Atola Insight now supports logical imaging of APFS partitions. Encrypted APFS volumes can be unlocked in File Recovery with a known password or recovery key. To start the imaging, select All sectors with data in imaging settings and click Start imaging.
Now you can search artifacts on a drive not only in the course of imaging, but as a separate operation, both on sources and targets.
Go to Artifacts Finder in the left-side menu. You will now see if any artifacts have previously been looked for. If you want to make an additional search, select the artifacts you are interested in, and click Start button.
Forensic & Data Recovery Tool
Atola Insight Forensic offers complex data retrieval functions along with utilities for manually accessing hard drives at the lowest level, wrapped in a very simple and efficient user interface.
The tool is developed by a team of industry renowned data recovery engineers in collaboration with law enforcement agencies and forensic experts from around the globe.
Atola Insight Forensic system includes:
- Atola Insight Forensic software (runs on any Windows PC or laptop)
- DiskSense hardware unit
- Hardware extensions (optional)
- Battery (optional)
Forensic and E-Discovery solution
All features of the system are designed to support damaged media. Where other Forensic data acquisition products stall or abort on media errors, Atola Insight Forensic can acquire a usable image.
When dealing with good (non-damaged) media, Atola Insight Forensic acquires data faster than any other data acquisition equipment commercially available.
The system has several key features for data capture in forensic and e-discovery cases:
- Fastest in industry imaging speed up to 500 MB/s
- High performance multi-pass imaging for damaged drives
- In-depth Automatic HDD diagnostics
- Extraction of unknown ATA Passwords
- Case management system prepares acquisition reports automatically
- Hash calculation: MD5, SHA1, SHA224, SHA256, SHA384, SHA512
- Forensic data erasure methods including DoD 5220.22-M, Security Erase, NIST 800-88, Pattern Erase
- File recovery for NTFS (all versions), Ext 2/3/4, HFS, HFS+, HFSX, ExFAT, FAT16, FAT32
- Support for SATA, IDE, SAS, USB media
- Support for Apple PCIe (2013 – recent models) and M.2 PCIe SSDs via Atola extension modules
- Built-in write blocker
- Optional 10Gb Ethernet via extension modules
- Network forensics via SSH
Acquiring data from damaged media
1. HDD Diagnosis
A successful acquisition job starts with accurate diagnosis of the media. The Atola Insight Forensic is the ONLY product in both data recovery and forensic industries with the ability to accurately evaluate a hard drive’s health and pinpoint specific problems. This feature puts our users at a major advantage by enabling them to take all factors into account before moving forward with data acquisition.
2. ATA Password Removal and Firmware recovery
The system properly recognizes locked hard drives and allows for a fully automated extraction or removal of an unknown ATA password with a single click of a button.
When a hard drive is experiencing firmware problems, it is not usually accessible using conventional data acquisition tools or imaging utilities. The Atola Insight Forensic recognizes firmware corruption using its advanced diagnostic module and repairs it with the click of a button for supported HDD models. For non-supported HDD models, the Atola Insight recognizes firmware corruption and provides direct access to firmware files (modules), enabling expert technicians to manually repair the corruption.
3. HDD Duplication / Backup Image Creation
Extracting every fragment of data from hard drive is a crucial part of the data acquisition process. The Atola Insight’s duplication/imaging system allows the user to completely customize the imaging process to suit each job, even when dealing with damaged or unstable media.
This module now comes standard with SELECTIVE HEAD IMAGING, allowing the operator to identify the status of individual read/write head and create an individual imaging approach for each one.
See the Disk Duplication page for details
4. File Recovery
File recovery is the last phase of most data acquisition jobs. The Atola Insight’s file recovery engine is simple, intuitive, and effective. It integrates seamlessly with Disk Duplication and Case Management systems to effectively extract data.
Advanced password removal capability
Atola Insight Forensic automatically removes ATA passwords from hard drives in just 2 minutes. This highly complex feature can be executed by the operator with one click of a button and the password is displayed after it is removed whenever possible.
Well-rounded feature set
Atola Insight Forensic comes equipped with a range of utility features for each step of the data acquisition process. These features include device configuration for modifying hard drive parameters, HDD current monitoring for continuous diagnosis, a disk editor for modifying hard drive data, and an add/remove password function.
Smooth case management from start to finish
Atola Insight Forensic is the only data recovery product that was built with case management in mind. All functions are tied in to one-another and the system tracks and records every action taken with a given hard drive. If a session is stopped and the hard drive is disconnected from Atola Insight and then later reconnected, the system will recognize the hard drive and give the operator the option to re-open the case.