SuperImager Plus Desktop Pro Gen-2 Forensic Lab unit with 8 SAS/SATA-3, 7 USB3.0, 2 USB3.1 ports. The unit is a top performing of multiple sources to multiple targets of computer forensic Imaging in the market. The unit has also PCIE 3.0 expansion option to supports 10 Gigabit/s Ethernet and supports for SCSI, FC, 1394 storage devices

Product Code: SIL-0002-00A
The SuperImager® Plus Desktop Pro Gen-2 Forensic Lab Unit - is a heavy duty, industrial, and extremely fast Forensic Imaging unit that captures data from multiple sources to multiple target drives. The unit is running under Linux Ubuntu OS, which is less targeted OS by malware, and it reduces the OS performance overhead, especially when performing full compression, by almost 15-20%.
User can use to the unit to:
1) Forensic Imaging with E01/Ex01 format and with full compression (4:4 native SAS/SATA, 16 compression engines)
2) Perform Forensic Imaging from 7 Suspect drives to one large Evidence drive
3) Upload 8 Forensic images to a network (SMB, CIFS, NFS)
4) Erase data from many drives simultaneously using DoD(ECE, E)/ Security Erase/Enhanced Security Erase modes
5) View the captured data directly on Ubuntu Desktop
6) Run optional Virtual Drive Emulator to boot, mount and view the Suspect drive in its native environment (mount raw drive or DD/E01 drive image), and extract important files into Evidence drive or any external storage
7) Perform Encryption and Decryption of drives that contain sensitive information
8) Use third-party applications to run Cellphone/Tablets Data Extraction and Analysis
9) Use the unit as a Full Forensic Analysis station running Encase/Nuix/FTK applications
10) Use of the unit's ports, in different ways, where each of the unit's ports can be configured as source or target
11) Convert the unit's 7 USB3.0 ports to SATA ports and run more parallel sessions (with the use of some USB3.0 to SATA adapters)
12) Expand with optional PCIE 3.0 expansion slots to support SCSI, 1394, TB, USB3.1, FC storage devices.
13) Configure the unit with 40Gigabit/s dual ports Ethernet controller for a faster forensic Images Network loader.
14) User the new NVMe Kit to capture data from NVMe 2.5" SSD or NVMe M.2 SSD

The unit is designed to help expedite the forensic imaging process, especially in facilities where there is a large backlog in imaging hard disk drives by performing many parallel forensic imaging in a true optimized multiple session's application.

TheUnit Built-in:
The unit has a built-in 8” Touchscreen color LCD display, 8 native SAS/SATA ports in a 8 open tray drive caddy, 7 native USB3.0 ports, e-SATA port, Generic USB2.0 port, 1 Gigabit/s Ethernet port, HDMI port.

The Unit as
Forensic Imaging Tool:
In one read pass from the "Suspect" drive, the application can run the following operations simultaneously: Forensic Imaging with E01 format and with full compression, Encryption with AES 256, simultaneously calculate 3 Hash Verification and Authentication values (MD5, SHA1, SHA2), and Saving the captured Forensic Images to many destinations such us 1) Two “Evidence” drives 2) Network 3) External compact USB3.0/e-SATA TB RAID encrypted storage. In addition, the user can run (optional) Virtual Drive Emulator to browse the Suspect drive under Windows, transfer and copy important files from the Suspect drive to any destination drives

The Unit as Complete Forensic Platform:
In addition the unit can serve as a platform for a forensic investigator to run a complete investigation and to perform: Cellphones and Tablets data Extraction and Analysis A complete Computer Forensic investigation Analysis with applications such as Nuix, FTK, EnCase, ProDiscovery, A Triage application on the captured drive

The Unit as Data Eraser:
Supports DoD and Security Erase, Enhanced Security erase protocols that are NIST 800-88 compliance.
The SuperImager Plus Desktop Forensic Lab unit is one of the top-of-the-line forensic imaging devices on the market today. It will outperform many units running Windows Imaging applications with i7 6th generation CPU The unit has many expansion capabilities and options using, PCIE 3.0 Expansion slots.

