MSI Plus Forensic Portable Unit NVMe and SATA mix ports
The MSI Plus 3 NVMe + 7 SATA Forensic unit is a Portable forensic imager with the ability to perform multiple Forensic tasks, allowing the Forensic investigator to capture data in the field from multiple source drives to multiple target drives simultaneously and extremely fast. It also enables the user to perform a full Forensic analysis in the field using encase, Nuix application for Windows 10, or capture data from multiple cellphones and run cellphone analyses, or use any third-party Windows application. The unit is compact and easy to carry, with built-in 2 ports of NVMe (U.2) and 1 NVMe M.2, 2 ports of SATA3 (with a secure connector), 1 port of e-SATA, 8 ports of USB3.0, 1 port of Thunderbolt 3.0 (40Gigabit/s), and it is supplied with a Thunderbolt 3.0 Expansion box with 4 e-SATA ports.
The MSI’s main application (the unit’s software) supports many imaging methods like Mirror Image, Encase E01/Ex01, and Linux-DD.
Here are some of the tasks that the unit can be used for:
- Multiple Parallel Forensic Capture: Mirror (bit by bit), Linux-DD, E01/Ex01 , copy the whole drive or only parts. Copy 1:6/2:4/3:3 for SATA drives, 1:1, 1:2 NVMe drives, or any mix between the 3 NVMe ports to 7 SATA ports or 8 USB3.0 ports.
- Run a Selective Imaging (Targeted Imaging) of files, folders, and partitions with file extensions filters.
- Erase data from Evidence drive - using DoD (ECE, E), Security Erase, NVMe, and Sanitize erase protocols.
- View the data directly on Ubuntu Desktop screen.
- Encrypt the data while capturing (AES256).
- HASH the data while capturing – run all the three, SHA-1, SHA-2, and MD5 HASH engines, at the same time.
- Run a quick Keyword Search on the Suspect drive prior to capture.
- Run Multiple Cellphone/Tablets data Extraction and Analysis.
- Run Forensic Triage application.
- Run a full Forensic Analysis application like Encase/Nuix/FTK.
- Run Virtual Drive Emulator prior to the data being captured on the Linux side (this option is enabled on this unit).
- Run Remote Capture from unopened laptops - Intel Based CPU (supplied with this unit).
- Use the Thunderbolt 3.0 port to capture data from USB3.1 storage devices, Mac via Thunderbolt 2/3 port or 1394 port.
- New feature - Use the MSI unit as a “Write Blocker” device: This new feature enables the MSI unit to function as a secure bridge between workstations on a network to Suspect drives attached to the MSI unit by using the iSCSI protocol over a network connection. A forensic investigator using a workstation or laptop in one location can access a Suspect drive in different locations in the Write block mode. The MSI unit will be connected to the same network and the Suspect drives will be attached to the MSI unit in read-only mode. The MSI unit will act as a “write blocker” for any of the unit’s attached storage, such as: SAS, SATA, USB, 1394, FC, SCSI, and NVMe.
Additional operations that are available include erase verification on a drive that was previously erased, Full or Quick Format, HASH a drive, drive diagnostics, and scripting. The application supports forensic imaging of multiple drives, in multiple sessions, in simultaneous forensic imaging runs.
The unit is supplied with 2 NVMe U.2 to M.2 adapters, 2.5” NVMe cables, and a TB3.0 to PCIE Expansion Box with 4 e-SATA ports, 1 M.2 NVMe controller, Remote capture KIT, and Virtual Emulators option is enabled.
Forensic Imaging of 1:2 NVMe and 3:3 SATA at the same time
- High data transfer rate when running E01 compression - using 16 Parallel Engines
- Support Selective Imaging of Files and Folders
- Virtual Drive Emulator
- Remote Capture KIT: Capture from Un-Open Laptops and PC
Features
- Captures data from storages devices with many types of form factors and interfaces(2.5”, 3.5”, ZIF, M.2, mSATA, Micro SATA,Ultra-slim SATA) and interfaces: SATA, IDE (with adapters), M.2 SATA, M.2 NVMe, U.SB2.0, USB3.0, SD, SAS***, SCSI***, 1394***
- USB3.0 ports can be converted to SATA ports with the use of USB3.0 to SATA adapters (4 Channel KIT)
- Previews data on the “Suspect” drive in secure environment using Linux or Windows
- Captures and saves images across many ports and interfaces
- Basic captures modes: SATA 1:5/2:4/3:3, NVMe* 1:1
- Supports capture modes: % (adjustable) bit by bit Mirror copy, Linux-DD files, E01, EX01 with up to 16 compression engines
- Targeted Imaging: Select Files and Folders to capture data very quick
- Forensic image from multiple “Suspect” drives to one large “Evidence” drive
- The application is flexible in assigning role of Source for Evidence port
- Encryption with AES256 on-the-fly and decrypt at remote location
- Supports save Images (DD, E01) to Network (NFS, CIFS, SAMBA) and capture from a Network via iSCSI storage protocols.
