Dell and AccessData Launched New Forensics Toolkit

Dell and computer forensics specialists Access Data have released their new Dell Digital Forensics Platform and Forensic Toolkit 4.0 at the International Security and National Resilience (ISNR) exhibition in Abu Dhabi.

adWP_logo

“Today’s launch of the FTK 4.0 is a significant milestone that marks the next phase of our efforts here in the Middle East. This release, which is unlike any other previously seen in the region, enables court-cited digital investigations and is built for speed, analytics and accuracy,” said Simon Whitburn, VP International Sales at AccessData.

The new forensics tool expands on AccessData’s existing solutions, to provide a turnkey solution for a wide range of investigative operations, including processing of forensic images and email archives; registry analysis; file decryption, password cracking, image creation and report building.

AccessData offers two expansion modules with the new version-Cerberus, a malware triage technology that provides threat scores and disassembly analysis to determine both the behaviour and intent of suspect binaries, and Virtualization for relationship analysis in multiple display formats, including timelines, cluster graphs, pie charts and more.

“We developed the combined platform in response to significant customer demand, in large part from this region. Dell has worked with us to provide a turn key digital forensics solution that enables our clients to get mobile very quickly. Partnerships with such leading organizations will play a pivotal role in our expansion in the region,” said Whitburn.

Access Data: http://accessdata.com/

AccessData is the leading provider of E-Discovery, Computer Forensics and Cyber Security software for law firms, corporations and government agencies

Dell Digital Forensics

In digital forensics cases, Dell can provide the tools and resources you need to process digital evidence, quickly and reliably. Click the below link to learn more:

http://content.dell.com/us/en/fedgov/fed-solutions-digital-forensics

Read More

Disk Imaging: Image by selective head(s)

Drives presented for recovery sometimes have some heads or surfaces damaged (physical damage). The problem is severe enough for the drive to stop working in its native system. However, with the latest upgraded Data Compass DCEXP utility, it is possible now (before installation of MHA replacement) to create a copy of data using the remaining good surfaces or drive heads; small files can even be recovered directly.

What’s more, this procedure will also be essential in cases:

1. When the drive is having read instability problem: by reading the surfaces one by one, it greatly reduces the seek time & times, smoothes the reading of the data, thus in some cases the original “damaged” head or surface becomes available, and users will then have no need to perform a risky MHA replacement.

2. When users have only a donor MHA with some heads damaged also: we can use the native head to read the available data first and then replace it with the donor one for reading the available data; if these two MHAs happen to be a complement to each other (for example native MHA with head 1 damaged, and donor MHA happens to have head 1 remained good), even in fact we don’t have/use a good MHA at all, we can recover all the data on the drive.

See More: Image by selective heads

Read More

Free Hard Disk Drive Diagnostic Utility For Samsung Hard Drive

Samsung Free Hdd Diagnostic Tool Note: The following free hard disk drive utilities and diagnostic tools are only for Samsung Hard Disk Drives. Using any of these utilities on a hard disk drive that was not manufactured by Samsung will have adverse effects on that hard disk drive.

Hardware Utilities

Disk Manager provides support for Dynamic Drive Overlay, which will allow older BIOSes to support large-capacity hard drives. Disk Manager can also partition the drive. (Note: Registration information needed for downloading)

  • Disk Manager for FDD
  • Disk Manager for CD Rom

Hardware Diagnostics

There are three utilities depending on the model of your hard disk drive for diagnosing hardware problems and performing low-level formats:

SHDIAG is a hardware diagnostic for older Samsung hard drives. Backing up data before using SHDIAG is strongly advised.

Hard Disk Drive Series

Model Number

Spinpoint V20400

SV4084D, SV3063D, SV2042D, SV1021D, SV0761D

Spinpoint V15300

V3064D, SV2043D, SV1532D, SV0761D

Spinpoint V10200

SV2044D, SV1533D, SV1022D, SV0511D

Spinpoint V9100

SV1824D, SV1363D, SV0842D, SV0431D

Other Older Models

SV2046D, SV1705D, SV1364D, SV1023D, SV0682D, SP1828D, SP1366D, SP0914D, SV1296D, SV0844D, SV0643D, SV0432D

HUTIL is made with the aim of testing a Samsung hard disk drive while it is installed inside a PC, regardless of the status of user’s operating system. It is a good idea to test drive that is having problems with HUTIL to see if it is truly defective to avoid possible unnecessary troubleshooting or factory service. HUTIL includes EraseHDD, a utility that will perform a low-level format including the partition table and Master Boot Record.

