SIPT3 Forensic Field Unit – Linux Forensic Imager with i7 and Thunderbolt port and NVMe

SIPT3 Forensic Field unit with 4 SAS/SATA3 ports, 8 USB3.0 ports, and Thunderbolt 3.0 port: The unit includes Thunderbolt 3.0 to PCIe 3.0 Expansion Box and with M.2 NVMe controller that enables capturing NVMe SSD at 65GB/min. It is a top performance Field Computer Forensic Imaging tool and Complete Digital Forensic Investigation platform. The user can run multiple parallel simultaneous forensic imaging from many devices, with 3 HASH values, and with encryption on the fly.
As a platform, the unit can be used to perform:

Cellphone Data Extraction
Triage Data Collection
Full Forensic Analysis

It includes
ThunderBolt 3.0 to PCIE Expansion Box
M.2 controller
Remote Capture KIT
Selective Capture
Virtual Drive Emulator feature

Complete Forensic E01 Imaging from 2TB WD2003FZEX with compression level 9, SHA-1 and MD5 are enabled, HASH the Evidence and compare is enabled @ 11GB/min


A mobile, compact, easy to carry, versatile, and extremely fast Forensic Imaging unit that can serve as a complete Field Computer Forensic Investigation platform. The unit is running under Linux Ubuntu OS with a dual boot to Windows 8.1. The unit has a built-in extremely fast Thunderbolt 3.0 port (40 Gigabit/s) and it supplied with Thunderbolt 3.0 PCIE 3.0 Expansion Box that allows the user to plug any storage controller (SCSI, 1394, NVMe..) and capture data from almost any source.
The unit can be used to perform:

  1. Multiple parallel simultaneous Forensic Capture using bit by bit, DD, E01/Ex01(with full compression), Mix DD/E01 formats, copy the whole drive or one partition. Copy up to 5:10 for SATA drives with use of USB3.0 to SATA adapters
  2. Run a Selective Imaging (Targeted Imaging) of files, folders, partitions with file extension filters
  3. Erase data from Evidence drive using DoD (ECE, E), or Security Erase, or Enhanced Security Erase, Sanitize protocols
  4. View the CAPTURED data directly on Ubuntu Desktop Screen or Windows
  5. Encrypt the data while capturing (AES256)
  6. HASH the data while capturing (run all the 3 HASH engines at the same session SHA-1, SHA-2, MD5)
  7. Run Cellphone/Tablets data Extraction and Analysis
  8. Prepare Forensic Triage keys and view the captured targeted data
  9. Run a Quick Keyword Search on the Suspect drive, prior to capture, or while the capture
  10. Run a full Forensic Analysis application like Encase/Nuix/FTK
  11. Run a Virtual Drive Emulator (This option is enabled on this unit)
  12. Use the Remote Capture application to capture data from unopened Laptops with Intel based CPU, Tablets and PC (Supplied with this unit)
  13. Use the Thunderbolt port to capture data from USB3.1 storage devices, Mac via Thunderbolt 2/3 port or 1394 port

Case Study: Some example of the unit’s performances:
Complete HASH verification operation with SHA-1 enabled on SSD @ 31GB/min, on WD 1TB Blue @10GB/min.
Complete Forensic Imaging 1:2 with SHA-1 enabled on 3 SanDisk Extreme II 120GB SSD @ 29GB/Min.
Complete Forensic E01 Imaging from 2TB WD2003FZEX with compression level 9, SHA-1 and MD5 are enabled, HASH the Evidence and compare is enabled @ 11GB/min

The unit built-in: 8” Touchscreen color LCD display, 4 native SAS/SATA ports, 8 native USB3.0 ports, e-SATA port, 2 Generic USB2.0 ports, 1Gigabit/s Ethernet ports, Display port, Thunderbolt 3.0 port and audio ports. The unit is supplied with slim and compact Thunderbolt PCIE 3.0 Expansion Box where the user can plug many different kinds of storage devices and capture data from (SCSI, 1394, NVMe, FC, and more). The Expansion Box has in addition USB 3.1 port that supports capture of USB3.1 storage devices.