- Remote-Capture data from an un-open Laptop/PC Via USB or Ethernet ports
- For more NVMe ports: The user can plug M.2 NVMe Adapter in the TB3.0 Expansion Box
- Optional with additional 4 SAS Ports controller plugged in the TB3.0 Expansion Box
Dual Boot Option
-
For Data Capture
- Perform Forensic Imaging under Linux for a faster & more secure operation
To Analyze the Captured Data
- Reboot the unit to Windows
- Use third-party applications to perform data analysis
Fast & Affordable
-
Acquire data from:
- Drives: SATA/M.2 SATA/NVMe/MSATA/MicroSATA/TB/USB3.1
- SCSI/1394/SS with optional controllers
- Multi-Media Cards
- SSD and USB Storage Devices and Network
Main Hardware Features: | |
---|---|
Case: | Portable, lightweight, small, and easy to carry |
CPU: | i7 Latest generation Quad Core Mobile CPU |
Display: | 8” (800x600), LED back-light, touchscreen, color LCD display. |
OS: | Linux Ubuntu 64 bit and Win 10 Professional 64 Bit in a dual boot. The open Ubuntu OS allows for easy application modification to include new features, easy adaptation to new hardware, and ease of adding third-party Ubuntu applications. |
Security: | Linux OS (Linux is less targeted by malware). |
Application Updates: | The application can easily be updated via USB thumb drive and displays a special update application screen. |
Dual Boot (Built-in): |
|
Hardware Upgrade: | The unit can be upgraded at the time of purchasing for additional cost to a larger internal SSD. |
Hardware Specifications: | |
RAM: | 16GB DDR4 internal memory |
Internal Storage: | 250GB SSD SATA drive |
Storage Controller: | SATA controller supporting 6 Gigabit/s SAS/SATA interface speeds with a maximum data rate of 37GB/min. |
Hardware Supports: | |
Target Ports: | One SATA port, One NVMe port, one e-SATA port, and 6 USB3.0/USB3.1 ports. In addition, the 4 e-SATA ports on the expansion box are set as target ports as well. |
Source Ports: | One SATA port, One NVMe port, and two USB3.0/USB3.1 ports are set as source ports (the user cannot change the role of these ports). |
PCIE Supports: | Supports M.2 and 2.5” PCIE SSD. For PCIE Express cards and PCIE express Memory, the user can use the unit’s T3 port and the TB3.0 to PCIE Expansion Box with a PCIE Express card reader. |
Supports Storage Protocols and Interfaces: | NVMe, SATA, e-SATA enclosures, IDE, USB2.0, USB3.0, MMC, M.2 NGFF (SATA or PCIE base), Mac via Thunderbolt 2.0, Mac via Thunderbolt 3.0, 1394, USB3.1, SCSI*, FC*, and SAS*. |
Supports Form Factors: | 3.5”, 2.5”, ZIF, 1.8”, Micro-SATA, Mini-SATA, Slim SATA, Ultra Slim SATA, M.2 SATA, PCIE-Memory Card*, Mini PCIE*, SFF-869 U.2 NVMe*, M.2 NVMe*, and CF-30. *With the optional controllers plugged into the Expansion Box. |
Application Settings: | |
HPA/DCO Automatic Supports: | The application has the ability to automatically open HPA and DCO areas and re-size the drive to its full native capacity in order to erase any “hidden data” (HPA/DCO are special areas on the drive that support this feature). |
Bad Sectors Handling: | The user can select to skip bad sectors/blocks or abort the operations. The skipped bad sectors will be reprted in the log file in detailed or in summary. |
48bit LBA Addressing: | Supports drives with sizes up to 256TB. |
Application Features: | |
GUI: | The application is built with large, very simple, and easy-to-navigate icons. In a few clicks, the user can set the operation, and it will quickly start up and run. |
Speed: |
|
Application Main Operation: | |
Forensic Imaging Mode:
|
|
Parallel Operations: | |
|
|
Parallel Operations - Linux Elaborated |
|
More Features |
|
Expansion Capabilities and Main Hardware Options: |
|
Options using the Thunderbolt 3.0 to PCIE 3.0 Expansion Box |
|
Ports: |
|
Power Characteristics |
|
Operating Environment: |
|
Mechanical Characteristics |
|
Included Items: |
|
Custom Field
- High data transfer rate when running E01 compression - using 16 Parallel Engines
- Support Selective Imaging of Files and Folders
- Virtual Drive Emulator
- Remote Capture KIT: Capture from Un-Open Laptops and PC