The Image MASSter Solo 4 Forensic Kit

Features

  • Extreme Speed Built for Today’s and Tomorrow’s Hard Drive Technology
    Built to work with the fastest hard drives available, Solo-4 captures, authenticates, and sanitizes at full SATA-2 speed (18GB/min top capability). This technology not only allows the unit to take advantage of today’s fastest hard drive speeds but also allows the user to be prepared for tomorrow’s future hard drive speed improvements.
  • Multiple "Suspect" Side Connections
    • 2 SATA/SAS connections and 2 USB 2.0 connection. (Operator can choose to use either the SAS/SATA connection or the USB connection for each of the two "Suspect" positions)
    • Unit features built–in support for imaging of a RAID drive pair (0, 1, JBOD).
    • IDE Drive Adapter included.
    • Optional drive adapters for 1.8", 2.5", ZIF, and proprietary Interface /Laptop drives, and Micro Media Formats including Compact Flash, Memory Sticks, SD, Micro SD, Multi Media card, etc.
    • Cross Copy Support allows user to image any "Suspect" Drive interface to any "Evidence" Drive interface. (ie. IDE "Suspect" drive to SATA "Evicence" drive)
    • All Suspect connections are permanently write-protected at all times to prevent changing Suspect Data (can not be disabled).
  • Multiple "Evidence" Side Connections
    2 SATA/SAS connections and 2 USB 2.0 connections. Optional Drive Adapters will allow imaging to many other drive formats including external RAID devices.
  • Operational Modes
    • Captures "Suspect" drive to one "Evidence" drive (Single Copy Mode)
    • Captures "Suspect" drive to two "Evidence" drives (Multi Copy Mode)
    • Captures 2 "Suspect" drives to two “Evidence” drives (Parallel Copy Mode)
    • Drive Wiping and Sanitization
    • Hashing (MD-5, SHA-1 and SHA-2) of "Suspect" Hard Drive and Linux DD Images
    • Uploads suspect Images to Network Storage and or any attached Network Share.
    • All processes can be done simultaneously
  • Multiple Imaging Formats
    • 100% Copy: Bit-for-bit copy
    • Linux DD: Supports storing single or multiple DD images (industry standard) on a single "Evidence" Hard Drive or USB storage device.
    • User can define the size of the Linux DD segments.
    • E01 files: Supports imaging to EnCase® Forensic Image file.
  • Multiple File Format Support
    Seize Data using Raw Mirror Capture Format, Raw Segment File Format or Encase (E01) File Format. The Mirror Capture Format transfers data to the Destination drive using the same LBA location which was read from the Source Drive . The Raw Segment File Format creates an NTFS partition on the Destination Drive and transfers data as Raw Segment files to a Destination folder. The Encase (E01) Segment file format creates an NTFS partition on the Destination drive and transfers data using the Encase Segment file format, to a destination folder. The Segment files size can be defined as 640 MB, 1GB, 2GB, 4.7GB, Whole Drive or Custom Size.
  • "On the Fly" Drive Image Encryption
    Built-in DiskCypher technology allows the full encryption (AES 192/256) of Forensic Images. The process is done without speed degradation during the acquisition phase.
  • Windows XP Operating System
    Solo-4 runs on the highly stable and proven Windows XP Operating System.
    • Unit can be customizable to many different languages.
    • Unit can be customized to individual organization needs upon request.
    • Automatic Support to many PC peripherals.
  • Drive Spanning
    Solo-4 allows for the imaging from one large "Suspect" drive to multiple smaller "Evidence" drives.
  • Image Restore
    Restore a previously captured Linux DD or E01 image to a 100% copy (fully bootable working copy).
  • Drive Wiping
    Supports single pass drive wiping or full Department of Defense (DoD) Sanitization.
  • Intuitive Easy to Use Interface
    8" Full Color, User Friendly Touch Screen eliminates the need of external display, mouse or keyboard. The user interface provides three graphical levels and the operational wizard allows user to easily operate the unit. The advantage settings mode can also be selected for low level control.
  • Unalterable "Suspect" Interface Write Protection
    ICS recognizes the industry standard and permanently write protects any device connected to the Solo-4 "Suspect" position thereby preventing any unintentional alteration of suspect Data. Data alteration could occur if a device allows the user the option of turning off this protection mode.
  • Multiple Hash Verifications
    All "Suspect" and "Evidence" positions allow Multiple Hash Verifications including SHA-1 and SHA-2 during the acquisition process simultaneously and without speed degradation.
  • Upload Suspect Images to Network Storage or Any Attached Network Share
    With the use of Windows XP Operating System Solo-4 allows the upload of Suspect Data Images to networked storage area using a built-in 1 Gigabit Ethernet connection. This will allow user to take advantage of large storage repositories (SAN) for the purpose of processing and archiving forensic images.
  • Preview Suspect Data Directly on the Unit
    Preview active files on the Suspect Drive utilizing Windows XP file viewers that allow previewing Word, Excel, PDF, text or multimedia (pictures, video and audio) files prior to seizing the data. Unit also features a built-in Audio Head Phone Jack for discreet listening.
  • Drive Block Functionality for use with a Forensic WorkStation
    Utilizing the "Suspect" "always on" write protection connections Solo-4 can be attached to a Forensic Workstation via USB connection to allow the preview, capture or analysis of Suspect Data in a safe environment.
  • USB Card Reader Support
    Supports Micro Media Formats (Compact Flash, Memory Sticks, SD, Micro SD, Multi Media card, etc.) expanding the option of types of "Suspect" Media that can be previewed, analyzed or captured.
  • Data Integrity check
    Read back verification of the two "Evidence" drives for extra data integrity checking.
  • Field Upgradable
    Free and easy to update firmware and software through USB port.
  • Logs and Auditing
    Complete and accurate auditing of all unit processes are provided in text file format that can be exported via USB connection.
  • Affordable
    Unparallel performance and built-in features at an affordable price makes Solo-4 the perfect and most complete forensic solution for any investigator today.

