top of page

Designed for digital forensic labs, the ZXi™10G-Forensic’s blazing fast imaging speeds of over 50GB*/min , two 10 GbE ports and one 2.5 GbE port streamline the forensic imaging processes. Built-in support for SAS, SATA, USB, Thunderbolt drives, and optional support for up to 16 M.2 NVMe SSDs along with the ZXi™-10G-Forensic’s advanced features provide efficient and secure digital evidence collection.
 

  • Extreme speed, imaging at over 50GB/min*
  • Designed for digital forensic labs
  • Two 10GbE Ethernet ports and one 2.5 GbE port
  • Network “Push” feature to upload images to a network repository from up to 5 evidence drives simultaneously
  • Secure sensitive evidence data with whole disk, open standard, drive encryption using the NIST recommended XTS-AES-256 cipher mode, decrypt using the ZXi-Forensic or Veracrypt

ZXi™-10G-Forensic

SKU: mos-F-ZXI-10G-2-FOR
£10,998.00Price
  • HIGH SPEED IMAGING 

    The ZXi™-10G-Forensic achieves imaging speeds surpassing 50 GB/min and can clone PCIe to PCIe at speeds at over 100 GB/min.

     

    SOURCE PORTS 

    5x SAS/SATA
    Up to 8 M.2 NVMe SSDs (with optional PCIe Expansion Modules)
    2x USB 5Gbps Type-A
    1x USB 20Gbps (Type-C)
    1x Thunderbolt™ 4/USB 20Gbps (Type-C)

     

    DESTINATION PORTS 

    Up to3x SAS/SATA and 2x SATA (with optional Expansion Kit)
    Up to 8 M.2 NVMe SSDs (with optional PCIe Expansion Modules)
    2x USB 10Gbps (Type-A)
    4x USB 5Gbps (Type-A)
    1x Thunderbolt™ 4/USB 20Gbps (Type-C)

     

    TWO 10 GBE PORTS 

    Two high-speed 10GbE connections are available to image to/from a network repository or NAS and achieve transfer speeds of up to 30GB/min. Utilize a 2.5GbE connection to help minimize bottlenecks.

     

    THUNDERBOLT 4 

    Two Thunderbolt™ 4/USB 3.2 Gen 2×2 ports allow users to connect Thunderbolt external storage enclosures. 

     

    M.2 NVME SUPPORT 

    The optional PCIe Expansion Modules support imaging or cloning up to 8 Source and 8 Destination M.2 NVMe SSDs. Up ro 2 modules can be used. Each module can be 4 as Source and 4 as Destination, all 8 as Source, or all 8 as Destination. 

     

    BROAD INTERFACE SUPPORT 

    Optional adapters are available for the following drives:
    M.2 SATA
    mSATA
    Micro SATA
    eSATA
    1.8”/2.5”/3.5” IDE
    IDE ZIF
    eSATA
    Flash media

     

    MULTIPLE IMAGING FORMATS 

    Image and verify to multiple image formats – Native copy, .dd, dmg, e01 and ex01. The ZXi-10G-Forensic provides MD5, SHA1, SHA256, and dual hash authentication at extremely fast speeds. 

     

    CONCURRENT IMAGE+VERIFY 

    Imaging and verifying concurrently takes advantage of destination hard drives that may be faster than the source hard drive. Duration of total image+verify process time may be reduced by up to half. 

     

    BITLOCKER, OPAL, VERACRYPT, AND TRUECRYPT DECRYPTION SUPPORT 

    Decrypt partitions or drives (requires the recovery key or password) and then image the selected partitions or drives. A password or a newly generated BEK (BitLocker Encryption Key) file is required to unlock FIPS-compliant BitLocker encryption. 

     

    APFS SUPPORT 

    The ZXi-10G-Forensic supports logical imaging (using our File to File mode) from drives formatted to APFS (Apple® File System). Requires use of Advanced set-up, reference our users’ manual for complete information. The ZXi-10G-Forensic can also view and browse APFS files using our file browser feature. 

     

    NETWORK CAPTURE 

    Capture network traffic, internet activity, and VOIP. Sniff data on a network and store captured packets on a hard drive connected to Falcon-NEO, data is saved to a .pcapng file format 

     

    TARGETED/LOGICAL IMAGING 

    Create a logical image by using pre-set, custom, or file signature filters, and/or keyword search function to select and acquire only the specific files you need. Format output to L01, LX01, ZIP or directory tree. 

     

    WIPE 

    Choose from Secure Erase, DoD wipe, and custom pass settings. Complies with NIST 800-88 guidelines. User selectable option to verify wipe pass value during the wipe process. 

     

    FILE BROWSER/WRITE-BLOCKED DRIVE PREVIEW 

    Provides logical access to source or destination drives and network repositories connected to the ZXi-10G-Forensic. View the drive’s partitions and contents and view text files, jpeg, PDF, XML, HTML files. View the contents of .dd, e01, ex01, dmg, L01 image files created by the ZXi-10G-Forensic. Preview on a PC/laptop or over a network via SMB or as an iSCSI target. 

     

    MULTI-TASK 

    Image from multiple sources to multiple destinations, including a network repository, simultaneously. Image to one destination while hashing and/or wiping a second drive at the same time. Perform up to 5 tasks concurrently. 

     

    IMAGE FROM A DESKTOP/LAPTOP 

    without removing hard drives. Create a forensic bootable USB flash drive to image a source drive from a computer on the same network without booting the computer’s native OS. Supports Surface Pro 4 and above laptops. 

     

    CAPTURE PATH SELECTION 

    Add folders to the destination repository and then select and image to the named folder. Empty folders can be deleted, and folders can be renamed. 

     

    FILE SYSTEMS 

    Format destination drives to NTFS, exFAT, HFS+, EXT4, EXT3, EXT2, or FAT32 file systems. Image from source drives formatted to any major file system. 

     

    ENCRYPTION 

    Secure sensitive evidence data with whole drive, open standard drive encryption using the NIST recommended XTS-AES 256 cipher mode. Decryption can be performed using the ZXi-10G-Forensic or by using open-source software programs such as VeraCrypt, TrueCrypt or FreeOTFE. 

     

    ENCRYPTION DETECTION 

    Whole disk and partition level encryption detection. Easily identify Source drives with possible encryption. 

     

    PARALLEL IMAGING 

    Perform multiple imaging tasks from the same source drive to multiple destinations using different imaging formats. 

     

    AUDIT TRAIL REPORTING/LOG FILES 

    Provides detailed information on each operation. Log files can be viewed on the ZXi-10Gorensic or via a web browser, exported to XML, HTML or PDF format to a USB flash drives. Users can print the log files directly from their PC when connected to the ZXi-10G-Forensic through a web browser. 

     

    ADDITIONAL FEATURES 

    Additional features include remote operation, internal removable storage drive for secure/classified locations, partition imaging, a task macro, a resume feature for interrupted tasks, image restore, reverse read, network “Push” feature, HPA/DCO capture, save configuration settings and set password-protected user profiles, image from CD/DVD Blu-Ray media, drive spanning, color touchscreen display, HDMI port, USB 3.0 ports for keyboard, mouse, or printer, blank disk check, drive trim, and S.M.A.R.T. data.

bottom of page