ZXi-Forensic Forensic Imager

Digital forensic labs or organizations that routinely handle large amounts of evidence data for review or analysis can take advantage of the ZXi-Forensic’s three Gigabit Ethernet ports, fast imaging speeds of over 50GB/min and advanced features to streamline processes. The solution provides a network “Push” feature that allows users to upload images from up to 3 evidence drives directly to a network repository simultaneously. Add the optional 3 drive expansion kit to push up to a total of 5 evidence drives. The ZXi-Forensic’s ability to image up to 3 source/suspect drives directly to a network repository and at the same time image to 3 destination/evidence drives (add the expansion kit to image up to 6 destination drives) provides efficiency and quick access to forensic evidence data.


  • High speed imaging at over 50GB/min*.
  • Multi-target, volume imaging: Image from 3 suspect drives simultaneously to network repositories using 3 Gigabit Ethernet connections; image from 3 source drives directly to 3 destination drives; image from 3 source drives to network repositories and simultaneously image to 3 destination hard drives. Use the optional expansion kit to add 3 additional destinations.
  • Supports dd, ex01, e01 or native imaging formats. User selectable MD5 or SHA-1 or SHA-256 verification is available. Dual hash (MD5+SHA-1) planned for a future release.
  • Use the Network Push feature to upload evidence drive images that were captured using the Forensic Falcon or the ZXi-Forensic to a network repository. Push from up to 3 evidence drives simultaneously on the base unit or add the optional expansion kit and push from up to 5 evidence drives. An MD5 or SHA-1 hash is performed during the process and a log file is generated for each push task.
  • Image to or from a network location. Use the ZXi-Forensic to image to a network location using CIFS protocol and/or image from a network location using iSCSI. Users can use iSCSI as a source or destination drive.
  • Supports imaging to and from USB enclosures and USB thumb drives. 1 USB 3.0 source port and 2 USB 3.0 destination ports are available.
  • Write-protected source drives. All ZXi-Forensic source ports are automatically write-blocked to prevent any alteration to sensitive data on the source drive.
  • The ZXi-Forensic has built-in support for 3.5”/2.5” SAS or SATA hard drives. 1.8”/2.5”/3.5” IDE and IDE ZIF drives, eSATA, microSATA, mSATA and compact flash media are supported with optional adapters. The ZXi-Forensic supports SSDs.
  • Optional 3 drive expansion kit provides an additional 2 SAS/SATA and 1 SATA for a total of 6 SATA or 5 SAS destinations.
  • Remote Operation. Connect the ZXi-Forensic to your network and allow remote access from any computer within the same network. A web-based browser interface provides easy navigation.
  • Write-blocked preview/triage of hard drive contents. Preview/triage the drive contents directly on the ZXi-Forensic. The file browser feature provides logical access to source or destination drives connected to the ZXi-Forensic. Users can view the drive’s partitions and contents, and view text files, jpeg, PDF, XML, HTML files. Other files types (such as .doc and .xls) can be viewed by connecting ZXI-Forensic to a network and via a workstation, download and view. Users can also use an iSCSI or SMB protocol to preview source drives via the network.


*The ZXi-Forensic achieves speeds of over 50GB/min using solid state “suspect” drives that contain a freshly installed Windows “X” OS and random data. Settings used are e01/ex01 image format, with compression and with verify “on”. The specification and condition of the suspect hard drives as well as the mode, image format and settings used during the imaging process may affect the achieved speeds.