CRU Digital Forensics

History of the CRU and 4Secure partnership

4Secure’s team of digital forensic practitioners have gained a wealth of experience through practical and real life forensics acquisitions for law enforcement agencies, military and commercial entities alike. This experience and expertise has been valuable in the creation of 4Secure’s digital forensics lab and it’s from this lab development that our practitioners assessed the market place to find the best tools to conduct quick acquisition and analysis of case sensitive data.

4Secure evaluated all forensic acquisition tools and from this worked to secure a working partnership with CRU Wiebetech in the US. CRU’s digital forensic tools were found to be incredibly versatile, mobile and importantly excellent value. 4Secure continue to use CRU’s suite of tools to conduct its own forensic acquisitions but also provide this equipment to other practitioners. Our sales team is backed by the expertise of practitioners allowing us to provide real world examples of the equipment being used, but also ensure our clients receive the right equipment allowing them to be successful with their own digital forensic ambitions.

4Secure has never been an out-and-out reseller and chooses its partners wisely. We work alongside CRU to provide new and innovative solutions to the marketplace. Using the CRU hardware as it’s backbone the 4Secure examine was created to be an all in one, highly capable digital forensics acquisition and investigation workstation. This machine is designed and built by forensic practitioners for forensic practitioners, priced sensibly 4Secure has removed the need for forensic investigators to build their own unsupported workstations and each and every unit we provide comes with a 12 month(+) warranty supported by our own forensics team. In addition, 4Secure has brought a new way of procuring digital forensics workstations to the market, we offer a simple out and out purchase or the ability to buy a manged service offering from 4Secure where we provide and maintain the equipment for a monthly service cost. This puts an end to securing budget to keep the digital forensics lab current and eliminates the need for consistent IT refresh.

4Secure also drove the development of the 4Secure erase, whilst not strictly a digital forensics tool, we adopted CRU hardware to create a hard disk erasure tool that has been certified by CESG to wipe to IAS5 standard. This device is both simple to use and puts an end for the need to buy licences for each and every hard disk erasure, representing a cost saving to the market Through the ability to reduce IT spend by recycling and repurposing IT equipment, but our one-off device cost has no lifecycle costs associated with it. The erase is currently making waves in the market place for public and private sector clients all thanks to the 4Secure/CRU partnership.

Arguably the staple of CRU’s forensic tools is the Ditto range, the product that first attracted us to CRU. The hand-held Ditto Forensic FieldStation is a compact mobile device designed for creating local, remote, or networked disk clones and images, including logical imaging of user-selectable lists of files and folders. With remote triage supported via in-built network connectivity the Ditto delivers an impressive range of features to the market at an unrivalled price point ensuring it’s place as our “go-to” device when conducting forensic investigations. Our findings have been further supported by the glowing independent review conducted by SC magazine where the device was found to be an “Excellent imager with lots of bells and whistles. The only imager you’ll ever need.” You can read that on the SC magazine website. 

To speak to our forensic sales team to discuss your requirements, please contact us.

Ditto-DX Forensic FieldStation
4secure-examine-main
edit-1-small1

Ditto DX Forensic FieldStation

Next-generation imaging

The Ditto® DX Forensic FieldStation is the latest addition to the Ditto Forensic FieldStation family, with the same great usability features as the original Ditto device.

Ditto DX performance has been optimized for various forms of media, including SSDs, NVMe/PCIe, hard drives, SD and CF cards, and others.

Time-saving Logical Imaging

With hard drives and networked file shares exploding in size, Logical Imaging is more important than ever. Ditto DX Logical Imaging performance is twice that of the Ditto device. And with automatic, pre-selected search and acquire capability, Ditto DX slashes the time it takes to capture needed evidence.

Remote operation

An easy-to-use web browser interface supports remote operation via network or VPN, providing access to Ditto configuration, user administration and user rights, as well as direct operation of Ditto cloning and imaging operations. Ditto DX improves on Ditto with separate Ethernet and USB 2.0 ports so Ditto DX can be managed without impacting imaging performance.

Create logical and physical images in the field

The built-in menu system makes it easy to configure and perform forensic captures of selected files–without an attached computer. Generate complete listings of drive or file system contents to facilitate discovery, or automatically capture specific file types.

Suspect Inputs (write-blocked)

Ditto natively supports many write-blocked inputs: SATA, eSATA, PATA, USB3.0/2.0. Additional acquisition interfaces are available via expansion modules, such as the Ditto SAS Expansion Module and Ditto FireWire Expansion Module.

Destination Outputs

Use dual SATA outputs simultaneously with same performance as one eSATA (single, dual and mirrored). Images can also be output to large volumes, including NAS and other network destinations, as well as portable RAID enclosures.

Data Acquisition Modes

Clone, DD, E01, L01 with MD5 or SHA-1 hashing. Ditto DX also offers a combined mode that captures a clone and DD (to different destination drives) in a single pass reading of the suspect drive.

Complete and Secure Erasure

Ditto DX is capable of sanitizing drives with preset erase modes or a user configurable pattern.

Water-resistant, dust-proof Pelican® custom carrying case available

Convenient, customized field kits are available for Ditto and accessories.

Ditto-DX Forensic FieldStation
Top Ditto DX Forensic Fieldstation
source_ditto_dx-300x198
dest_ditto_dx-300x198

Forensic UltraDock

Digital and forensics investigators, technicians, and lawyers who want to view, evaluate, or image a disk drive safely rely upon the CRU® WiebeTech® Forensic UltraDock™. It’s an easy-to-use, professional-grade drive dock that provides multiple host and drive connection types.

