • Forensic Restore back the data that was captured to another drive in the original format
    • • Erase data from drives and Quick Format
    • • HASH calculation authentication and verification
    • • Keyword search to be run prior to the capture
    • • Virtual Drive Emulator Option: Enable the user run a drive or image of a drive emulator on the unit (Windows only), and ability to share folders and copy important files. (Bypass the user Windows passcodes)
    • • Remote Capture (Intel based CPU) – capture from un-opened laptops and PC
    • Main Forensic Imaging Mode Features:
    • • Forensic Imaging Modes: Mirror Imaging bit by bit (100% or any % of the drive), DD, E01/Ex01 – with optional compression, Selective Capture(Capture Partitions, Files and Folders and with the use of file extension filters), Mix-Format of DD/E01/Ex01
    • • Targeted Imaging: Some time the forensic investigator does not have the time to do a full data capture of the Suspect drive. Now he/she can use the Selective Imaging feature to select only partitions, files, or folders (like the Windows user folders or Windows User- Documents and User-Pictures). With the use of pre-set file extension filters or add its own filter, the Forensic investigator, can narrow it capture scope and shorten is the acquisition time
    • • HASH while capture: MD5, SHA-1, SHA-2 (all 3 can be selected simultaneously)
    • • Erase The Reminder of the drive, after the copy
    • • Encryption/Decryption
    • Parallel operations:
    • Parallel Forensic Imaging - Multiple Session Operations: Improve efficiency of the evidence data collection process by using multitasking and parallel imaging process. The user can run multiple efficient parallel operations taking advantage the availability of the SuperImager unit’s multiple ports. The user can mix different type of operations, and each operation can be set as a new independent session. An example of operations: erase data from a drive connected to one port, HASH verify on a different drive connected to the second port, while performing forensic imaging of 1 to 1 on drives connected to the remaining ports.
      Basic Parallel Forensic Imaging: The supported modes are:
      Native SAS/SATA: 1 to 1, 1 to 2, 1 to 3, 2 to 2, 2 to 3. The 2 to 3 imaging mode uses the e-SATA port with the need to supply external power to the e-SATA plugged device and the 1:3 imaging mode need to be configured at time of purchasing of the main unit
      USB3.0: 1 to 1, 1 to 2, 2 to 2 and up to 2:6
      More Ports for Forensic Imaging:
    • With the use of USB3.0 to SATA fast adapters and with the combination of e-SATA port, the unit can support up to 2 to 7 and up to 4 to 7 Forensic Imaging of SATA drives.
      Parallel operation – Linux Elaborated:
      Detection Application Screen: All drives and storage devices that are connected to the unit will be "scanned" and displayed in one application screen called “The detection screen”. The user can tap on each drive to get its detailed info, run a quick S.M.A.R.T. tests (only using Target port), run Virtual Emulator (Source port), Safely preview the content of the drive (Source port), as well as selecting it for the desire operation they are planning to us
      Parallel Forensic Imaging: It depends on the number and the kind of ports that each model has. The application is very flexible in running multiple sources to multiple destinations, all in simultaneous operations. The user has the flexibility to change a role of a port from been Evidence port to be Suspect port and is not limited by the pre-assigned "Suspect" ports. The session control application screen provides the user with a very comprehensive information and control over the running sessions, including all the setting of the session, and the ability to abort the session
    • Network
    • Network Capture: Data from a network folder can be captured and saved into “Evidence” drives via the use of the iSCSI storage protocols. The SuperImager application (for both capture from a network or save to a network) supports SMB, NFS, CIFS network protocols. The capture can be run with HASH authentication and HASH verification
    • Saves Forensic Images to Network:Upload multiple Forensic images to a local network (DD, E01), simultaneously by using 1Gigabit/s port, 10Gigabit/s option, or any of the unit’s USB port to upload up to 8 parallel 1Gigabit/s network streams.
    • Disable Network process and protocols for security reason: Those network protocols are easy to disable using Ubuntu Preferences tools
    • Copy lose files from/to the network: The user can copy files from to network with HASH authentication for a better data integrity
    • Remote Capture - Capture Data from the Internal Drives of a un-opened Laptops or Computer: Using USB or 1Gigabit Ethernet ports of the laptop/computer, enables capture with the supplied Remote capture application on a USB stick, without the needs to remove the drive from the Laptop/computer or boot the laptop from its own OS (The capture speed is restricted to performance of the Laptop/PC CPU and the 1Gigabit/s connection). The captured can run with using HASH authentication. The Remote Capture Option Kit includes the USB flash drive, 1 Gigabit/s to USB3.0 Adapter and a crossover network cable. The Remote capture application supports capture via USB/1394/TB/R45-network ports
      A few More Features:
      Drive Trim Feature: Allows the user to manipulate the HPA/DCO area on the drive to create an Evidence/Target drive with the same capacity of the Suspect/Source drive
      Unit’s User Configuration Feature: This feature allows the administrator of the unit to set specific operation with a specific setting and with a lock passcode to be used by operators and users. (This feature need to be requested at the time of purchasing of the main unit - It needed for security purpose)
      Tasks Scripting Feature: The user can create a script to run sequential operation and parallel operations (more than 1 operation at the same time). There are no limitations on the number of scripts and operations. Be aware that for operation requires the use input, in that case, the operation will still stop and wait for the user input (Like when the user is running a drive spanning and a user respond is needed.
