OpenText home page.
Digital Forensics and Incident Response

OpenText Forensic Equipment

Acquire digital evidence in a reliable, defensible, and efficient way

 Digital forensic hardware tool.

Overview

During evidence collection, changes to a storage device can occur, rendering collected evidence inadmissible in court or invalidating an investigation. Investigators need a solution that delivers rapid, accurate imaging that ensures evidence integrity.

OpenText™ Forensic Equipment is a portfolio of digital forensic hardware tools— including imagers, duplicators and write-blockers—designed to meet the rigorous demands of digital forensic investigations with integrity, reliability, and efficiency. Rapidly acquire data from a wide range of digital devices while preserving the chain of custody and maintaining compliance with legal and forensic standards.

Why OpenText Forensic Equipment?

OpenText Forensic Equipment provides a competitive advantage due to its tight integration with OpenText™ Forensic software, enterprise-level features, and emphasis on defensibility, scalability, and chain-of-custody fidelity.

  • 5x faster
    forensic imaging than previously available
    Rapidly extract files, review metadata, recover deleted content, and search for relevant evidence.
  • Easy
    intuitive, seamless workflows
    Streamline the acquisition of digital forensic evidence for investigators at all levels of expertise.
  • Portable
    tools that can acquire data no matter where you are
    Whether in the field or in the lab, OpenText Forensic Equipment ensures your ability to acquire evidence from a variety of device types.

Use cases

Capturing, preserving, and analyzing digital evidence without altering its original state is critical. OpenText forensic imagers, duplicators, and bridges (otherwise known as write blockers) play a foundational role in ensuring this integrity.

  • Maintain chain of custody and evidentiary integrity with the OpenText™ Forensic TX2 Imager to preserve original digital forensic data and ensure it isn’t modified during acquisition.

  • Create quick, forensically sound clones of suspect drives directly in the field with OpenText™ Forensic TD4 Duplicators to preserve evidence integrity on the spot.

  • Gather digital forensic evidence quickly when law enforcement or military teams seize multiple devices during a raid. Image multiple drives simultaneously with OpenText Forensic TD4 Duplicators to reduce acquisition time during sensitive operations.

  • Ensure analysts don’t inadvertently change or damage the original digital evidence by using a forensic write-blocker like OpenText™ Forensic Bridges to preserve digital artifacts during inspection.

    Key features

    OpenText forensic imagers, duplicators, and bridges form the backbone of forensically sound data collection and analysis, supporting law enforcement, cybersecurity teams, and legal professionals in maintaining the highest standards of evidence.

    A screenshot of the OpenText Forensic Equipment user interface.

    Hashing capabilities in forensic imaging operations

    Delivers innovative tree hashing, breaking data streams into chunks that can be hashed individually, reducing evidence-acquisition times and improving the efficiency of digital evidence discovery.

    A screenshot of the OpenText Forensic Equipment user interface.

    Wide device interface support

    Provides native connectivity to PCIe, USB, SATA, SAS, and network-based (ethernet) media, ensuring data from any device can be easily captured.

    A screenshot of the OpenText Forensic Equipment user interface.

    Color, touch-screen interfaces

    Offers easy-to-use, intuitive user interfaces that save valuable investigative time with real-time drive and job status indicators.

    A screenshot of the OpenText Forensic Equipment user interface.

    Hardware-based write blocking

    Blocks host system writes to avoid operating system behaviors and non-standard host interface drivers that can be prone to misuse and exploitation.

    A picture of the physical hardware for OpenText Forensic Equipment.

    LED activity status indicators

    Utilizes six LEDs to provide visible activity feedback, including DC in, power, host (connection), device (media detection), write-block status, and activity.

    Accelerate the value of OpenText Forensic Equipment

    Add-ons

    Extend the capabilities of your digital forensic investigations with additional digital forensic and incident response capabilities.

    Professional Services

    OpenText Professional Services combines end-to-end solution implementation with comprehensive technology services to help improve systems.

    Partners

    OpenText helps customers find the right solution, the right support, and the right outcome.

    Training

    OpenText Learning Services offers comprehensive enablement and learning programs to accelerate knowledge and skills.

