PGP is available for secure communication. Please send your request for public key download information.
The Image MASSter Solo 4 Forensic Kit
Features
Extreme Speed Built for Today’s and Tomorrow’s Hard Drive Technology
Built to work with the fastest hard drives available, Solo-4 captures, authenticates, and sanitizes at full SATA-2 speed (18GB/min top capability). This technology not only allows the unit to take advantage of today’s fastest hard drive speeds but also allows the user to be prepared for tomorrow’s future hard drive speed improvements.
Multiple "Suspect" Side Connections
2 SATA/SAS connections and 2 USB 2.0 connection. (Operator can choose to use either the SAS/SATA connection or the USB connection for each of the two "Suspect" positions)
Unit features built–in support for imaging of a RAID drive pair (0, 1, JBOD).
IDE Drive Adapter included.
Optional drive adapters for 1.8", 2.5", ZIF, and proprietary Interface /Laptop drives, and Micro Media Formats including Compact Flash, Memory Sticks, SD, Micro SD, Multi Media card, etc.
Cross Copy Support allows user to image any "Suspect" Drive interface to any "Evidence" Drive interface. (ie. IDE "Suspect" drive to SATA "Evicence" drive)
All Suspect connections are permanently write-protected at all times to prevent changing Suspect Data (can not be disabled).
Multiple "Evidence" Side Connections
2 SATA/SAS connections and 2 USB 2.0 connections. Optional Drive Adapters will allow imaging to many other drive formats including external RAID devices.
Operational Modes
Captures "Suspect" drive to one "Evidence" drive (Single Copy Mode)
Captures "Suspect" drive to two "Evidence" drives (Multi Copy Mode)
Captures 2 "Suspect" drives to two “Evidence”
drives (Parallel Copy Mode)
Drive Wiping and Sanitization
Hashing (MD-5, SHA-1 and SHA-2) of "Suspect" Hard Drive and Linux DD Images
Uploads suspect Images to Network Storage and or any attached Network Share.
All processes can be done simultaneously
Multiple Imaging Formats
100% Copy: Bit-for-bit copy
Linux DD: Supports storing single or multiple DD images (industry standard) on a single "Evidence" Hard Drive or USB storage device.
User can define the size of the Linux DD
segments.
E01 files: Supports imaging to EnCase® Forensic Image file.
Multiple File Format Support
Seize Data using Raw Mirror Capture Format, Raw Segment File Format or Encase (E01) File Format. The Mirror Capture Format transfers data to the Destination drive using the same LBA location which was read from the Source Drive . The Raw Segment File Format creates an NTFS partition on the Destination Drive and transfers data as Raw Segment files to a Destination folder. The Encase (E01) Segment file format creates an NTFS partition on the Destination drive and transfers data using the Encase Segment file format, to a destination folder. The Segment files size can be defined as 640 MB, 1GB, 2GB, 4.7GB, Whole Drive or Custom Size.
"On the Fly" Drive Image Encryption
Built-in DiskCypher technology allows the full encryption (AES 192/256) of Forensic Images. The process is done without speed degradation during the acquisition phase.
Windows XP Operating System
Solo-4 runs on the highly stable and proven Windows XP Operating System.
Unit can be customizable to many different languages.
Unit can be customized to individual organization needs upon request.
Automatic Support to many PC peripherals.
Drive Spanning
Solo-4 allows for the imaging from one large "Suspect" drive to multiple smaller "Evidence" drives.
Image Restore
Restore a previously captured Linux DD or E01 image to a 100% copy (fully bootable working copy).
Drive Wiping
Supports single pass drive wiping or full Department of Defense (DoD) Sanitization.
Intuitive Easy to Use Interface
8" Full Color, User Friendly Touch Screen eliminates the need of external display, mouse or keyboard. The user interface provides three graphical levels and the operational wizard allows user to easily operate the unit. The advantage settings mode can also be selected for low level control.
Unalterable "Suspect" Interface Write Protection
ICS recognizes the industry standard and permanently write protects any device connected to the Solo-4 "Suspect" position thereby preventing any unintentional alteration of suspect Data. Data alteration could occur if a device allows the user the option of turning off this protection mode.
