The SuperImager® Plus 8” 3 NVMe + 3 SATA + 4 SAS Portable Forensic Unit
SuperImager Plus 8” Portable Forensic Field unit with 3 NVMe + 4 SAS/SATA + 3 SATA+ 2 Thunderbolt 4.0 + 6 USB3.2 + one USBC 3.2 Gen 2x2 ports. It is one of the top performance Field Computer Forensic Imaging tools and a Complete Digital Forensic Investigation platform
The unit is Portable, Compact, easy to carry, and extremely fast. It is built with 2 NVMe U.2 data & power ports, 2 SATA3 data & power ports, one e-SATA port in the back of the unit, 6 USB3.2 ports, one USB3.2 Gen 2x2 USBc port, and two Thunderbolt 4.0 ports.
The unit is configured with Dual Open OS of Linux for fast, efficient Forensic imaging and Windows 11 for running full Forensic Analysis (EnCase, Nuix, Axiom, and others), cellphone data extraction(Cellebrite, MASB, and others), and triage data collection. Using the Linux OS, the user can run: multiple,simultaneous independent forensic imaging sessions (mirror image, image a single partition, Linux-DD, EnCase, mix E01/DD, VHD, Triage with Files and Folders) with 4 HASH values(MD5, SHA1, SHA2, and SHA512 run all the four at the same time), encryption AES256 XTS, compression, keyword search all on the fly and save images to a network.
The max speed achieved: 31GB/min SATA SSD, 187GB/min NVMe SSD.
The unit hardware is robust, running Core Ultra 7 CPU with 32GB of memory, 1TB SSD, and 8” LCD display.
Main ports:
• 3 SATA ports: 2 SATA ports (power & data) and one e-SATA port on the main unit
• 4 SAS/SATA ports: On the TB3.0 Expansion Box
• 3 NVMe ports: 2 U.2 NVMe nativ eports on the main unit (power & data), one U.2 & M.2 NVMe port on the TB3.0 Expansion Box, and addition NVMe port (#4) with the use of the second TB4.0 port with fast USB3.2 Gen2x2 to NVMe adapter.
• 2 TB4.0 ports
• 1 USB3.2 Gen2x2 (USBc) port, and 6 USB3.2 ports
The unit supplied with:
• Remote Capture KIT
• Virtual Emulator (viewing the Suspect drive before the capture).
• 2 U.2 Extension Cables.
• 2 U.2 to M.2 NVMe adapters.
• Thunderbolt 3.0 PCI-E Expansion Box with 4 SAS ports controller, split cables, power cables, and with U.2 and M.2 NVMe controller (The Thunderbolt 3.0 Expansion box brings a lot of additional connectivity, like Thunderbolt 3.0 to 10GbE adapter).
Here are some of the tasks that the user can do:
1) Multiple Parallel Forensic Capture: Raw Image Mirror bit by bit, Linux-DD format, E01/Ex01 format (with full compression), Mixed-Format DD/E01. Ablityy to select single partition or capture the whole drive.
2) Run a Selective Imaging (Targeted Imaging) of files, folders with file extension filters and save HASH and metadata of the files (Logical Extraction)
3) Erase data from the Evidence drive before use - using DoD (ECE, E), Security Erase, NVMe Secure Erase, Sanitize, or User-Erase protocols.
5) Encrypt the data while capturing (using the AES256 XTS engine) and decryption at the destination using MediaClone supplied utility.
6) HASH the data while capturing – run simultaneously all the four MD5, SHA-1, SHA-2, and SHA-512 HASH engines.
7) Run a quick Keyword Search on the Suspect drive before or during the capture.
8) Run Multiple Physical Cellphones/Tablets data Extraction and Analysis using a third-party application on the Windows 11 side.
9) Run the Forensic Triage application with selective capture mode or with the use of a third-party application on the Windows 11 side.
10) Run a full Forensic Analysis application like Encase/Nuix/FTK/Axiom.
11) Run Virtual Drive Emulator to view the Suspect drive before captured (Linux)
12) Run Remote Capture from unopened laptops - Intel-Based CPU (supplied with this unit).
13) Use the Thunderbolt 4.0 ports to connect to 10GbE network with the use of optional TB3.0 to 10GbE adapter.
14) Unlock drives with passcode such ATA, BitLocker, Opal for SED drives, and TruCrypt.