Hard Disk Drive Series

Model Number

SpinPoint F1

HD161GJ, HD162GJ, HD251HJ, HD252HJ, HD322HJ, HD501IJ, HD502IJ, HD752LJ, HD753LJ, HD102UJ, HD103UJ

SpinPoint F1 CE

HA251HJ, HA321HJ, HA501IJ, HA751LJ, HA101UJ

SpinPoint F1 RAID

HE322HJ, HE502IJ, HE753LJ, HE103UJ

SpinPoint S250

HD162HJ, HD200HJ, HD250HJ

SpinPoint S250 CE

HA250HJ, HA161HJ

SpinPoint N2

HS030GB, HS031GA, HS040HB, HS041HA, HS04THB, HS060HB, HS061HA, HS06THB, HS080HA, HS080HB, HS081HA, HS082HB, HS10TJB, HS120JB, HS122JB

SpinPoint N1

HS122JC, HS08XJC, HS10XJC/M

SpinPoint M5

HM201JI, HM250JI, HM061GI, HM080GI, HM121HI, HM160HI, HM160HC, HM121HC, HM080GC, HM061GC

SpinPoint MH80S

HM08HHI, HM12HII, HM16HJI

SpinPoint S166

HD041GJ, HD081GJ, HD042GJ, HD082GJ, HD120HJ, HD161HJ

SpinPoint T166

HD251KJ, HD252KJ, HD320KJ, HD321KJ, HD402LJ, HD403LJ , HD500LJ, HD501LJ, HD080GJ, HD160HJ, HD300JJ, HD301JJ, HD320JJ, HD321JJ

SpinPoint T133

HD250KD, HD250KJ, HD300LD, HD300LJ, HD301LJ, HD320LD, HD320LJ, HD321LJ, HD400LD, HD400LJ, HD401LJ

SpinPoint P80SDH

HD121IJ, HD161JJ

SpinPoint P80SD

HD040GJ, HD080HJ, HD120IJ, HD160JJ

SpinPoint M80

HM040GI, HM040GC, HM061HC, HM062HI, HM080HI, HM080HC, HM100II, HM100IC, HM120II, HM120IC, HM160JI, HM160JC

SpinPoint M60

HM020GC,HM021GI, HM030GI, HM030GC, HM040HC, HM041HI, HM042HI, HM060HI, HM060HC, HM061HI, HM080II, HM080IC, HM081II, HM100JI, HM100JC, HM101JI, HM120JI, HM120JC, HM121JI