      Language Supports Feature: Easy to implement translation for a new languages. Supporting today the Korean and Chines languages
      Keyword search: Ability to perform a quick keyword search on the Suspect drive files and folder with filters on the files extension types, and with a few important keywords. (This is a quick keyword search to determent if a Suspect drives need to be captured)
    • Use the unit as a drive Eraser and Quick Format: Erase the Evidence drive prior to use, with extremely fast speed of up to 28GB/min with use of SSD and up
    • to 11GB/min with use of Hard Disk Drives.
    • Drive Erase Protocols: DoD 5220-22M, Security Erase, Enhanced Security Erase, Sanitze, or a USer-mode where the user can define the final data filling pattern and the number of iterations (Security Erase, Enhanced Security Erase, Sanitze, and DoD erase protocols are NIST 800-88 compliance)
    • Quick Format: NTFS, FAT, HFS+, EXT4, and exFAT
    • Logs and Erase Certification: The application generates extensive erase log files and NIST 800-88 erase certification (Also S.M.A.R.T. tests before and after the erase operation and are saved to XML file format) and erase that can be exported to USB thumb drive. The application has also built-in erase databases that easily can be exported to XLS
      Use the Unit as a Platform:
    • Secure Write Blocked File Preview: Browse and preview captured data on the Internal Display. The user should connect the drive to the unit’s Suspect port to protect the drive via the port write-blocking mechanism, turn the power to the drive by using the application power icon, and mount the drive using Ubuntu. The drive can be viewed including XLS, Docs files using the Ubuntu Open Office package. Alternatively, the user can boot the unit to Windows (if this option was purchased) and view the drive under Windows.
    • High Performances: As a platform, a forensic investigator can, in addition to imaging and capturing data, load and run third-party applications to analyze the captured data:
      • Cellphone/Tablet data extraction and analysis: Cellebrite, Oxygen, BlackBag, MPE+, Paraben applications
      and more, the user can use all the 8 USB3.0 ports to run cellphone extractions.
    • • Triage data collection: Nuix/Encase/ADF portable applications
    • • Full computer forensic analysis: Encase, Nuix, and FTK applications - data is already captured, and the hardware can support a full analysis
    • The units have very firm hardware that enables those said applications to run with excellent performance
    • External Hardware Options
    • USB3.0 to SATA Adapters and Kits Option: Today USB3.0 technology is extremely fast and can run read data from SSD drives up to 20GB/min. With the use of USB3.0 to SATA 4 channel Kit, the user can convert 4 USB3.0 ports to 4 SATA ports on any of MediaClone units. The optional Kit is supplied with one external PS, and it includes all the cabling to power and connects the 4 USB3.0 to SATA adapters.The tested performance when running 4 adapters in parallel was measured at a very high speed, with a very little speed degradation
    • M.2 SATA to SATA Adapter
    • Macbook Memory and SSD adapters
    • Built in the USA: The units are built and tested in the US
    • Warranty: One-year warranty for the main unit. (does not include cables and accessories)



Accessories
USB3.0 MMC Card reader SATA Split Data Cable USB3.0 to e-SATA Adapter at Speed of 3GBs Laptop Remote Access & Data Capture Kit for SuperImager units
USB3.0 MMC reader SATA Split Data Cable USB3.0 to e-SATA adapter at speed of 3Gbs. Laptop remote capture kit with the use of SuperImager units
Metal Stand for 8" Field Unit 2.5 Inch IDE to SATA Adapter IDE to SATA Adapters M.2 NGFF to USB3.0 adapter supporting PCIE base SSD (B+M) not NVME
Our Price: $150.00
Metal Stand for 8" Field unit 2.5 Inch IDE to SATA Adapter IDE to SATA Adapters M.2 NGFF to USB3.0 adapter supports PCIE SSD
Hard Case and custom foam for the 8" Field Unit ErgoTouch USB TouchPad Macbook 2013-14 PRO/Air SSD to USB3.0 adapter supporting PCIE base SSD (12+16 type) Micro SATA to SATA Adapter
Our Price: $100.00
SuperImager 8" Field unit hard case and foam option ErgoTouch USB TouchPad Macbook 2013/2014 to USB3.0 adapter supports PCIE SSD Micro SATA to SATA Adapter
M.2 (NGFF) SSD to SATA for MacBook Air 2012 Mac SSD 7+17 pins to SATA adapter for MacBook Pro 2012 1394 To Thunderbolt 2 Adapter 1.8" IDE to SATA Adapter
Our Price: $25.00
Our Price: $25.00
Our Price: $100.00
M.2 (NGFF) SSD to SATA for MacBook Air 2012 Mac SSD 7+17 pins to SATA adapter for MacBook Pro 2012 1394 to thunderbolt 2.0 1.8 Inch IDE to SATA adapter
M.2 (NGFF) SSD to SATA III B (SATA base only) USB3.0 to SATA Adapters - 4 Channel Kit include power - Linux ZIF Adapter to SATA Adapter, with a Flex Cable Mini SATA(mSATA) to SATA Adapter
Our Price: $25.00
M.2 (NGFF) SSD to SATA III  B (SATA base only) USB3.0 to SATA 4-Channel kit- Linux ZIF Adapter to SATA Adapter Mini SATA(mSATA) to SATA Adapter
Metal Swivel 360 Stand for 8" Field Unit Expansion Box Option SCSI Kit support up to 2 SCSI Hard Disk Drive SATA Split Power Cable
Metal Swivel 360 Stand for 8" Field Unit PCIE Expansion Box Data Acquisition or Cloning of SCSI hard drives SATA Split Power Cable

Share your knowledge of this product. Be the first to write a review »