15) Use the SuperImager Plus unit as a “Write Blocker” device: This feature enables the unit to function as a secure bridge between workstations on a network to Suspect drives attached to the SuperImager unit and by using the iSCSI protocol over a network connection. A forensic investigator using a workstation or laptop in one location can access a Suspect drive in different places in the Writes-Block safe mode. The unit will be connected to the same network, and the Suspect drive will be attached to the unit in read-only mode. The unit will act as a “write blocker” for any of the unit’s attached storage, such as SAS, SATA, USB, 1394, FC, SCSI, and NVMe.
Additional operations: HASH authentication, Drive Diagnostics, erase Evidence drive use, image restores from DD/E01, and process automation with scripting.
The main difference between using a product with U.2 port (with Extension cables) vs. using M.2 port where the media is plugged directly into the port:
NVMe U.2 port is more versatile and can support three types of NVMe SSD: M.2, U.2, PCIE NVMe storage controller, while M.2 port is limited to M.2 SSD. Using the U.2 Extension cables protects the unit's NVMe port from overuse and many insertions by plugging the SSD directly into the unit's port and damaging the port. (It is easier to replace an extension cable than the interface board of a damaged port!). Competitors that use NVMe M.2 ports are limited with their supports (Only M.2), and force the user to plug the media directly into the port. U.2 extension cables are very durable and built with high quality and precision, and they exhibit an extreme transfer rate of over 200 GB/min.
Performances:
Mirror Imaging of Samsung MZVPV512HDGL NVMe SSD, with a max speed of
Mirror Imaging of WD 1 TB NVMe SSD, with a max speed of 187 GB/min!
The SuperImager application is optimized to achieve extreme top speeds when using NVMe SSD:
HASH SHA-1 132.5 GB/min, Mirror Image 187 GB/min, Erase + Verify 130 GB/min, Verify 197 GB/min
|
SuperImager Plus 8" NVMe SATA mix ports unit with i7 CPU, 32GB Memory, and S/W Version 1.8.133.11
|
|
|
Operation:
|
Avg Speed GB/Min
|
|
HASH single drive, in a single session (Samsung 870 EVO SSD)
|
|
|
SHA-1
|
32.1
|
|
MD5
|
32.1
|
|
SHA-1+ MD5
|
32.1
|
|
HASH 2 drives in 2 separate sessions (2 Samsung 870 EVO SSD)
|
|
|
SHA-1 + MD5 drive 1
|
29.0
|
|
SHA-1 + MD5 drive 2
|
29.0
|
|
HASH single drive, in a single session (1TB WD black M.2 NVMe)
|
|
|
SHA-1
|
132.00
|
|
SHA-1 + MD5
|
132.00
|
|
Erase Drives using 1TB WD Black M.2 NVMe SSD
|
|
|
Read Verify
|
202.00
|
|
Single Pass - User Erase Mode
|
153.00
|
|
Forensic Imaging
|
|
|
100% bit by bit Imaging 1 TB WD Black to 1 TB WD black M.2 NVMe SSD
|
|
|
no HASH
|
187.00
|
|
with SHA1 HASH
|
132.00
|
|
DD Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
|
|
|
with SHA-1 + MD5 HASH
|
30.1
|
|
DD Imaging SanDisk Extreme II SSD to Samsung 850 EVO SSD 2 GB file Chunks and NTFS)
|
|
|
with SHA-1 + MD5 HASH on
|
28.5
|
|
E01 Imaging Samsung 850 EVO SSD to Samsung 850 EVO SSD (2GB Files Chunks and NTFS)
|
|
|
with SHA-1 + MD5 HASH on
|
24.2
|
SuperImager Plus Forensic Imaging Application Advanced Digital Forensic Imaging Application Capabilities
Drive Handling and Compatibility
• HPA/DCO Support: When enabled, it automatically detects and resizes drives to their native capacity, revealing hidden areas (common on some SATA drives) to ensure full data capture.
• Management of Drive Bad Sectors: In parts of bad drive handling, the user can choose to skip bad sectors or blocks or halt operations. Detailed or summarized error logs are automatically generated.
• 48-bit LBA Support: Supports drives up to 256TB.
• Dual OS: Operates under both Linux (Ubuntu) and Windows environments.
• Security Focused: All forensic imaging operations run on Linux for reduced malware risk.
• Easy Updates: Update the application via USB port or with a single tap on the main menu.
--------------------------------------------------------------------------------------------------------------------------------
Performance & Speed
• Unmatched Throughput:
• SATA SSD: Up to 32GB/min
• SATA: SHA-1 + Imaging: Up to 30GB/min (SSD) | 10GB/min (HDD)
• NVMe SSD: Over 100GB/min
Media: Support HDD, SSD, M.2, MSATA, MicroSATA (1.8mm) and more. Support cross imaging from any port and any media.
