Forensic Cube V3


All-in-One Solution for Crime Scene Investigations. A portable and versatile computer forensics equipment. Highly-integrated hard disk duplication, data analysis and system emulation functions in a magic box.

Hard Drive Imaging
  • 1-to-1, 1-to-2, 2-to-2 disk duplication

  • Support IDE, SATA, SAS, SCSI, USB

  • Duplication speed up to 39GB/min     

  • Keyword searching during duplication

  • Acquisition in HPA/DCO protected area

  • Support MD5 and SHA-1 hashing during duplication

  • Recovery image to hard disk

  • Remote duplication through network

Forensic Analysis
  • Quick and automated forensic analysis

  • Evidence preview

  • Data recovery (FAT32,NTFS, ReFS, HFS+ etc.)

  • Fast indexing and keyword searching

  • Enctypted volume/file decryption, eg. BitLocker, TrueCrypt, FileVault 2

  • Instant messenger, browser history, user access and email analysis

  • Quickly recover deleted mails on Foxmail and Outlook Express

OS Emulation
  • OS emulation allows a direct view on the suspect computer

  • Dynamic emulation helps malware / website / database analysis

  • Acquire saved passwords (dial-up, MSN messenger, browser, PSSP) on emulated computer

  • Bypass login password to emulate Windows and Mac OS

  • Emulate mounted raw, 001, or E01 image files, and physical disk with write-blocker

  • Support popular Windows, Mac, Linux operation system