Friday, April 20, 2012

Comparison of Handheld Forensic Duplicators

Let me start by saying that I have been fortunate to have had the ability to try out a number of different duplicators in my career.  For this post I want to show some of the strengths and weaknesses of three of the duplicators that I currently use on a semi-regular basis.

The first I would like to discuss is the Talon Enhanced by Logicube.

The second I would like to discuss is the TD2 by Tableau.

The third and final is the Forensic Dossier also by Logicube.

The Talon Enhanced and the TD2 are very similar machines.  The Forensic Dossier has a few extra capabilities that I will discuss in the Dossier section (coming soon).  I will detail a couple speed tests that I have done with the tools.  I will also list some strengths, weaknesses, and key difference between the tools.

All three tools report roughly the same transfer speeds.  It is my hope to document tests I have personally run using the same Hard Drives in each test.  This will show some differences that you can draw conclusions from yourselves.

The Talon Enhanced
Strengths:
  • Formats Destination FAT32 or NTFS
  • Will create two copies of the source (can copy simultaneously to two destinations)
  • Can act as a write-blocker via USB or eSATA for computer access
  • Stealth mode to hide what the Talon is currently doing
  • Will image to E01 (compressed and non-compressed) or DD (Raw) format.
  • Full QWERTY keyboard for inputting case information 
  • Touch Screen for easy navigation
Weaknesses:
  • (10/May/2012) As of release 1.1.1RC22 the Talon now logs the time of processes! 
  • Larger than the TD2, however with the first destination located inside, the desk space is about the same.
Key Differences from the TD2:
  • Source inputs from the top of the Talon and the Destination/s go inside or to the right.
  • Has NTFS Format Option
  • Allows examiner to plug the Talon into a computer via USB or eSATA and use as a write-blocker.
  • Options to wipe once (1) or DoD wipe which wipes seven (7) times.  TD2 offers one (1) wipe or three (3) wipes  
  • Gives options for compressed E01 and non-compressed E01
Speed Tests:
Source is a Samsung 64GB SSD 830 Series Model: MZ -- 7PC064 with 44.7 GB of data on it
Destination is a WD 500GB HDD Model: WD5000KS wiped previous to each image.

Speed Test 1:
Destination formatted FAT32, E01 option with compression, Hashed
Time to completion:    00:30:50
Size of Image:   44.7 GB

Speed Test 2:
Destination formatted FAT32, E01 option with no compression, Hashed
Time to completion:  00:31:36 (yes it took longer w/o compression)
Size of Image:    59.6 GB

Speed Test 3:
Destination formatted FAT32, DD, Hashed
Time to completion:   00:30:38
Size of Image:    59.6 GB

Speed Test 4:
Destination formatted NTFS, E01 option with compression, Hashed
Time to completion:    00:29:58
Size of Image:    44.7 GB

There are more options available for imaging but I believe that the above four (4) give a reasonable showing of the Talon's capabilities.

TD2
Strengths:
  • Size, The TD2 is smaller than the Talon.
  • Will create two copies of the source (can copy simultaneously to two destinations)
  • Will image to E01 compressed or DD (Raw) format.
  • Logs the time for an image to complete as well as the average speeds.  
  • All Tableau tools are updated using the same update utility.
  • Quick Start.  Allows user to setup a common setup and use it as the first and only option
Weaknesses:
  • Does not Format destinations NTFS.  Tableau has said that an ExFAT option will be released later this year.
  • Only seven buttons that are used with up and down arrows for inputting case information.
  • In my tests the TD2 image time logs were off by about 30 seconds.  It recorded a time 30 seconds faster than the actual time on a 64GB source. 
Key Differences from the Talon Enhanced:
  • Source drive is placed on the left and destination is placed on the right
  • Options to wipe once (1) or three (3) times.  Talon Enhanced and Dossier offer one (1) wipe or DoD wipe which is seven (7) passes.

Speed Tests:
Source is a Samsung 64GB SSD 830 Series Model: MZ -- 7PC064 with 44.7 GB of data on it
Destination is a WD 500GB HDD Model: WD5000KS wiped previous to each image.

Speed Test 1:
Destination formatted FAT32, E01 option with compression, Hashed
Time to completion:   00:31:07
Size of Image:   44.5 GB

Speed Test 2:
Destination formatted FAT32, DD, Hashed
Time to completion:    00:32:35 (yes this is slower than an E01 w/compression)
Size of Image:    59.6 GB

Forensic Dossier:
Coming Soon...

www.h11dfs.com

~Hew

Monday, April 16, 2012

I added X-Ways forensics to the "Current Versions" page

X-Ways has been added to the "current versions" page

I also added Win Hex which can be found on their home page as well.

www.x-ways.net

~Hew

Katana releases a new version of Lantern

Katana has released a new version of Lantern.  Version 2.3

I also added Lantern Lite Imager to the current versions page.

www.katanaforensics.com

~Hew

Access Data releases a new version of the FTK

FTK 4.0.1 has been released.

Quite a bit has been updated with this release.
http://accessdata.com/downloads/current_releases/ftk/FTK_4_0_1_RN.pdf

From the Release notes:
  • You can now obtain metadata from PDFs.  This feature also allows you to extract attachments, but not embedded graphics.
  • Additional Registry data processing
  • New index processing option "Do Not include document metadata in filtered text"
  • Speed for optical character recognition has been improved
  • KFF processing through a Postgres SQL database has been improved
  • Reporting process times for the log file and progress window have been improved
  • When bookmarking index.dat entries, the 'Create Bookmark' dialog now provides an option to include the entry's parent index.dat file in the bookmark
  • Improvement in the exportation of NSF emails into MSG format
  • A new default filter named 'Cerberus Static Analysis' has been added to let you see the files that have had Cerberus Stage 2 Analysis run against them
  • Improved support for finding hidden processed
For more information visit accessdata:
www.accessdata.com

~Hew

Monday, April 9, 2012

Tableau has released a new Firmware Updater

Tableau has released firmware updater 6.90!

Looking in the Firmware Versions section of the updater the only update I see is a new TD2 update.

This takes the TD2 to version 3.15

www.tableau.com

~Hew

Wednesday, April 4, 2012

Guidance Software has released a new version of EnCase

EnCase 7.03.02 has been released.

The primary bug fixes they have listed are the following:
  • HFS+ hard link, Extents Overflow and .rtd files not reading correctly on Apple Macintosh computers
  • Data in HFS+ resource forks not displaying correctly.
  • File Carver using default length instead of footer to carve files.
  • Compound queries with "and" or "or" operators not completing in certain cases.
www.guidancesoftware.com

I will be reading all of the release notes and playing with the new build more this week.  I will post more on version 7.03.02 the beginning of next week.

~Hew

I read up on the the release notes, and there are a few more things to be mentioned.

  • Fixed an issue where acquiring a remote device via the evidence processor always resulted in the same acquisition hash for an Ex01 file
  • Fixed an issued where the Evidence tab "rescan" capability was not working
 ~Hew