To use, connect a suspect hard drive–IDE or SATA–to the Forensic UltraDock, plug in power, and attach a cable to the host computer. The drive connector enables automatic alignment and easy insertion. The Forensic UltraDock’s LED indicator light and easy screen menu also clearly identify the work mode.

The Forensic UltraDock detects and indicates hidden areas of the drive (HPA and/or DCO) automatically, and allows you to choose on-the-fly whether or not to temporarily or permanently unhide them. The LCD menu makes such selection easy–no complicated DIP switches to set.

The Forensic UltraDock’s LCD puts drive information at your fingertips. Quickly access selected important SMART data such as hours used, number of power cycles, and disk health. It can also display the model and serial number reported by the drive’s firmware. Free downloadable software can also allow you to view this information on your computer and save it to a file for easy inclusion in a case report.

The Forensic UltraDock model FUDv5.5 has USB 3.0, USB 2.0, eSATA, and FireWire 800 host connections. It natively supports the most common types of drives, such as SATA and IDE/PATA, but if you need to work with a non-standard drive, there are a variety of adapters available for additional flexibility.

Additional features:

  • Compatibility with forensic acquisition and analysis software
  • Rugged aluminum construction
  • Industry-leading 3-year warranty
  • Free US-based customer support
forensic-ultradock-main-300x198
top-forensic-ultradock-300x198
ports-forensic-ultradock-300x198

Forensic ComboDock

Digital and forensics investigators, technicians, and lawyers who want to view, evaluate, or image a drive safely rely upon the CRU® WiebeTech® Forensic ComboDock™. It’s an easy-to-use, professional-grade, dual mode dock that provides a plethora of host and drive connections.

To use, connect a suspect hard drive to the Forensic ComboDock, plug in power, and attach to your computer. The drive connector enables automatic alignment and easy insertion.

When turned on, the Forensic ComboDock asks you to choose either write-blocking or read/write mode. If you need to modify contents of a suspect drive, switch the Forensic ComboDock into temporary read/write mode.

Even though switching from write blocker mode to read/write mode is easy, the Forensic ComboDock v5 makes it impossible to unintentionally turn off write-blocking. This prevents problems that can occur if you forget to change the mode back to write-blocking.

The Forensic ComboDock’s LED indicator and easy screen menu also clearly identify the operating mode. You can even detect, remove, or modify Host Protected Areas (HPAs) and Device Configuration Overlays (DCOs) that may be hiding additional data on the suspect drive.

The Forensic ComboDock puts drive information at your fingertips. Quickly access selected important SMART data such as hours used, number of power cycles, and disk health. It can also display the model and serial number reported by the drive’s firmware. Free downloadable software can also allow you to view this information on your computer and save it to a file for easy inclusion in a case report.

The Forensic ComboDock model FUDv5.5 has USB 3.0, USB 2.0, eSATA, and FireWire 800 connections, and works natively with the most common types of hard drives such as IDE/PATA and SATA. But if you need to work with a non-standard drive there are a variety of adapters available for additional flexibility.

Additional features:

  • Multiple computer and drive connection types, including USB 3.0
  • Compatible with forensic acquisition and analysis software
  • Rugged aluminum construction
  • 3-year warranty
  • Free US-based customer support
main-forensic-combodock-300x198
top-forensic-combodock-300x198
ports-forensic-combodock-300x198

USB 3.0 Writeblocker

Digital forensics investigators, lawyers, and corporate IT staff who want to view, examine, and image drives quickly and easily, look to the CRU® WiebeTech® USB 3.0 WriteBlocker™ to ensure they are protecting and not altering data.

The handheld and lightweight USB 3.0 WriteBlocker connects via a Windows operating system host’s USB 3 interface to allow investigators and technicians to look through the contents of a drive without risking any damage or disruption of source data. To use, simply use the included USB 3.0 cable to connect the USB 3.0 WriteBlocker to the drive or drives you wish to inspect.

Additional features:

  • Bus powered
  • Status LED indicates if drive is safe to inspect
  • Industry-leading 3-year warranty
  • Free, US-based customer support
main-usb-3-writeblocker-300x198
ports-usb-3-writeblocker-300x198

Forensic LabDock U5

“Create a write blocked workstation for hard drives and thumb drives”

Forensics investigators, technicians, and system builders who want to create a digital forensic workstation rely upon the CRU® WiebeTech® Forensic LabDock™ U5. Installed in a standard 5.25″ PC bay, the Forensic LabDock U5 gives convenient, front-panel access to suspect hard drives and thumb drives. Write-blocking is done in hardware, with proven WiebeTech write-blocking technology.

In addition to providing native write-blocked access to SATA and IDE drives, the Forensic LabDock U5 model also incorporates a USB WriteBlocker, so you can forensically access USB thumb drives or many USB drive enclosures.

Do you know what could be lurking in the hidden areas of a hard drive? HPA (Host Protected Areas) or DCO (Device Configuration Overlays) can exist on hard drives, which are not detected or accessible by your operating system. The Forensic LabDock U5 will alert you if these areas exist, so you can inspect them. The Forensic LabDock U5 comes with software to let you choose how to handle any hidden areas it encounters.

Forensic LabDock U5 offers native connections for the most common drives types, such as SATA and IDE/PATA. Optional SATA and PATA Adapters are available that allow access to many additional types of drives such as ZIF drives, notebook drives, drives found in iPods, and more. SATA and PATA Adapters work with many of our docking products, including the Forensic LabDock.

Additional features:

  • 2-year warranty
  • Includes cables
  • Free US-based customer support

Whether you’re a forensic investigator, technician, or cyber security analyst, the CRU WiebeTech Forensic LabDock is a necessary part of your toolkit.

main-forensic-labdock-u5-300x198
side-forensic-labdock-u5-300x198

captcha