MSI Desktop NVMe - SATA Forensic Imaging Unit
The MSI Plus Desktop NVMe + SATA Forensic unit is a standalone forensic imager with the ability to perform multiple Forensic tasks, allowing the Forensic investigator to capture data in the Lab from multiple source drives to multiple target drives simultaneously and upload them to a network extremely fast. It also enables the user to perform a full Forensic analysis using encase, Nuix Windows 10 application, or capture data from multiple cellphones and run cellphone analyses, or use any third-party Windows application. The unit is industrial and durably built, using a desktop-style, with easy to use touchscreen icons. The unit has built-in 4 ports of NVMe, 4 ports of SATA, and 8 ports of USB3.0/3.1.
The MSI’s main application (the unit’s software) supports many imaging methods like Mirror Image, Encase E01/Ex01, and Linux-DD.
Forensic Lab Unit (Linux) Features
- Captures data from digital storages devices with many types of form factors and interfaces(2.5”, 3.5”, ZIF, MSATA, MicroSATA, M.2 SATA, Ultra SATA, Slim SATA, NVMe U.2/ M.2)
- USB3.0 ports can be converted to SATA ports with the use of USB3.0 to SATA adapters (use of 4 ports USB KIT)
- Previews data on the “Suspect” drive in a secure environment
- Captures and copy across many ports and interfaces
- Simultaneously calculates HASH values with all the 3 algorithms MD5/SHA1/SHA2 at the same run
- Automatic support for DCO/HPA special areas
- Supports Bad Sector Handling (with 3 types of reporting)
- Encryption/Decryption with AES256 on-the-fly
- Supports capture mode of 100% bit by bit copy, Linux-DD files, E01, EX01 with full compression, E01/DD Mix mode where each of the target port can be a mix of DD or E01
- Supports targeting imaging, partition imaging
- For Automated process, use Scripting
- Use the unit as “Write blocker “ Bridge between any storage attached to the unit and the network
- Designed to work with touch screen display, with easy navigation icons & screens
- Image 2:2 NVMe, 2:2 SATA, 4:4 USB3.0, 1:1 USB3.1 storages.
- Forensic capture: Mirror, DD, E01, Mix DD/E01
- Selective Capture of files and folder, or Partition
- Keyword Search with 2 modes: Before the data capture or during the data capture
- Optimized for Multi-Core CPU with multi-threading to achieves extreme speed, especially when running E01 compression
- Flexibility in re-assigning the role of Evidence port to be Suspect port.
- Run mix operations at the same time such as HASH, Erase, Capture all in multiple simultaneous sessions
- Easy to switch the screen to an upload mode, where all the 8 ports assigned to be source ports
*Validated speed of 93.7G/min by using Samsung MZVPV512HDGL NVMe SSD
Here are some of the tasks the unit can be used for:
- Multiple Parallel Forensic Capture: Mirror (bit by bit), Linux-DD, E01/Ex01 (with full compression) formats, Mixed-Format DD/E01, copy the whole drive or only parts
- Run a Selective Imaging (Targeted Imaging) of files, folders, and partitions with file extensions filters (for example, run 8 independent sessions of E01 capture with 16 native SAS/SATA ports and 16 E01 compression engines simultaneously).
- Perform Forensic Imaging from many Suspect drives to one large Evidence drive; in append mode (can perform forensic imaging from 15 Suspect drives to one large Evidence drive).
- Upload many Forensic images to a network (SMB, CIFS, NFS).
- Erase data from Evidence drive - using DoD (ECE, E), Security Erase, Enhanced Security, or Sanitize erase protocols.
- View the data directly on the Ubuntu Desktop screen.
- Encrypt the data while capturing (using the AES256 engine).
- HASH the data while capturing – run all the three, SHA-1, SHA-2, and MD5 HASH engines, at the same time.
- Run a quick Keyword Search on the Suspect drive prior to capture.
- Run Multiple Cellphone/Tablets data Extraction and Analysis using a third-party application on the Windows 10 side.
- Run Forensic Triage application using a third-party application on the Windows 10 side, prepare Forensic Triage keys, and view the captured targeted data.
- Run a full Forensic Analysis application like Encase/Nuix/FTK.
- Run Virtual Drive Emulator prior to the data being captured on the Linux side (this option is enabled on this unit).
- Encryption and Decryption on the fly of drives that contain sensitive information.
