Data-Acquisition-and-Duplication-Tools-Hardware

Data Acquisition and Duplication Tools: Hardware

Data Acquisition and Duplication Tools: Hardware in this article discussed below are the featured data acquisition and duplication hardware tools can be used to acquire and create duplicate copies of the suspect system data:

1. Ultrakit

Source: http://www.digitalintelligence.com

The UltraKit is a portable kit, which provides a complete set of UltraBlock hardware write blockers including adapters and connectors to acquire a forensically sound image of virtually any hard drive or storage device. Just select the relevant Write Protected UltraBlock and attach it to the source drive and use the desktop or laptop to create a forensically protected disk image to an internal drive or externally connected drive enclosure.

2. Forensic Falcon

Source: http://www.logicube.com

Forensic Falcon is a power-rich performance, feature-packed forensic tool which provides expandability to support future digital forensics technological advances. It achieves 23GB/min imaging speed.

Features;

  • Image & verify from 4 source drives to 5 destinations
  • Preview suspect drive contents directly on the Falcon
  • Image to/from a network location
  • Remote operation with a web-based browser interface
  • Parallel Imaging, Image a source drive to multiple destination drives using different imaging formats

Related Product : Computer Hacking Forensic Investigator | CHFI

Data Acquisition and Duplication Tools: Hardware (Cont’d)

Discussed below are few more featured data acquisition and duplication hardware tools can be used to acquire and create duplicate copies of the suspect system data:

1. T3iu Forensic SATA Imaging Bay

The Tableau T3iu Forensic SATA imaging Bay is designed for fast write-blocked acquisitions of 3.5″ and 2.5″ SATA hard drives and for easy integration into workstations using a single SuperSpeed USB 3.0 host connection.

The data transfer bandwidth of USB 3.0 allows system integrators to scale SATA imaging capability of workstations by including multiple T3iu units. The T3iu is a cost effective way to eliminate SATA imaging backlog. The T3iu is a package consisting of three forensic products, a high-performance AT write blocker, a suspect drive cooler and a suspect drive tray,

2. Triage-Responder

Source: http://www.adfsolutions.com

Triage-Responder is designed particularly for nontechnical first responders. It uses an easy two-step process to scan, analyze and extract evidence from a digital device. It searches the whole target drive in four categories and integrates different technologies, like, ActivitySensor™, which enables the investigators to find and collect valuable files quickly.

The Triage-Responder Kit consists of:

  • One portable mini travel case
  • One 326B high-speed USB key
  • One boot CD
  • One plastic teasing needle

3. XRY Office

Source: https://www.msab.com

XRY Office provides both logical and physical support for mobile forensic examiners. It provides full access to thousands of mobile devices with all the required tools supplied. XRY is a software based solution and is built for a purpose with all the required hardware to recover data from mobile devices in a secure way.

It can implement the following functions:

  • SIM Card Reading
  • GP5 Device Physical Examinations
  • Mobile Device Physical and Logical Examinations
  • Memory Card Physical Examinations
  • HEX Viewer
  • Triage Mode
  • Find Functions & Watch List
  • Hash Algorithms

4. Atola Insight Forensic

source: http://atola.com

Atola Insight Forensic provides complex data retrieval functionalities with utilities for accessing hard drives at the lowest level, wrapped in an efficient user interface. The tool is designed by recovery engineers, law enforcement agencies, and forensic experts.

Atola Insight Forensic system consists of:

  • Atola insight Forensic software (runs on any Windows PC or laptop)
  • DiskSense hardware unit
  • Hardware extensions

Features:

  • High-performance multi-pass imaging for damaged drives
  • Supports various hash calculation: MD5, SHA1, SHA224, SHA256, SHA384, SHA512
  • Enables file recovery for NTFS (all versions), Ext 2/3/4, HIS, HF54, HISX, ExFAT, FAT16, FAT32
  • Includes built-in write blocker

Also Read : Data Acquisition Methods

5. US-LATT PRO

Source: https://wetstonetech.com

US-LATT PRO implements live acquisition and triage of Microsoft’s’ Windows systems (XP ­Windows 8). It offers the ability to the investigators to triage live evidence with fast and efficient on scene investigations.

6. IM Solo-4 G3 Forensic Enterprise Super Kit

Source: http://ics-iq.com

The image MASSter Solo-4 G3 PLUS Forensic Enterprise Super Kit is a drive data acquisition unit with i7 Processor and ExpansionBox hardware configuration. It provides the ability to the investigators to simultaneously extract data from suspect to evidence hard drives at SATA-3 speed. It can also acquire data from two separate suspect hard drives to two individual evidence hard drives.

7. ROADMASSTER-3 X2

Source: http://ics-iq.com

The RoadMASSter-3 X2 provides the forensic examiner with a powerful and flexible platform for forensic data capture and analysis. It is a portable lab built as a rapid forensic data acquisition and analysis workstation. It is ruggedized and has all the required tools to collect the data from drives.

8. TD2u Forensic Duplicator

TD2u Forensic Duplicator is designed for both field and lab forensic environments. It offers easy operability, reliability, and fast forensic imaging performance. It images at a speed of 15B/min while simultaneously calculating MD5 and.SHA-1hashes.

9. Disk Imager Forensic Edition

Source: http://www.deepspar.com

DeepSpar Disk Imager Forensic Edition is a portable forensic imaging tool. It allows the examiners to view the imaging process to see the read status of each retrieved sector and what data and what type of files are being imaged. Failing hard drives are imaged using very few passes to get maximum information. It reduces the time taken to image bad sectors disks.

