|
|
Product informationThe Atola Forensic Imager is the same product as the Atola Imager with 3 key features for data capture in forensic and e-discovery cases (wipe/erase, case manager, and password removal). This is an ideal option for forensic professionals who need an imager with strong data recovery capability for creating forensic images of damaged or unstable hard drives. Using a data recovery imager saves time in the field and extracts more data to create a more complete image. Click here to skip to this section’s FAQ at the bottom of the page Customize every step of the processThe Atola Forensic Imager enables the user to create the perfect imaging process to meet the needs of a case by adjusting simple parameters. It is able to image damaged or unstable hard drives in the field that cannot be imaged by regular forensic products. This means technicians can image more hard drives in the field without needing to take them back to their labs. By accessing more sectors it is able to deliver a more complete image and more data for evidence. Multiple hashing methods are available and they are calculated on the fly (while the image is being written). GList auto reallocation can be disabled to prevent the hard drive from contaminating evidence by remapping sectors. Main Imaging Parameters:
Chunk and stack images for efficiency in the fieldImage file capture settings can be set up quickly and easily. Image file size can be set to 2GB, 4GB, or any custom size. Multiple images can be stored on a single destination HDD (stacked), allowing the user to reduce the number of drives they need to carry on site. Please note that this option requires Destination HDD to be attached to a PC or Laptop. Erase the destination hard drive to prepare for a caseMany forensic professionals are required to wipe/erase hard drives before they are used to receive forensic images. This is usually done to guarantee the accuracy of the data and check the destination drive for any errors by writing to every sector. The Atola Forensic Imager wipes hard drives at the hard drive’s maximum speed using any specified HEX pattern to overwrite the sectors. It can also execute the Security Erase function, perform a Zero-Fill, NIST 800-88, and DoD 5220.22-M compliant wiping. ATA password removal to gain access to locked hard drivesThe Atola Forensic Imager comes equipped with a powerful Automatic Password Removal function. This function removes any User Level ATA password from a locked hard drive and displays the password to the user. The password can also be extracted (displayed for the user) without unlocking the hard drive. Please visit the Password Removal page for further details. Note: Unlocking the hard drive does not affect hash values because the password is stored in the hard drive’s system area (which is never included in hash calculation by any forensic product). Built-in case management for effective record keepingThe Atola Forensic Imager’s Case Management system automatically records every step of the data extraction and acquisition process. Every action performed is automatically recorded (including date, time and hash values) and filled by a unique case number. When a hard drive is imaged, a media map is recorded that details all sectors that have been skipped along with other vital information. Case notes can be added at any time with one click of the mouse to log information such as the case technician or owner of the hard drive. Archives of all past cases are stored on the host PC, which can be searched by case # or any keyword. Please visit the Case Management page for further details Key differences between this product and Atola Imager (non-forensic version)The Atola Forensic Imager has all of the same functions as the Atola Imager, and also has the following 3 functions for forensic investigation and e-discovery data capture.
Frequently Asked QuestionsClick questions to expand text
|






