SuperImager Plus Forensic Imaging Application Settings
Advanced Digital Forensic Imaging Application Capabilities
Drive Handling and Compatibility
• HPA/DCO Support: When enabled, it automatically detects and resizes drives to their native capacity, revealing hidden areas (common on some SATA drives) to ensure full data capture.
• Management of Drive Bad Sectors: In parts of bad drive handling, the user can choose to skip bad sectors or blocks or halt operations. Detailed or summarized error logs are automatically generated.
• 48-bit LBA Support: Supports drives up to 256TB.
• Dual OS: Operates under both Linux (Ubuntu) and Windows environments.
• Security Focused: All forensic imaging operations run on Linux for reduced malware risk.
• Easy Updates: Update the application via USB port or with a single tap on the main menu.
----------------------------------------------------------------------------------------------------
Performance & Speed
• Unmatched Throughput:
• SATA SSD: Up to 32GB/min
• SATA: SHA-1 + Imaging: Up to 30GB/min (SSD) | 10GB/min (HDD)
• NVMe SSD: Over 100GB/min
Media: Support HDD, SSD, M.2, MSATA, MicroSATA (1.8mm) and more. Support cross imaging from any port and any media.
Forensic Imaging Modes:
Full Imaging
• Raw image, bit-by-bit mirror image (100% or partial of the drive)
• Supports DD, E01/EX01, AFF4 formats (with the ability to select which partition to capture),
• E01/E01 Optional compression
Targeted (Triage) Imaging
• Selective Capture: Quickly capture only relevant data: partitions, user folders, documents, etc. (great for cellphone logical extraction)
• Filter by file type and apply up to 4 HASH algorithms (MD5, SHA-1, SHA-2, SHA-512) per file.
• File-based capture with metadata
• It supports FAT, exFAT, NTFS, EXT2-4, HFS+/APFS, and HPFS.
Imaging Options
• Mix Format output of E01/DD
• Standalone HASH authentication (raw image/DD/E01)
• Target Drives Spanning: Supports multi-drive spanning for large image captures
• Parallel Span Mode: When the source drive is much faster than the target drives, writing data to multiple destination drives in parallel can save a lot of imaging time – no need for special reconstruction software
Encryption & Decryption
• AES256-XTS on-the-fly encryption during capture
• Save encrypted images in DD, E01/Ex01, or 100% formats
• Standalone Decryption Utility:
• Works on any PC
• Bootable from USB
• Does not rely on 3rd-party tools like TrueCrypt
Parallel & Multi-Session Operations
• Run multiple forensic Imaging, HASHING, erasing, or drive diagnostics sessions simultaneously with no queuing or limitation of the number of sessions.
• Ability to configure each target port as a Source or Target with Write-Blocking for Source drives.
• Full session control via dedicated GUI
Data Erasure & Drive Prep
• Securely erase Evidence drives before use:
• SSD: up to 32GB/min
• HDD: up to 11GB/min
• Erase Protocols: DoD 5220-22M, NIST 800-88 compliant Security Erase, Sanitize, NVMe Secure Erase, and user-defined patterns.
• Format Options: NTFS, FAT, HFS+, EXT4, exFAT
• Detailed Erase Logs & Certifications (PDF/XML/XLS exportable)
Audit Trail & Reporting
• Automatic Log Generation: PDF logs are saved on Evidence/Target drives and the unit’s local storage.
• Erasure Reports: Includes S.M.A.R.T. pre/post logs and NIST 800-88 certificates
• Full Traceability: Logs every session action and hash value
Networking & Remote Imaging
• Network Protocol Support: SMB, NFS, CIFS, iSCSI
• Upload forensic images to NAS/local networks via 1GbE or 10GbE ports
• Disable network features for air-gapped workflows
• Remote Capture Capabilities:
• From laptops via USB or Ethernet with use of cross-over network cable
• Use of bootable agent
• Support for Windows/macOS (Intel, T1/T2, M1/M2)
• Supports capture via USB, 1394, or RJ-45
Special Imaging Features
• Drive Emulator: Simulate & preview a suspect drive's Windows environment and extract files
• RAID Support (Linux):
• Auto-detects and reconstructs RAID-0, 1, 5, 6 using DDF, mdadm, or Intel headers
• Advanced Imaging Modes for “ill” drives:
• Reverse Imaging- Helps for drives with many bad sectors at the beginning of the drive.
• Segmental HASHING
• Timeout adjustment per drive
• Auto retry after the power cycle
• Read-ahead disabling to avoid freezes
User Experience & Usability
• Large Icon GUI: Simple, intuitive, and fast to configure
• Detection Screen: Scan and view all connected drives in one place
• Drive Trim: Match target drive size to source by manipulating HPA/DCO commands on the SATA target drives
• Audio Alerts: Session completion notifications
• Task Scripting: Create custom sequential or parallel workflows
• Language Support: Includes Korean and Chinese
• Keyword Search:
• Pre-Imaging (to assess importance)
• Live During Imaging (with extension filters)
Additional Tools
• Cloud Sync: Optional Insync service to capture from OneDrive, Google Drive, etc.
• Network Tapping Module: Optional Live network sniffing and PCap capture using Wireshark
Use as a Complete Digital Forensic Workstation
Install industry tools directly onto the unit:
• Cellphone Data Extraction: Support for Cellebrite, Oxygen, MSAB, Axiom
• Triage Tools: Encase, Nuix, ADF
• Full PC Forensics: FTK, Axiom, Encase
• RAID Analysis: Compatible with Windows-based RAID recovery tools
Hardware & Build
• Made in the USA: Engineered, built, and tested in California
• Warranty: One-year limited warranty on the main unit (excludes cables/adapters)