OpenText Forensic TX2 Imager

Descripción

High-performance forensic imager designed to maximize speed and efficiency in the triage and acquisition of digital forensic evidence.

During digital forensic investigations and incident response (DFIR), forensic examiners must acquire an exact bit-for-bit copy, or forensic image, of the digital evidence, rather than simply copying the visible files. This ensures the integrity, completeness, and admissibility of the evidence. However, investigators face several challenges when acquiring exact bit-for-bit copies of digital evidence, which can affect the integrity, speed, and effectiveness of their forensic investigations.

OpenText™ Forensic TX2 Imager simplifies complex forensic data acquisition with advanced local and network imaging capabilities, without compromise, even during simultaneous forensic jobs. Designed to deliver speed, reliability, and ease of use, OpenText Forensic TX2 Imager ensures consistent and defensible results in a standalone high-performance hardware solution, giving investigators confidence in the digital evidence captured from a suspect device.

High-performance acquisition

OpenText Forensic TX2 Imager uses an innovative approach to read verification in physical acquisitions called "parallel hash verification" (patent pending). As data is written to the destination, hash states are captured at the beginning and end of each data block. When the TX2 begins read verification, it uses these initial and final hash states to independently verify the integrity of each block. In addition to greatly accelerating verification through parallelization, this method allows verification to fail immediately upon detecting an incorrect block, rather than waiting until the end of a long sequential process.

Benefits

  • Up to 5 times faster evidence acquisition

  • Seamless connectivity with a wide variety of device types

  • Intuitive user interface for simple operation

  • Maximized productivity by running multiple jobs simultaneously

OpenText Forensic TX2 Imager 2

The imager also supports "tree hashing," an industry first for portable imagers. Tree hashing divides the acquisition data stream into blocks that are processed independently using traditional hash algorithms. These hashes are then combined sequentially to create a single forensic hash value that represents the entire input data set.

The speed improvement comes from parallelizing the first-level hashing, which allows leveraging all available processing resources of the system. The same benefit is obtained during read verification, since each block is verified in parallel before the final verification hash is computed sequentially.

Tree hashing eliminates the main bottleneck of traditional sequential hashing, enabling enormous performance improvements in acquisition and verification. OpenText tree hashing is the solution needed to keep pace with the rapid increase in disk capacity and read/write speeds.

Enhanced security

OpenText Forensic TX2 Imager supports multi-factor authentication via PIV smart cards with YubiKey devices. This authentication is especially important in networked environments, as it prevents unauthorized access to digital evidence, ensures that only authorized personnel handle forensic images, maintains evidentiary integrity, reduces the risk of internal misuse or tampering of forensic data, and helps organizations comply with network security and evidence regulatory standards.

Broad device compatibility

Investigators never know what type of device they will need to analyze. With source and destination support for PCIe, SATA, and USB, OpenText Forensic TX2 Imager enables forensic imaging of virtually any type of device encountered. With optional adapters, the TX2 is also compatible with SAS, IDE, and FireWire media. In addition, thanks to PCIe hot-swap functionality, investigators can be confident that the TX2 remains efficient, flexible, and capable of handling high-speed forensic acquisitions without delays.

Likewise, mobile devices play a fundamental role in digital forensic investigations, as they often contain valuable evidence related to criminal activities, cyber threats, or legal disputes. Given the large volume of data stored on these devices, forensic investigators can rely on OpenText Forensic TX2 Imager for the acquisition of backup files from Apple and Android mobile devices.

Seamless workflows

The resources available for forensic acquisitions are often limited in terms of personnel, experience levels, and pressure from high case volumes. OpenText Forensic TX2 Imager reduces the burden on investigation teams by offering a compact and lightweight device that can be easily transported to field operations or used in forensic laboratories.

Through a high-resolution color LCD screen, the TX2's intuitive user interface smoothly guides investigators through the forensic imaging processes. It simplifies triage tasks with a practical thumbnail gallery view for all known multimedia file types. In addition, thanks to the ability to run multiple forensic operations simultaneously, efficiency in the evidence acquisition process is guaranteed.

The cornerstone of digital forensic investigation

By delivering forensic integrity, efficient workflows, portability, and high-performance acquisition/verification both in the field and in the lab, OpenText Forensic TX2 Imager should be the cornerstone of any digital forensic investigation. It helps law enforcement, corporate security teams, and legal professionals discover and acquire crucial evidence with industry-leading speed.

Feature Description
Concurrent acquisition and verification Allows forensic acquisition jobs to be completed significantly faster.
Innovative hashing concepts Enable up to a 5 times performance improvement.
Multi-factor authentication (MFA) support Provides enhanced security in networked environments.
Gallery view for image files Enables fast triage and ease of use.
Destination disk reconfiguration function Offers the option to select one or any combination of HPA/DCO/AMA removal, wiping, formatting, or encryption in a single job, improving data imaging process efficiency by automating destination media management.
USB 3.2 G2 and PCIe Gen3 source/destination support Improves disk interface performance, reducing acquisition and verification time.
Disjoint NVMe namespace support Improves evidence accuracy.
Automatic job start based on dynamic assessment of available system resources, with manual override option Optimizes job execution efficiency.