Twitter Linked In
 

MediaClone

MediaClone, Inc. Computer Forensic Solutions company, designs and manufacture computer forensic Mobil Platforms - high speed and high quality computer forensic imaging units - enabling computer forensic investigators in the lab or in the field, to capture data from many different kinds of media sources and interfaces in a very short period of time. The SuperImager Plus line of products, designed with extremely fast forensic imaging capabilities, and with a very strong hardware serve as platforms for a computer forensic investigator to perform many different kinds of operations in one place. The main unit functions capabilities are:

Under Linux:

  1. Parallel multi-sessions Forensic Imaging operations running under Linux with extreme speed that can reach up to 31GB/Min
  2. Capture data from Network Storages via iSCSI protocols
  3. Remote Capture
  4. S.M.A.R.T. test
  5. Virtual Drive Emulator


Under Windows:

  1. Complete data analysis using FTK, Encase, Nuix applications
  2. Cellphone data extraction and analysis with the use of a third-party application such as Celebrite, Oxygen, XRY and more
  3. Field Forensic Triage applications
  4. Network traffic analysis and more


The solutions are cost effective, with the use of a fast parallel simultaneous operation that save time and money. In one pass over a "Suspect" drive, a user can run E01 Forensic imaging utilizing 16 threads to perform extremely fast full compression, 3 HASH value, AES Encryption, and a binary keyword search.


The SuperImager Plux Linux application can performs at 15-20% faster speed than the SuperImager Windows application, especially when user runs E01 with compression


Training & Events

Sorry there are no training Courses offered by this Supplier.

SuperImager™ Plus 7

The unit can be used as a Field Forensic Imager, Cellphone data extractions and analysis, and Triage data collections.

The unit as Forensic Imager:

The SuperImager 7" Mini is very small, lightweight, and easy to carry, and it is the perfect tool to perform Forensic Imaging out in the field. It built with 7" Touchscreen color LCD display, 3 SATA ports (with secure and keyed SATA power connector), 4 USB3.0 ports, 1Gigabit Ethernet, and VGA port. It is affordable, and capable of performing extremely fast Forensic Imaging (Run SHA-1 hash authentication @ 30GB/min with use of Solid State Drive (SSD), 10GB/min with use of 1TB WD Blue Hard Disk Drive).

The unit as Forensic Imager:

The SuperImager Plus 7" Mini Forensic field unit is very small, lightweight, and easy to carry, and it is the perfect tool to perform Forensic Imaging out in the field. It built with 7" Touchscreen color LCD display, 3 SATA ports (with secure and keyed SATA power connector), 4 USB3.0 ports, 1Gigabit Ethernet, and VGA port. It is affordable, and capable of performing extremely fast Forensic Imaging (Run SHA-1 hash authentication @ 30GB/min with use of Solid State Drive (SSD), 10GB/min with use of 1TB WD Blue Hard Disk Drive).
The SuperImager application has the capabilities to perform in one read pass from the "Suspect" hard disk drive:
Forensic Imaging with E01 format and full compression, Encryption with AES256, 3 parallel hash authentication (MD5, SHA1, SHA2), a simple binary keyword search, and the ability of Saving Forensic Images to 2 external SATA Evidence Hard Disk Drives, External compact USB3.0/eSATA RAID encrypted storage device, and to a local Network.
With the use of 4 USB3.0 to SATA optional kit, user can covert 4 USB3.0 to SATA ports and use the SuperImager Plus 7" Mini Forensic Field unit with a total 7 SATA ports and perform forensic imaging of 2:5 (2 Suspect 5 Evidence)

As a Field Data Eraser unit:

User can erase hard disk drives and USB3.0 storage devices, by using the unit¡¯s 2 SATA ports and 3 USB3.0 ports. The application supports DoD erase, Security Erase, Enhanced Security Erase protocols which are NIST 800-88 compliance.

As a field Forensic platform:

Forensic investigator can load and run third-party applications such as Cellebrite, Oxygen, BlackBag, Paraben, or a Triage data collection applications such as Nuix, Encase, MPE+, all of which is done with excellent performance.

Optional External Battery:

An External Compact Battery Option is available: User can complete Forensic Imaging of WD 1TB hard disk drives (1:2) for around 2 hours, or perform a cellphone extraction and analysis for around 5 hours.