Road MASSter
Portable Evidence Seizure, Preview and Analysis System

  • High speed Forensic Data Aquisition and Analysis tool. The unit supports today's most common drive interfaces (IDE, SATA, SAS, SCSI, USB, FireWire 1394B)
  • Ruggedized Design: built for the road using a Storm case, it offers a tought, rugged, airtight water tights and light weight design. At only 37 pounds it can be accepted as "carry-on" for transport.
  • Shock absorbent design.
  • Large 15" color display designed to operate indoors and outdoors.
  • Modular design. Provides ease of maintenance. Keyboard, mouse and internal drive can be easily removed.
  • Lower power processor
  • Full aluminium enclosure for EMI shielding and mechanical protection.
  • Five USB ports can be used to connect different devices such as S/W dongles, BlueTooth devices, card readers, memory epxress card readers, mini hubs, storage devices, printers.
  • Two high-speed drive cooling fans.
  • Analyze write-protected data under the Windows XP Pro environment using 3rd party Forensic Analysis applications.

Hardware features

  • AMD CPU Opteron 260HE low power (upgradeable to 2 CPUs)
  • 4GB DDR RAM (upgradeable to 8 GB and with two CPUs up to 12GB)
  • 100GB 7200 RPM internal SATA drive with Windows XP Pro
  • 15" TFT color LCD display super bright with 600 NITS
  • Slim CD-RW + DVD-RW
  • Slim floppy drive
  • 400 W internal power supply
  • Stereo speakers
  • Dimensions 21.7" x 14.1" 8.9"

Software features

  • Multiple capture LinuxDD segmented file format
  • Single capture Mirror image sector-by-sector format
  • IQCopy capture Copies only allocated clusters (FAT and NTFS file systems)
  • Wipeout (sanitize) drives Uses the DoD standard or user defined function
  • Hash verification CRC-32, MD5, SHA-1, SHA-2
  • Saves and prints Audit Trail and Case information
  • Multi drive copy Simultaneously capture multiple source drives to multiple target drives
  • MultiMASSter Stores multiple IT loads in a single drive

Built-in ports

  • 2 SAS/SATA (Evidence and Suspect)
  • 1 SATA for internal drive expansion
  • 2 USB 2.0 (Evidence and Suspect)
  • 2 USB 2.0 generic
  • 2 SCSI Ultra 320 68P (Evidence and Suspect)
  • 2 1394B
  • 1 RJ-45 for Gigabit Ethernet
  • 1 VGA (connect to LCD or external monitor)
  • 1 Audio (connect to speakers or headphones)
  • 3 drive power connectors (one for Suspect and 2 for Evidence drives)

Option

  • 2 SATA-to-IDE adapters
  • 1 ICS LinkMASSter toolkit designed to capture data from unopen computers and notebooks
  • 2 USB card readers (one write protected)
  • 1 PS/2 Mini Keyboard
  • 1 PS/2 TouchPAD
  • All required data and power cables