SpinPoint P80VEM

SP0451N, SP0842N

SpinPoint P80VEA

SP0822N

SpinPoint P80M

SP1243N, SP1253N, SP1644N, SP1654N

SpinPoint P80A

SP0431N, SP0441N, SP0832N, SP1223N, SP1233N, SP1624N, SP1634N

SpinPoint P120

SP2014N, SP2514N, SP2004C, SP2504C

SpinPoint V120

HA250JC, HA200JC, SP2504N, SP2004N, SP1603N, SP1613N, SP1202N, SP1212N, SP1603C

SpinPoint M40

MP0302H, MP0402H, MP0603H, MP0804H,HM040HI, HM060II, HM080JI

SpinPoint P80

SP0211N, SP0401N, SP0612N, SP0802N, SP0812N,SP1203N, SP1213N, SP1604N, SP1614N, SP0812C,SP1213C, SP1614C, SP0822N

SpinPoint V80

SV0401N, SV0802N, SV1203N, SV1604N, SV0211N, SV0612N, SV0802E, SV1203E, SV1604E

SpinPoint VL40

SV0211H, SV0311H, SV0401H, SV0411N, SV0211N

SpinPoint PL40

SP0411N, SP0211N, SP0311N, SP0411C

SpinPoint V60

SV1204H, SV0813H, SV0602H, SV0301H

SpinPoint P40

SP8004H, SP6003H, SP4002H, SP2001H, SP80A4H, SP60A3H, SP40A2H, SP20A1H

SpinPoint V40

SV8004H, SV6003H, SV4002H, SV2001H, SV8014H, SV6014H, SV6013H, SV4012H, SV3012H, SV2011H

SpinPoint V30

SV6004H, SV4003H, SV3002H, SV2002H, SV0802H

SpinPoint P20

SP4004H, SP3003H, SP2002H, SP1001H

SpinPoint V20400

SV4084H, SV3063H, SV2042H, SV1021H, SV0761H

  • HUTIL for FDD       
  • HUTIL for CD Rom

SUTIL is a utility for older Samsung hard drives that will format them and reset their DMA Modes.

Hard Disk Drive Series

Model Number

Spinpoint V20400

SV4084D, SV3063D, SV2042D, SV1021D, SV0761D

Spinpoint V15300

V3064D, SV2043D, SV1532D, SV0761D

Spinpoint V10200

SV2044D, SV1533D, SV1022D, SV0511D

Spinpoint V9100

SV1824D, SV1363D, SV0842D, SV0431D

Other Older Models

SV2046D, SV1705D, SV1364D, SV1023D, SV0682D, SP1828D, SP1366D, SP0914D, SV1296D, SV0844D, SV0643D, SV0432D

  • SUTIL for FDD

Data Advisor®

Data Advisor is a free hard disk drive diagnostic utility available from http://www.ontrack.com/dataadvisor/. Data Advisor quickly assesses the health of your hard disk drive, file structures, and computer memory by identifying problems that could cause data loss. Don’t worry if you can’t boot your system to Windows; Data Advisor is self-booting, so it runs even when your system won’t.

Note: Ontrack DataRecovery is not associated with Samsung, Inc.

Read More

Comparison of Software RAID on Windows versus Linux

The basic idea of RAID (Redundant Arrays of Inexpensive Disks) is to combine multiple small, independent disk drives into an array of disk drives which yields performance and recoverability exceeding that of a Single Large Expensive Drive (SLED). Redundancy is also provided (unless RAID 0) which allows easy and often automatic recovery from hard disk crash. With the reduction in price of ATA and SATA drives it is often a good idea, even for desktop computers, to setup a RAID 1 system to allow you to function in the event of hard disk failures. In RAID 1 two hard disks (or portions of them) mirror each other. RAID 1 is essential for our environment. I have tested both Windows software RAID facility as well as Linux RAID capability. Linux RAID support is way superior to Windows and should by itself be the reason to switch to Linux. I have given 4 reasons to support my claim below.

Linux supports RAID on block devices. So you can setup RAID between two partitions on the same hard disk or even on two RAID 0 arrays, effectively creating RAID 10 array. Windows simply supports RAID 0 and GBOD (known as linear on Linux) only for non-server users. Linux support all RAID variants. Even Windows server doesn’t support the intermediate RAID variants.

In Linux as well as Windows you can create RAID arrays spanning machines.

In Windows you cannot install the operating system on RAID. In Linux you can even install the operating system on RAID file system. This means if one of the hard disk dies you can easily boot from the other hard disk (assuming you transferred the MBR earlier).

If you have spare hard disks, Linux will automatically configure it and add to the RAID array, should one of the RAID disks fail. This is to my knowledge not possible in Windows.

Linux RAID can be easily configured during installation. All the partitions (/, /opt and even swap) can and should be RAID enabled. Windows RAID is harder to configure and is done after installation of the OS, from disk management.

Comprehensive RAID support by itself (not to mention security) should be reason enough for SMB servers to switch to / use Linux.

Read More

Seagate hard drive data recovery data recovery

Case:Customer name: Siemens Company’s hardware operating environment: Seagate 7200.12ST3500418AS software operating environment: Winxp file system: NTFS fault phenomenon: Customer adopting measures: Directly sending data recovery company data recovery process received after the after -disc engineer detection and found that the sound of hard disks was very sound.Normal, the hard disk has been busy, not ready.Read…

Read More