MSI Mini Portable Drive Imaging Unit
The MSI Plus Mini Forensic unit is a Portable forensic imager with the ability to perform multiple Forensic tasks, allowing the Forensic investigator to capture data in the field from multiple source drives to multiple target drives simultaneously and extremely fast. It also enables the user capture data from multiple cellphones and run cellphone analyses, or any third-party application. The unit is compact and easy to carry, with built-in 3 SATA (with a secure and keyed SATA power connector) and 4 USB3.0 ports, 1 port of 1Gigabit/s Ethernet, and 1 port of HDMI.
The MSI’s main application (the unit’s software) supports many imaging methods like Mirror Image, Encase E01/Ex01, and Linux-DD. Here are some of the tasks that the unit can be used for:
- Multiple Parallel Forensic Capture: Mirror (bit by bit), Linux-DD, E01/Ex01 (with full compression) formats, Mixed-Format DD/E01, and Selective Capture (files and folders with the use of file extension filters). Select a single partition to capture.
- Erase data from Evidence drive - using DoD (ECE, E), Security Erase, Enhanced Security, or Sanitize erase protocols.
- View the data directly on the Ubuntu Desktop screen.
- Encrypt the data while capturing (using the AES256 engine).
- HASH the data while capturing – run all the three, SHA-1, SHA-2, and MD5 HASH engines, at the same time.
- Run a quick Keyword Search on the Suspect drive prior to capture.
- Run Multiple Cellphone/Tablets data Extraction and Analysis using a third-party application on the Windows 10 side.
- Run Forensic Triage application using a third-party application on the Windows 10 side.
- Run Virtual Drive Emulator prior to the data being captured on the Linux side.
- Run Remote Capture from unopened laptops (Intel ased CPU).
Additional operations that are available include HASH a drive, drive diagnostics, and scripting.
The application supports forensic imaging of multiple drives, in multiple sessions, in simultaneous forensic imaging runs.
- For Data Capture: Perform Forensic Imaging under Linux for a faster, more efficient and a more secure operation
- To Analyze the Data Captured:Reboot the unit to Windows
- Use third-party applications to perform data analysis, or cellphone extraction
Fast & Affordable
- Aquire data from:
- HDD: SATA/IDE
- Multi-Media Cards
- USB Storage devices
- M.2 NVMe (via USB)
- Captures data from digital storages devices with many types of form factors and interfaces
- Previews data from “Suspect” HDD in a secure environment
- Captures and saves across many ports and interfaces
- Includes easy navigation, and display of the multiple sessions
- Forensic Imaging SATA 1:1, 1:2
- Forensic Imaging USB3.0 1:1 up to 2:2
- The application is flexible in assigning role of Source/Target for Evidence port
- Simultaneously calculate three authentication Hash values: MD5/SHA1/ SHA2
- Encryption/Decryption with AES 256 on-the-fly
- Forensic Imaging modes: bit by bit, Linux-DD files, E01, EX01
- Remote Capture Data from an un-open Laptop Via USB or Network ports
- Supports “Evidence” drive formats: NTFS/exFAT/EXT4/HFS+
- Save Forensic Images to Network, or Capture from Network via iSCSI storage protocols
- Supports SATA, e-SATA, USB, IDE, Micro-SATA, Mini-SATA, M.2( NGFF) storage devices
- Use USB3.0 to SATA adapters to converts
The user can perform in a single run:
- Forensic Imaging with DD/Ex01/E01 formats, and with E01 full compression
- Simultaneously calculate 3 Hash values: MD5, SHA-1, SHA-2
- Encryption/Decryption with AES256
The unit Operates as a Platform:
- Load and use a third-party Cell phone data extraction and analysis tools
- Triage data collection tool
- Writes Protects CF cards and Multi-Media Cards
- Use the unit as a “Write Blockers” bridge, for any attached storage to the unit.
** Optional External Lithium-Polymer Battery
|Main Hardware Features:|
|CPU:||i7 Latest Generation Quad Core Mobile CPU|
|Display:||10”, LED back-light, touchscreen, color LCD display.|
|8 Channel HDD Open Tray:||Easy to insert and plug tray that accommodates any size and shape of SAS/SATA drives or storage devices; contains power status LED indicators.|
|Hardware:||Very high-quality, high performing components; some with military specifications|
|Dual Boot (included):||
|Security:||Linux OS (Linux is less targeted by malware).|
|Application Updates:||The application can easily be updated via USB thumb drive and displays a special update application screen.|
|Hardware Upgrade:||The unit can be upgraded at the time of purchasing for additional cost to a larger internal SSD.|
|RAM:||32GB DDR4 internal memory|
|Storage controller:||SATA controller on the main board with a maximum data rate of 37GB/min.|
|Internal Storage:||250GB SSD|
|Source Ports:||One NVMe port, and two USB3.0/USB3.1 ports are set as source ports (the user cannot change the role of these ports).|
|Supports Storage Protocols and Interfaces:||NVMe (M.2 U.2, PCIE), SATA, e-SATA enclosures, IDE, USB2.0, USB3.0/3.1, MMC, and M.2 SATA.|
|Supports Form Factors:||3.5”, 2.5”, ZIF, 1.8”, Micro-SATA, Mini-SATA, Slim SATA, Ultra Slim SATA, M.2 SATA, CF-30, NVMe U.2 2.5” and M.2. *With Optional controllers plugged into the Expansion Box.|
|Target Ports:||4 SATA ports, 3 NVMe ports, one e-SATA port, and 6 USB3.0/USB3.1 ports. In addition, the 4 e-SATA ports on the expansion box are set as target ports as well.|
|HPA/DCO Automatic Supports:||The application has the ability to automatically open HPA and DCO areas and re-size the drive to its full native capacity in order to erase any “hidden data” (HPA/DCO are special areas on the drive that support this feature).|
|Bad Sectors Handling:||The user can select to skip bad sectors/blocks or abort the operation when it encounters bad sectors/blocks on the source drive.|
|48bit LBA Addressing:||Supports drives with sizes up to 256TB.|
|Forensic Images - Destination:||The user can save Forensic Images to any storage device attached to the SuperImager unit, or to any connected network, using the unit’s 1Gigabit/s port, the 10Gigabit Option, any external USB3.0 RAID (encryption is optional), or an external NAS storage at a very good speed.|
|Cross Copy from any Ports and any Interfaces:||The user can choose to capture from one port, with one type of storage protocol and interface, and save the forensic image onto a different storage protocol and interface using destination ports. The cross copy of data can be done between any of these interfaces – NVMe/SATA/IDE/USB3.0/3.1.|
|GUI:||The application is built with large, very simple, and easy-to-navigate icons. In a few clicks, the user can set the operation, and it will quickly start up and run.|
|Application Main Operation:|
Forensic Imaging Mode:
|Expansion Capabilities and Main Hardware Options:||
- Very small form factor, portable, easy to carry
- 3 SATA ports for Forensic Imaging 1:2
- Dual boot Linux/Win10
- multiple cellphone data extraction using Win10 and multiple USB ports