10. Disk Jockey PRO

Source: http://www.diskology.com

The Disk Jockey PRO is a disk copy and write blocking toot developed for computer forensics. It is capable of copying the Drive Configuration Overlay (DO} areas and Host Protected Area (H PA) of a hard disk drive. It can work on Windows or Macintosh systems connected via high­speed USB 2.0 ports, or it can be used as a standalone unit. It can also be used to mount drives to the desktop, copy data between hard disks quickly, verify, test and erase hard disks.

11. RAPID IMAGE 7020 X2 IT

Source: http://ics-iq.com

The Rapid Image’ Hard Drive Duplicators are built to copy a single master hard drive to up to 19 target hard drives at ATA-III Speeds. It can also be configured to copy multiple master drives simultaneously. It can also copy and sanitize drives simultaneously with minimum speed degradation.

11. ZClone Xi

Source: http://www.logicube.com

The DO is a duplicator, it provides advanced features like fast cloning, task macros networking and user profiles along with an easy to use interface. It supports mirror cloning, a 100% bit for bit copy, as well as a CleverCopy mode that copies only data areas. It can also sanitize hard drives safely.

12. HardCopy 3P

source: http://www.digitalintelligence.com

It is a portable Forensic Hard Drive Duplicator with MD5, SHA256, and an integrated IDE port. It offers up to 7.5 GB Per Minute Data Transfer Rate. It offers two duplication Modes.

  • Clone mode: block by block copy of the whole drive; block locations are identical to source
  • Image mode: block by block copy (dd image) of the whole drive into a single file or chunked files.

13. Forensic Tower IV Dual Xeon

Source: http://www.forensiccomputers.com

The Forensic Tower IV Dual Xeon sets a standard for forensic laboratory systems. it consists of a case of ten 5.25-inch bays to provide flexibility in configuring a lab system to fulfill client requirements. It is compatible with all commercial forensic acquisition and analysis software such as EnCase, ProDiscover, Forensic Tool Kite, and P2 Commander.

14. FREDDIE

Source: http://www.digitalintelligence.com

FREDDIE is a portable mobile forensic tool with flexible, integrated, and modular forensic platform built for computer evidence acquisition and analysis. First, remove the hard drive(s) from the subject computer and attach into FREDDIE to extract evidence. This tool can directly gather data from IDE, POE, ATA, SATA, ATAPI, SAS, USB or Firewire hard drives and other storage devices,

15. PRO Data Extractor

Source: http://www.deepspar.com

PC-3000 Data Extractor detects and fixes file system issues. It collaborates with PC-3000 hardware to recover data from any media, such as, IDE FIDD, SCSI HDD, and flash memory readers. Using algorithms this tool performs logical file recovery to rectify file system structure problems or retrieves data by implementing a sector-by-sector search for header files independent of the OS.

16. Project-A-Phone

Source: http://www.project-a-phone.com

This tool helps to take high-quality screenshots of any device. It has 8-megapixel camera to take clear pictures of the display of the device. This camera connects to the computer to capture a clear screenshot. HD quality videos can also be recorded using this tool. A license of P2CC is issued for this tool for advanced reporting, including hash value validation.

17. Mobile Field Kit

Source: http://forensicstore.com

Paraben’s Mobile Field Kit is a portable handheld forensic product. The kit contains all the equipment required to perform a digital forensic analysis of more than 4,000 cell phones, GPS devices, and PDAs.

18. iRecovery Stick

Source; https://www.paraben.com

The iRecovery Stick has special investigation software on a USB drive, which enables to investigate data on iPhones and other Apple mobile devices. It can also restore deleted data like iMessages, text messages (SMS), call history, contacts, calendar entries, and internet history.

19. UFED Touch

Source: http://www.cellebrite.com

It is a standalone mobile forensic extraction device. It has an easy to use the touchscreen and an instinctive GUI. This tool allows file system, physical and logical extractions of all data from a wide range of mobile devices.

20. UFED Pro Series

Source: http://www.cellebrite,com

Cellebrite develops UFED Pro Series for forensic investigators. They require mobile data extraction and decoding took, which helps to extract valuable data, combine different data to visualize necessary connections, speed up investigations, and identify evidence.

21. FRED

Source: http://www.digitalintelligence.com

FRED systems built for stationary forensic laboratory acquisition and analysis. First, remove the hard drive(s) from the subject system and attach into FRED to extract digital evidence. This tool will get the data directly from IDE, EIDE, ATA, SATA, ATAPI, SAS, Firewire or USB hard drives and save forensic images to CD, Blu-Ray, DVD, or hard drives. This tool can also gather data from CD-ROM, DVD-ROM, Blu-Ray, Micro Drives, Compact Flash, Memory Stick, Smart Media, xD Cards, Memory Stick Pro, Multimedia Cards, and Secure Digital Media.

22. Ditto Forensic FieldStation

Source: https://www.cru-inc.com

The Ditto Forensic FieldStation is a portable forensic tool used to create local, remote or networked disk clones and images. It also helps to log user activity and preserve the chain of custody while using forensic write-blocked methods.

23. Forensic UltraDock

Source: https://www.cru-inc.com

Forensic UltraDock is used to view, evaluate, and image a disk drive safely. It is a professional drive dock that allows multiple hosts and drives connection types. It automatically detects and notifies hidden areas of the drive and also supports common types of drives like SATA and IDE/PATA.

Questions related to this topic

  1. What is data acquisition hardware?
  2. What are data acquisition tools?
  3. What two data copying methods are used in software data acquisitions?
  4. What is data acquisition in digital forensics?

This Blog Article is posted by

Infosavvy, 2nd Floor, Sai Niketan, Chandavalkar Road Opp. Gora Gandhi Hotel, Above Jumbo King, beside Speakwell Institute, Borivali West, Mumbai, Maharashtra 400092

Contact us – www.info-savvy.com

https://g.co/kgs/ttqPpZ

Leave a Comment