Dual Boot: The unit is configured as a dual boot unit (Linux and Windows 7 PRO). The Linux OS to be used for Forensic Imaging purpose where the performance of the Forensic Imaging under Linux is faster, more efficient, and a more secure operation. The Windows 7 Pro OS to be used for running third-party applications to perform data analysis, Cellphone data extraction capture, Triage data extraction and other tasks

Multiple Forensic Images Network Loader - Unique feature solves the 1 Gigabit/s Ethernet Port Upload Bottleneck. The user can upload up to 8 Forensic images directly to a network using 8 equivalent 1 Gigabit/s Ethernet network streams
SuperImager Plus unit with i7 CPU, 16GB Memory, and S/W Version 1.4.52
Hash Verification/ Authentication Only (Reading Speed) Avg Speed GB/Min
Hash single drive, in a single session (Samsung 850 EVO SSD)
SHA-1 30.6
MD5 30.6
SHA-1+ MD5 30.6
Hash 2 drives in 2 separate sessions (2 Samsung 850 EVO SSD)
SHA-1 + MD5 drive 1 26.2
SHA-1 + MD5 drive 2 26.6
Hash single drive, in a single session (SanDisk Extreme II 128GB)
SHA-1 30.8
SHA-1 + MD5 30.8
Wipe Drives (Write Speed) (Samsung 850EVO SSD)
Security Erase Mode 577.2
Single Pass - User Erase Mode 28.8
Forensic Imaging
100% bit by bit Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD
with SHA-1+ MD5 Hash on 28.5
DD Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
with SHA-1 + MD5 Hash on 29.1
DD Imaging SanDisk Extreme II SSD to Samsung 850 EVO SSD 2 GB file Chunks and NTFS)
with SHA-1 + MD5 hash on 28.5
E01 Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
with SHA-1 + MD5 Hash on 24.2
    • Main Hardware Features:
    • Case: Industrial, heavy duty, desktop style
    • CPU: i7 6th Generation
    • Display: 8" (800x600) LED backlight Touchscreen color LCD display
    • Hardware: Very high quality high performing components, some with military specifications.
    • Hardware upgrade: The unit can be upgraded at time of purchasing for additional cost, to a large internal SSD
    • OS: Linux Ubuntu 64 Bit
    • Writes Block: Using “device driver” blocking mechanism based on Maxim Suhanov Mechanism (https://github.com/msuhanov/Linux-write-blocker)
    • Application Updates: Application can be easily updated via USB flash drive and special update screen
    • Application Settings:
    • HPA/DCO Automatic Supports: The application has the ability to automatically open HPA and DCO areas, and resize the "Suspect" hard drive to its full native capacity in order to capture any “hidden data” (HPA/DCO are special areas on the hard disk drive that support this feature)
    • Bad Sectors Handling: The user can select to skip bad sectors, or abort the operation when it encounters bad sectors/block of sectors on the "Suspect" hard disk drive
    • Connectivity:
    • Forensic Imaging Destinations: The user can save Forensic Images to a local network shared folder for easy access and analysis, or save images to an external USB3.0 RAID (encryption is optional) storage at a very good speed
    • Captured Storage Protocols and Interfaces: SAS, SATA, e-SATA enclosures, IDE, USB2.0, USB3.0, MMC, M.2 NGFF(SATA or PCIE base), 1394*, Thunderbolt*, FC*, USB3.1, and SCSI*
    • Form Factors: Capture data from various form factor devices, such us: 3.5", 2.5", ZIF, 1.8", Micro-SATA, Mini-SATA, PCIE*, Mini PCIE*, M.2 NGFF
    • Cross Copy from Ports and Interfaces: The user can choose to capture from one type of port, storage protocol and interface, and save the forensic Images into a different port, storage protocol and interface. The cross copy of data can be done between SAS/SATA/IDE/USB/SCSI/1394 interfaces
    • Application Features:
    • GUI: The application is built with large icons and is very simple and easy-to-navigate. In a few clicks the user can setup the operation and up and running
    • Speed: Extremely fast
    • • Tested with Hash verification operation with SHA-1 enabled. The recorded top speed was 30GB/min with a Solid State Drive, and 10GB/min with 1TB WD Blue SATA-3 Hard Disk Drive
    • • Tested with Forensic Imaging operation of 1 to 2 with SHA-1 enabled. The recorded sustained top speed was 29GB/min with 3 SSD of SanDisk 120GB Extreme II
    • Extreme Speeds when performing Forensic capture with E01/Ex01 formats and with full Compression:
    • • The new Linux-based SuperImager Plus application utilizes and optimizes multiple CPU cores to achieve one of the most efficient operations, while performing at incredibly high speeds with E01/Ex01 compression. The application allows users to manually select and adjust the number of threads and the level of compression used during each session
    • • Forensic data capture with Encase E01/Ex01 formats with full compression is widely used operation in the forensic industry, and generally requires a trade-off between speed, space, and time of decompressing by the EnCase application
    • • Comparative tests show a 20% increase in speed when using the SuperImager Plus Linux-based application over the SuperImager Windows-based application. Tests were performed with the same hardware and the same hard disk drives (filled with 43% of random data), and the same level 1 of compression. The Linux-based application was set to use 16 compression threads
    • Hash Authentication: Simultaneously calculates on-the-fly up to 3 Hash Authentication values MD5/SHA-1/SHA-2
    • Encryption: On-the-fly AES256 encryption of the "Suspect" Hard Disk Drive, saving the encrypted data on the "Evidence" Hard Disk Drive in 100%, DD, E01/Ex01 formats
    • Decryption: The user can perform decryption on a drive, previously encrypted by any of the SuperImager units. Alternatively user can use a standalone MediaClone Linux decryption utility application to perform decryption on that drive using any PC. The supplied standalone decryption utility application can be burned onto a USB flash drive that later can be used to boot the PC to the Linux utility, where the encrypted drive and a blank destination drive were attached to the PC. (The user needs to supply to the utility application the saved encryption key)
    • Forensic Images can be saved in the following formats: Mirror Image Bit by Bit (100% or any % of the drive), Linux DD Format, Encase E01/Ex01 formats including optional optimized compression
    • Evidence Drive Formats: exFAT/FAT/NTFS/HFS+/EXT4
    • Log Files: Audit trail in PDF and TXT formats with the ability to customize the reports and adding company Logo and info
    • Drive Spanning: Supports spanning the captured data onto many “Evidence” drives , when the Evidence drives are not large enough (Also supports restoring from a spanned capture)
    • Partial captures: When a Forensic imaging operation is terminated before it completes due to power failure or other reasons, some of the captured data can still be usable. In this case the SuperImager Plus application saves the partial captured data to the Evidence drive. A forensic investigator can use the data to extract vital information: 1) For 100% bit-by-bit capture mode using any forensic analysis application 2) For E01 Capture mode using some data mining utilities (since the E01 was not completed it cannot be used by the Encase application since EnCase will detect the image as corrupted)
    • Main application Features:
    • • Forensic Imaging Mode
    • • Forensic Restore (Restore the data to the original format)
    • • Erase data from drives and Quick Format
    • • Hash calculation authentication and verification
    • • Virtual Drive Emulator (Optional)
    • Main Forensic Imaging Mode Features:
    • • Forensic Imaging Mode 100% bit by bit, DD, E01/Ex01 – with optional compression
    • • Hashing while capturing: MD5, SHA-1, SHA-2 (all 3 can be selected simultaneously)
    • • Erase Remainder of the drive (Unused area)
    • • Encryption/Decryption(AES-256)
    • Parallel operations:
    • Parallel Forensic Imaging - Multiple Session Operations: The user can run a multiple efficient parallel operation, since many ports are available, the user can mix different type of operations, and each operation is set as a new independent session. Example of operations: erase data from hard disk drive on one port, perform hash verify on second port while forensic imaging 1 to 1 on the remaining ports
    • Basic Parallel Forensic Imaging: The supported modes are:
    • Native SAS/SATA: 4 to4
    • USB3.0: 3 to 3
    • More Ports for Forensic Imaging:
    • With the use of USB3.0 to SATA fast adapters, the unit can support up to 7:7 Forensic Imaging of SATA Hard Disk Drives. With the use of additional PCIE SAS controller with external ports, the application can support more possibilities of imaging of SAS drives
      Parallel Operations – Linux Elaborated:
    • The Drive Detection Screen: All hard disk drives and storage devices that are connected to the units will be scanned and displayed in one application screen called “the detection screen”. The user can tap on each drive to get the detailed info, as well as selecting it for the desired operation
    • Parallel Forensic Imaging: Depends on the number and the type of ports that each model has. The application is very flexible in running multiple source/Suspect drives to multiple destination/Evidence drives, all in a single operations. The user has the flexibility to change a role of a port from Evidence to Suspect, and her is not limited by the pre-assigned "Suspect" ports. The session control application screen provides the user with a very comprehensive information and control over the running sessions, including all the settings of each session,as well as the ability to abort the session
    • Parallel Forensic Imaging - Multiple Session Operations: User can run multiple efficient parallel operations and can mix different type of operations; for example erase hard disk drive on one port, hash verification on another port, while performing forensic imaging on other ports (each operation can function as a new independent session). The number of sessions also depends on the CPU: i5 -4 sessions, i7- 8 sessions
    • Batch Mode Forensic Imaging - Multiple Suspects into one Evidence Drive: User can run in one session a forensic capture from many Suspect drives and save the images (E0/DD) into one large Evidence drive in append mode.
    • Network:
    • Network Capture: Data from a network folder can be captured and saved into “Evidence” drives via iSCSI storage protocols.(SMB, NFS, CIFS)
    • Upload Forensic Images to Network: Upload many forensic images to the local network (DD, E01) simultaneously by using up to 8 parallel equivalents of 1 Gigabit/s network streams. Also with the use of a 10 Gigabit/s Ethernet Option to max the upload speed
    • Remote Capture - Capture Data from the Internal Hard Disk Drives of a Computer: Using USB or 1 Gigabit Ethernet ports of the laptop/computer, enables capture without the needs to remove the hard drive from the Laptop/computer. The imaging speed is restricted by the performance of the Laptop/PC's CPU and the 1 Gigabit/s connection (Also if USB3.0 to 1 Gigabit adapter will been used, it will restrict this performance as well)
    • Virtual Drive Emulator (Optional S/w)
    • User can use the Drive Emulator Built-in module in the SuperImager Plus Linux application to simulate, on the spot, the Suspect PC environment, browse the Suspect drive under Windows, transfer and copy important files from the Suspect drive to any destination drive. The Drive Emulator works only on Windows-based Suspect drives. The application can mount Suspect raw drives, or an image of the Suspect drives (DD/E01).
    • Erase and Quick Format Operation:
    • Hard Disk Drive Erase Protocols: DoD 5220-22M, Security Erase, Enhanced Security Erase, or the user can define the final data filling pattern and the number of iterations (Security Erase, Enhanced Security Erase, and DoD erase protocols are NIST 800-88 compliance since they comply with the required verification pass)
    • Quick Format: NTFS, FAT, HFS+, EXT4, and exFAT
    • Logs and Erase Certification: The application generates extensive erase log files and erase certification (option to save to NIST 800-88 certification format) that are easy to export to a USB flash drive
    • Unit as a Platform:
    • File Preview: Browse and preview captured data on the internal unit's display
    • High Performances: As a platform, a forensic investigator can, in addition to imaging and capturing data, load and run third-party applications to analyze the captured data:
    • • Cellphone/Tablet data extraction and analysis: Cellebrite, Oxygen, BlackBag, MPE+, Paraben applications
    • • Triage data collections applications: With the use of Nuix/Encase portable applications, the user can capture important data from the Suspect drive and save it to any destination
    • • Full computer forensic analysis: Encase, Nuix, and FTK applications
    • • Firm Hardware: The units have very firm hardware that enables those said applications to run with excellent performance
    • • The MediaClone Windows Drive Power Utility application allows the user to mount safely drives as read-only or read-write (depends on the unit’s port) in a secured way. The application also allows the user to dismount and remove drives in a safe way. Suspect’s port is automatically assigned to be read only
    • Expansion capabilities and the main hardware options:
      • Expansion Slots: Optional expansion slots (3 PCIE 3.0) that can be select to configure the main unit, at the time of purchasing the main unit, to supports many different kinds of storage devices such as SCSI, FC, 1394, TB, Express-Cards, Mini PCIE, M.2 PCIE NVMe and more. The Supports is limited to the total number of available Expansion slots.