Dual Boot Option:

User can purchase the unit with only Linux OS for Forensic Imaging purpose. Dual Boot to Windows is optional for additional cost

For Data Capture Under Linux:

Perform Forensic Imaging under Linux for a faster, more efficient and a more secure operation

To Analyze the Captured Data Under Windows:

Reboot the unit to Windows, and use third-party applications to perform data analysis and other tasks

Network Multiple Forensic Images Loader- Unique feature solves 1Gigabit/s Port Bottleneck. User can upload many Forensic images directly to a local network using 5 equivalent 1Gigabit/s network streams


Case Study:

Compare Windows to Linux application with E01 format and full compression on a hard disk drive with 50% random data: Linux: E01 Non compressed average speed of 3.6GB/min, E01 compression average speed of 4.3GB/min. Windows application with the same data with E01 format compression average speed of 3.8GB/min, all runs were with SHA-1+MD5 hashing authentication enabled. The Linux application increased the speed over Windows by 13%

Application Setting

  • HPA/DCO Automatic Supports:¡¡The application has the ability to automatically open HPA and DCO areas, and resize the "Suspect" hard drive to its full native capacity, in order to capture any "hidden data" (HPA/DCO are special areas on the hard disk drive that support this feature)
  • Bad Sectors Handling: User can select to skip bad sectors/blocks, or abort the operation when it encounters bad sectors/block of sectors on the "Suspect" hard disk drive

Ports:

  • Forensic Images Destination: User can save Forensic Images to a local network shared folder for easy access and analysis, or save images to external USB3.0 RAID (encryption is optional) storage in a very good speed
  • Captured Storage Protocols and Interfaces: SAS, SATA, e-SATA enclosures, IDE, USB2.0, USB3.0, MMC
  • Form Factors: Capture data from various form factor devices: 3.5", 2.5", ZIF, 1.8", Micro-SATA, Mini-SATA
  • Cross Copy from Ports and Interfaces: The user can choose to capture from one type of port, storage protocol and interface, and save the forensic Images into a different port, storage protocol and interface. The cross copy of data can be done between SATA/IDE/USB interfaces

Application Features:

  • GUI: The application is built with large icons and is very simple and easy-to-navigate. In a few clicks user can set the operation, and it will be quickly up and running
  • Speed: Extremely fast
    • Tested with Hash verification operation with SHA-1 enabled the recorded top speed was 30GB/min with Solid State Drive, and 10GB/min with 1TB WD Blue SATA-3 Hard Disk Drive
    • Tested with Forensic Imaging operation of 1 to 2 with SHA-1 enabled the recorded sustained top speed was 29GB/min with 3 SSD of SanDisk 120GB Extreme II

  • Hash Authentication: Simultaneously calculates on-the-fly up to 3 Hash Authentication values MD5/SHA-1/SHA-2
  • Encryption: On-the-fly AES256 encryption of the "Suspect" Hard Disk Drive, saving the encrypted data on "Evidence" Hard Disk Drive in 100%, DD, E01/Ex01 formats
  • Keyword Search: Instantaneous binary keyword search on the "Suspect" Hard Disk Drives (not a Unicode match)
  • Forensic Images can be saved in those Formats: 100% Bit by Bit, Linux DD Format, Encase E01/Ex01 formats include options for optimized compression
  • Evidence Drive Formats: FAT, NTFS, exFAT, HFS+, EXT4
  • Log Files: Audit trail in PDF formats, or txt formats with ability to customize the reports and adding company Logo
  • Drive Spanning: Supports spanning the captured data onto many "Evidence" drives , when the Evidence drives are not large enough (Also supports restore from spanned multiple drives)

Main application Features:

  • Forensic Imaging Mode
  • Forensic Restore back data to original
  • Erase data from drives and Quick Format
  • Hash calculation authentication and verification

Main Forensic Imaging Mode Features:

  • Forensic Imaging Mode 100%, DD, E01/Ex01 ¨C with optional compression

SuperImager™ Plus 7
Name
Organisation
Phone
Email
Enquiry
Verification Code:
 
Contact us
Australia:+61 (0)2 8012 9810
Singapore:+65 9297 1289
Customer Service:
Technical Support:
Training Bookings:
 
Register For the Fulcrum Newsletter HERE

© Fulcrum Management 2012
Name
Email
Organisation
Phone
Verification Code:
Name
Email
Organisation
Phone
Verification Code: