Forensic Cube V3


All-in-One Solution for Crime Scene Investigations. A portable and versatile computer forensics equipment. Highly-integrated hard disk duplication, data analysis and system emulation functions in a magic box.
Hard Drive Imaging
-
1-to-1, 1-to-2, 2-to-2 disk duplication
-
Support IDE, SATA, SAS, SCSI, USB media
-
Forensic imaging speed up to 39GB/min
-
Keyword searching during duplication
-
Acquisition in HPA/DCO protected area
-
Support MD5 and SHA-1 hashing during imaging
-
Restore image to hard disk
-
Remote duplication through network
Forensic Analysis
-
Quick and automated forensic analysis
-
Evidence preview
-
Data recovery (FAT32,NTFS, ReFS, HFS+, APFS etc.)
-
Fast indexing and keyword searching
-
Enctypted volume/file decryption, eg. BitLocker, TrueCrypt, FileVault 2
-
Instant messenger (PC QQ, WhatsApp, DingTalk etc.) , browser history, user access and email analysis
-
Quickly recover deleted emails
OS Emulation
-
OS emulation allows a direct view on the suspect computer
-
Dynamic emulation helps malware / website / database analysis
-
Acquire saved passwords (dial-up, MSN messenger, browser, PSSP) on emulated computer
-
Bypass login password to emulate Windows and Mac OS
-
Emulate mounted raw, 001, or E01 image files, and physical disk with write-blocker
-
Support popular Windows, Mac, Linux operation system