Forensic Imaging Modes
Full Imaging
• Raw image, bit-by-bit mirror image (100% or partial of the drive)
• Supports DD, E01/EX01, AFF4 formats (with the ability to select which partition to capture),
• E01/E01 Optional compression
Targeted (Triage) Imaging
• Selective Capture: Quickly capture only relevant data: partitions, user folders, documents, etc. (great for cellphone logical extraction)
• Filter by file type and apply up to 4 HASH algorithms (MD5, SHA-1, SHA-2, SHA-512) per file.
• File-based capture with metadata
• It supports FAT, exFAT, NTFS, EXT2-4, HFS+/APFS, and HPFS.
Imaging Options
• Mix Format output of E01/DD
• Standalone HASH authentication (raw image/DD/E01)
• Target Drives Spanning: Supports multi-drive spanning for large image captures
• Parallel Span Mode: When the source drive is much faster than the target drives, writing data to multiple destination drives in parallel can save a lot of imaging time – no need for special reconstruction software
Encryption & Decryption
• AES256-XTS on-the-fly encryption during capture
• Save encrypted images in DD, E01/Ex01, or 100% formats
• Standalone Decryption Utility:
• Works on any PC
• Bootable from USB
• Does not rely on 3rd-party tools like TrueCrypt
Parallel & Multi-Session Operations
• Run multiple forensic Imaging, HASHING, erasing, or drive diagnostics sessions simultaneously with no queuing or limitation of the number of sessions.
• Ability to configure each target port as a Source or Target with Write-Blocking for Source drives.
• Full session control via dedicated GUI
------------------------------------------------------------------------------------------------------
Data Erasure & Drive Prep
• Securely erase Evidence drives before use:
• SSD: up to 32GB/min
• HDD: up to 11GB/min
• Erase Protocols: DoD 5220-22M, NIST 800-88 compliant Security Erase, Sanitize, NVMe Secure Erase, and user-defined patterns.
• Format Options: NTFS, FAT, HFS+, EXT4, exFAT
• Detailed Erase Logs & Certifications (PDF/XML/XLS exportable)
Audit Trail & Reporting
• Automatic Log Generation: PDF logs are saved on Evidence/Target drives and the unit’s local storage.
• Erasure Reports: Includes S.M.A.R.T. pre/post logs and NIST 800-88 certificates
• Full Traceability: Logs every session action and hash value
Networking & Remote Imaging
• Network Protocol Support: SMB, NFS, CIFS, iSCSI
• Upload forensic images to NAS/local networks via 1GbE or 10GbE ports
• Disable network features for air-gapped workflows
• Remote Capture Capabilities:
• From laptops via USB or Ethernet with use of cross-over network cable
• Use of bootable agent
• Support for Windows/macOS (Intel, T1/T2, M1/M2)
• Supports capture via USB, 1394, or RJ-45
Special Imaging Features
• Drive Emulator: Simulate & preview a suspect drive's Windows environment and extract files
• RAID Support (Linux):
• Auto-detects and reconstructs RAID-0, 1, 5, 6 using DDF, mdadm, or Intel headers
• Advanced Imaging Modes for “ill” drives:
• Reverse Imaging- Helps for drives with many bad sectors at the beginning of the drive.
• Segmental HASHING
• Timeout adjustment per drive
• Auto retry after the power cycle
• Read-ahead disabling to avoid freezes
User Experience & Usability
• Large Icon GUI: Simple, intuitive, and fast to configure
• Detection Screen: Scan and view all connected drives in one place
• Drive Trim: Match target drive size to source by manipulating HPA/DCO commands on the SATA target drives
• Audio Alerts: Session completion notifications
• Task Scripting: Create custom sequential or parallel workflows
• Language Support: Includes Korean and Chinese
• Keyword Search:
• Pre-Imaging (to assess importance)
• Live During Imaging (with extension filters)
Additional Optional Tools
• Cloud Sync: Optional Insync service to capture from OneDrive, Google Drive, etc.
• Network Tapping Module: Optional Live network sniffing and PCap capture using Wireshark
Use as a Complete Digital Forensic Workstation
Install industry tools directly onto the unit:
• Cellphone Data Extraction: Support for Cellebrite, Oxygen, MSAB, Axiom
• Triage Tools: Encase, Nuix, ADF
• Full PC Forensics: FTK, Axiom, Encase
• RAID Analysis: Compatible with Windows-based RAID recovery tools
Hardware & Build
• Made in the USA: Engineered, built, and tested in California
• Warranty: One-year limited warranty on the main unit (excludes cables/adapters)