FZXI Drive Cloning, Erasing & Forensic Imaging
Digital forensic labs that routinely handle large amounts of evidence data for review or analysis can take advantage of the FZXI-Forensic’s three Gigabit Ethernet ports, fast imaging speeds of up to 50GB/min and advanced features to streamline processes. The solution’s Push feature allows users to upload images from up to 3 evidence drives directly to a network repository simultaneously. Add the optional 3 drive expansion kit to push up to a total of 5 evidence drives. The FZXI Forensic’s ability to image up to 3 source/suspect drives directly to a network repository and at the same time image to 6 destination/evidence drives (when you add the optional expansion kit) provides efficiency and quick access to forensic evidence data.
- Extreme speed, imaging at over 50GB/min*
- Designed for digital forensic labs
- Three Gigabit Ethernet ports
- Network “Push” feature to upload images to a network repository from 3 evidence drives simultaneously
- Image from 3 suspect drives to a network repository or to 3 evidence drives simultaneously Secure sensitive evidence data with whole disk, open standard, drive encryption using the NIST recommended XTS-AES-256 cipher mode, decrypt using the FZXI-Forensic or Veracrypt
- Optional expansion kit adds 3 additional destination drives
- High speed imaging at over 50GB/min*
- Multi-target, volume imaging: Image from 3 suspect drives simultaneously to network repositories using 3 Gigabit Ethernet connections; image from 3 source drives directly to 3 destination drives; image from 3 source drives to network repositories and simultaneously image to 3 destination hard drives. Use the optional expansion kit to add 3 additional destinations.
- Supports dd, ex01, e01 or native imaging formats. User selectable MD5 or SHA-1 or SHA-256 verification is available.
- Use the Network Push feature to upload evidence drive images that were captured using the Forensic Falcon or the FZXI-Forensic to a network repository. Push from up to 3 evidence drives simultaneously or add the optional expansion kit and push from up to 5 evidence drives. An MD5 or SHA-1 hash is performed during the process and a log file is generated for each push task.
- Image to or from a network location. Use the FZXI-Forensic to image to a network location using CIFS protocol and/or image from a network location using iSCSI. Users can use iSCSI as a source or destination drive.
- Supports imaging to and from USB enclosures and USB thumb drives. 1 USB 3.0 source port and 2 USB 3.0 destination ports are available.
- Write-protected source drives. All FX-AIO-Forensic source ports are automatically write-blocked to prevent any alteration to sensitive data on the source drive.
- The FZXI-Forensic has built-in support for 3.5”/2.5” SAS or SATA hard drives. 1.8”/2.5”/3.5” IDE and IDE ZIF drives, M.2 PCIe (SATA & AHCI types), eSATA, microSATA, mSATA and compact flash media are supported with optional adapters.
- Optional 3 drive expansion kit provides an additional 2 SAS/SATA and 1 SATA for a total of 6 SATA or 5 SAS destinations.
- Remote Operation. Connect the FZXI-Forensic to your network and allow remote access from any computer within the same network. A web-based browser interface provides easy navigation.
- Write-blocked preview/triage of hard drive contents. Preview/triage the drive contents directly on the FZXI-Forensic. The file browser feature provides logical access to source or destination drives connected to the FZXI-Forensic. Users can view the drive’s partitions and contents, and view text files, jpeg, PDF, XML, HTML files. Other files types (such as .doc and .xls) can be viewed by connecting FZXI-Forensic to a network and via a workstation, download and view. Users can also use an iSCSI or SMB protocol to preview source drives via the network
- Wipe feature. Sanitizes hard drives to DoD 7-pass specification, offers Secure Erase and custom pass settings.
- Network services. Users can disable various network services (such as HTTP, SSH, Telnet, CIFS/NETBIOS, iSCSI, Iperf and Ping) for security purposes.
- Image from a desktop or laptop PC without removing the hard drive. Create a forensic bootable USB flash drive that allows the user to image a source drive from a computer on the same network without booting the computer’s native operating system.
- Parallel Imaging. Perform multiple imaging tasks from the same source drive to multiple destinations using different imaging formats.Image (e01, ex01 or dd) to a network location while simultaneously cloning to a destination drive.
- Concurrent Image+Verify. Imaging and verifying concurrently takes advantage of destination hard drives that may be faster than the source hard drive. The duration of the total image+verify process time may be reduced by up to half.
- The FZXI-Forensic can perform a forensic,filter-based file copy. Filter and then image specific file types by file extension such as .PDF, .doc, .jpeg, .mov, etc.
- Secure sensitive evidence data with whole disk, open standard, drive encryption using the NIST recommended XTS-AES-256 cipher mode. Decryption can be performed using the FZXI-Forensic or by using open source software programs such as FreeOTFE or TrueCrypt.
- Removable drive stations are field replaceable
- Task Macro feature. Set specific tasks to be performed sequentially, for example, image from source drives to destination drives and then push to a network repository. Set-up your Macro, press start and all tasks within the Macro will be performed automatically.
- Features an internal, removable storage drive that stores O/S and audit trail/logs. The drive is easily removed for secure/classified locations.
- Audit Trail/Log files provide detailed information on each operation. Log files can be viewed on the FZXI-Forensic or via a web browser, exported to XML, HTML or PDF format to a USB enclosure. Users can print the log files directly from their PC when connected to FZXI-Forensic via a web browser.
- Additional features include HPA/DCO capture, drive “trim” feature to manipulates the DCO and HPA areas of destination drives, the ability to set password-protected user profiles and save configurations, drive “timeout” feature automatically puts drives in stand-by mode after a specified idle time, drive spanning, a 7” color touch screen display, on-screen keyboard, four USB 2.0 host ports for mouse or printer connectivity and an HDMI port to connect a projector or monitor.
The following options are available with the FZXi forensic:
|In the box:
The following items are included with the FZxi Forensic
|32°- + 122°F
0° to 50°c
|-4° to +176°F
(-20° to +80°C)
|Operating: 85% RH, non-condensing
Storage: 95% RH, non-condensing
|3.7”H X 19”D X 17.2”W
9.39cm X 48.26cm X 43.68cm
- Fast imaging speeds of over 50GB/min
- 3 Gigabit Ethernet ports
- Network Push feature to upload images to a network repository from 3 suspect drives simultaneously