      • USB3.0 to SATA adapters and Kits Option: Today USB3.0 technology is extremely fast and can run read data from SSD drives up to 20GB/min.With the use of USB3.0 to SATA 4 channel Kit, the user can convert 4 USB3.0 ports to 4 SATA ports on any of MediaClone unit. The optional Kit is supplied with one external PS and it includes all the cabling to power and connect the 4 USB3.0 to SATA adapters. The tested performance when running 4 adapters in parallel was measured at a very high speed and very little speed degradation.
      • SCSI Expansion and Configuration Option: The user can select to configure the main unit, at the time of purchasing of the main unit, with SCSI controller cards. . There are 2 kits available: 6 Drives SCSI and 3 Drives SCSi Supports. The kits include SCSI LVDS 3 channel cables (68pin connectors), SCSI terminators, VHDCI to SCSI adapters, SCA80 and HD50 SCSI adapters to supports old SCSI drives, and external PS. The PCIE 3.0 expansion slots do provides a very high bandwidth and the application can achieve a very high-speed meeting SCSI drives transfer rates.
      • Fiber Channel Expansion and Configuration Option: User can select to configure the main unit, at the time of purchasing of the main unit, with FC controller cards. The 2 drives FC-KIT includes FC dual ports 4Gigabit/s controller, 2 FC drive's Adapters, 2 Optical 1 meter cables, and two Transceivers. The PCIE 3.0 expansion slot do provides a very high bandwidth and the application can achieve a very-high-speed meeting FC drives transfer rates.
      • 1394 Expansion Configuration Option: The unit can be configured with 1394 PCIE controller to supports 1394 devices (1394 devices can be easily daisy chained).
      • USB3.1 Configuration Option: The unit can be configured with USB3.1 controller card to supports newly USB3.1 storage devices.
      • Thunderbolt adapter Option: With the use the Thunderbolt to 1394 adapter, a user can connect the main unit to a Mac laptop that has a TB port (that is booted in target mode) and have an access the Mac internal drive.
      • NVMe Option KIT: The unit can be configured with NVMe controller, supporting NVMe (M.2 or 2.5") SSD
      • 10 Gigabit Ethernet connections: Dual port Intel PCIE 3.0 Controller. Option to install 10-40Gigabit/s controller with SQFP+ optic ports.
      • USB3.0/SATA to M.2 (NGFF) SATA base adapters Option: Most current laptops and tablets use M.2 (NGFF) Storage devices. This adapter supports connectivity to some of the newest M.2 SSD storage (Storage that supported by SATA Protocols). There are 2 types of adapters that support M.2 NGFF: one is USB3.0 to M.2 NGFF and the second is SATA to M.2 NGFF
      • USB3.0 to M.2 (NGFF) PCIE(not NVMe) base adapters Option: A few adapters are available to supports Mini-PCIE SSD NGFF that are used in MacBook Air 2012 and MackBook Pro Retina 2012, MacBook 2013. Some adapters do not have standard connectors such in MacBook Air 2013 (12+16)
      • Built in USA: The units are built and tested in the US
      • Warranty: One-year free warranty on the main unit (it is not included warranty on accessories, adapters, and cables)
      • * With Expansion options