Multiple Hash Verifications
All "Suspect" and "Evidence" positions allow Multiple Hash Verifications including SHA-1 and SHA-2 during the acquisition process simultaneously and without speed degradation.
Upload Suspect Images to Network Storage or Any Attached Network Share
With the use of Windows XP Operating System Solo-4 allows the upload of Suspect Data Images to networked storage area using a built-in 1 Gigabit Ethernet connection. This will allow user to take advantage of large storage repositories (SAN) for the purpose of processing and archiving forensic images.
Preview Suspect Data Directly on the Unit
Preview active files on the Suspect Drive utilizing Windows XP file viewers that allow previewing Word, Excel, PDF, text or multimedia (pictures, video and audio) files prior to seizing the data. Unit also features a built-in Audio Head Phone Jack for discreet listening.
Drive Block Functionality for use with a Forensic WorkStation
Utilizing the "Suspect" "always on" write protection connections Solo-4 can be attached to a Forensic Workstation via USB connection to allow the preview, capture or analysis of Suspect Data in a safe environment.
USB Card Reader Support
Supports Micro Media Formats (Compact Flash, Memory Sticks, SD, Micro SD, Multi Media card, etc.) expanding the option of types of "Suspect" Media that can be previewed, analyzed or captured.
Data Integrity check
Read back verification of the two "Evidence" drives for extra data integrity checking.
Field Upgradable
Free and easy to update firmware and software through USB port.
Logs and Auditing
Complete and accurate auditing of all unit processes are provided in text file format that can be exported via USB connection.
Affordable
Unparallel performance and built-in features at an affordable price makes Solo-4 the perfect and most complete forensic solution for any investigator today.
Road MASSter
Portable Evidence Seizure, Preview and Analysis System
High speed Forensic Data Aquisition and Analysis tool. The unit supports today's most common drive interfaces (IDE, SATA, SAS, SCSI, USB, FireWire 1394B)
Ruggedized Design: built for the road using a Storm case, it offers a tought, rugged, airtight water tights and light weight design. At only 37 pounds it can be accepted as "carry-on" for transport.
Shock absorbent design.
Large 15" color display designed to operate indoors and outdoors.
Modular design. Provides ease of maintenance. Keyboard, mouse and internal drive can be easily removed.
Lower power processor
Full aluminium enclosure for EMI shielding and mechanical protection.
Five USB ports can be used to connect different devices such as S/W dongles, BlueTooth devices, card readers, memory epxress card readers, mini hubs, storage devices, printers.
Two high-speed drive cooling fans.
Analyze write-protected data under the Windows XP Pro environment using 3rd party Forensic Analysis applications.
Hardware features
AMD CPU Opteron 260HE low power (upgradeable to 2 CPUs)
4GB DDR RAM (upgradeable to 8 GB and with two CPUs up to 12GB)
100GB 7200 RPM internal SATA drive with Windows XP Pro
15" TFT color LCD display super bright with 600 NITS
Slim CD-RW + DVD-RW
Slim floppy drive
400 W internal power supply
Stereo speakers
Dimensions 21.7" x 14.1" 8.9"
Software features
Multiple capture LinuxDD segmented file format
Single capture Mirror image sector-by-sector format
IQCopy capture Copies only allocated clusters (FAT and NTFS file systems)
Wipeout (sanitize) drives Uses the DoD standard or user defined function
Hash verification CRC-32, MD5, SHA-1, SHA-2
Saves and prints Audit Trail and Case information
Multi drive copy Simultaneously capture multiple source drives to multiple target drives
MultiMASSter Stores multiple IT loads in a single drive
Built-in ports
2 SAS/SATA (Evidence and Suspect)
1 SATA for internal drive expansion
2 USB 2.0 (Evidence and Suspect)
2 USB 2.0 generic
2 SCSI Ultra 320 68P (Evidence and Suspect)
2 1394B
1 RJ-45 for Gigabit Ethernet
1 VGA (connect to LCD or external monitor)
1 Audio (connect to speakers or headphones)
3 drive power connectors (one for Suspect and 2 for Evidence drives)
Option
2 SATA-to-IDE adapters
1 ICS LinkMASSter toolkit designed to capture data from unopen computers and notebooks