- Easily reconfigure the unit’s ports, where each of the target port can be configured as source or target for running 8:8 sessions, or to run an upload of 16 storages to a network.
- Convert the unit’s 10 USB3.1 ports to SATA ports and run more parallel sessions (with the use of some USB3.0 to SATA adapters).
- New feature - Use the MSI unit as a “Write Blocker” device: This new feature enables the MSI unit to function as a secure bridge between workstations on a network to Suspect drives attached to the MSI unit by using the iSCSI protocol over a network connection.
A forensic investigator using a workstation or laptop in one location can access a Suspect drive in different locations in the Write block mode. The unit is not expandable.
The MSI unit will be connected to the same network and the Suspect drives will be attached to the MSI unit in read-only mode. The MSI unit will act as a “write blocker” for any of the unit’s attached storages, such as: SAS, SATA, USB, 1394, FC, SCSI, and NVMe.
The unit is designed to help expedite the forensic imaging process, especially in facilities where there is a large backlog in imaging drives, by performing many parallel forensic imaging in a true optimized multiple session's application. The advantage of this unit is that it supports imaging from mix media of SAS/SATA/USB.
|Main Hardware Features:|
|CPU:||i7 Latest Generation Quad Core Mobile CPU|
|Display:||10”, LED back-light, touchscreen, color LCD display.|
|8 Channel HDD Open Tray:||Easy to insert and plug tray that accommodates any size and shape of SAS/SATA drives or storage devices; contains power status LED indicators.|
|Hardware:||Very high-quality, high performing components; some with military specifications|
|Dual Boot (included):||
|Security:||Linux OS (Linux is less targeted by malware).|
|Application Updates:||The application can easily be updated via USB thumb drive and displays a special update application screen.|
|Hardware Upgrade:||The unit can be upgraded at the time of purchasing for additional cost to a larger internal SSD.|
|RAM:||32GB DDR4 internal memory|
|Storage controller:||SATA controller on the main board with a maximum data rate of 37GB/min.|
|Internal Storage:||250GB SSD|
|Source Ports:||One NVMe port, and two USB3.0/USB3.1 ports are set as source ports (the user cannot change the role of these ports).|
|Supports Storage Protocols and Interfaces:||NVMe (M.2 U.2, PCIE), SATA, e-SATA enclosures, IDE, USB2.0, USB3.0/3.1, MMC, and M.2 SATA.|
|Supports Form Factors:||3.5”, 2.5”, ZIF, 1.8”, Micro-SATA, Mini-SATA, Slim SATA, Ultra Slim SATA, M.2 SATA, CF-30, NVMe U.2 2.5” and M.2. *With Optional controllers plugged into the Expansion Box.|
|Target Ports:||4 SATA ports, 3 NVMe ports, one e-SATA port, and 6 USB3.0/USB3.1 ports. In addition, the 4 e-SATA ports on the expansion box are set as target ports as well.|
|HPA/DCO Automatic Supports:||The application has the ability to automatically open HPA and DCO areas and re-size the drive to its full native capacity in order to erase any “hidden data” (HPA/DCO are special areas on the drive that support this feature).|
|Bad Sectors Handling:||The user can select to skip bad sectors/blocks or abort the operation when it encounters bad sectors/blocks on the source drive.|
|48bit LBA Addressing:||Supports drives with sizes up to 256TB.|
|Forensic Images - Destination:||The user can save Forensic Images to any storage device attached to the MSI unit, or to any connected network, using the unit’s 1Gigabit/s port, the 10Gigabit Option, any external USB3.0 RAID (encryption is optional), or an external NAS storage at a very good speed.|
|Cross Copy from any Ports and any Interfaces:||The user can choose to capture from one port, with one type of storage protocol and interface, and save the forensic image onto a different storage protocol and interface using destination ports. The cross copy of data can be done between any of these interfaces – NVMe/SATA/IDE/USB3.0/3.1.|
|GUI:||The application is built with large, very simple, and easy-to-navigate icons. In a few clicks, the user can set the operation, and it will quickly start up and run.|
|Application Main Operation:|
Forensic Imaging Mode:
|Expansion Capabilities and Main Hardware Options:||
- 4 NVMe U.2 ports and 4 SATA ports
- Built with l i7 11 generation (not embedded CPU), which bring performances to maximum
- Imaging from NVMe to SATA and vice versa, NVMe to NVMe at blazing speed