    Communities

    Explore our OpenText communities. Connect with individuals and companies to get insight and support. Get involved in the discussion.

    Premium Support

    Optimize the value of your OpenText solution with dedicated experts who provide mission-critical support for your complex IT environment.

    OpenText Forensic Equipment resources

    OpenText Forensic TD4 Duplicator

    Read the product overview

    OpenText Forensic TX2 Image

    Read the product overview

    OpenText Forensic Bridges

    Read the data sheet

    OpenText Forensic TD4 Duplicator

    Read the product overview

    OpenText Forensic TX2 Image

    Read the product overview

    OpenText Forensic Bridges

    Read the data sheet
    • OpenText Forensic Equipment includes specialized hardware for digital forensics evidence acquisition, such as forensic imagers, duplicators, and bridges. These tools enable investigators to safely image and analyze hard drives (HDD, SSD), removable media (USB, SD cards), mobile devices, and networked storage. OpenText Forensic Equipment delivers portable form factors that enable investigators to perform high-speed, forensically sound evidence acquisition and triage in the field. OpenText Forensic Equipment is part of the OpenText cybersecurity digital forensics and incident response (DFIR) portfolio.

    • OpenText Forensic Equipment is primarily used by law enforcement, government agencies, digital forensic labs, and security professionals conducting criminal investigations, incident response, or eDiscovery. It is also used in corporate security DFIR settings for internal investigations and regulatory compliance. OpenText Forensic Equipment is designed for both in-lab forensic workflows and portable field deployments. Lightweight, rugged devices with intuitive interfaces make it easy for investigators to collect evidence quickly, even in time-sensitive or remote situations.

    • A forensic imager, such as the OpenText Forensic TX2 Imager, is a hardware tool used to create a bit-for-bit copy (also called a forensic image) of digital storage media such as a hard drive, SSD, or USB stick. It is typically used to preserve evidence for forensic analysis, a common use case in criminal investigations, eDiscovery, and/or incident response. 

      A forensic duplicator, such as the OpenText Forensic TD4 Duplicator, is a hardware-based device that performs one-to-one or one-to-many exact copies of digital media. It is often used for bulk duplication, such as copying multiple drives for evidence review or court submission, while preserving a master image.

    • When investigators need to access a suspect device (e.g., a laptop hard drive), connecting it directly to a computer could unintentionally alter or write data to the drive, compromising the integrity of the evidence and making it invalid during court proceedings. A forensic bridge, also known as a write blocker, is a hardware device used in digital forensics investigations that prevents any modification to the original evidence when accessing suspect storage media, including hard drives, SSDs, or USBs. OpenText Forensic Bridges block all write commands, allowing a system to read data from the drive without the risk of changing anything and preserving the original state of the evidence.

    • Following Tableau’s acquisition and integration into OpenText, the product line was rebranded as part of the OpenText digital forensics and incident response (DFIR) portfolio, offering the same trusted hardware, now backed by the power of OpenText cybersecurity. Today, OpenText Forensic Equipment continues to deliver the industry-leading forensic imaging, duplication, and write-blocking capabilities trusted by investigators worldwide.

    • OpenText provides a series of forensic adapters that allow OpenText Forensic Equipment to connect to different drive interfaces (e.g., SATA, IDE, SAS, PCIe, mSATA, M.2 NVMe), as well as drives with different form factors (e.g., 2.5", 3.5", M.2).

    • The OpenText Forensic TX2 Imager is the next-generation forensic imager that provides significantly faster imaging operations when compared to the legacy OpenText TX1 Imager. Investigators using OpenText Forensic TX1 Imagers who need considerably faster operations to enhance their investigations' efficiency should contact OpenText for information on upgrading to the OpenText TX2 Imager.

    • OpenText Forensic Equipment can be used with any forensic software platforms designed for data acquisition, analysis, and investigation. However, it integrates seamlessly with OpenText Forensic, OpenText Endpoint Investigator, OpenText Endpoint Forensics and Response and OpenText Information Assurance, providing teams with a cohesive, efficient, and legally reliable forensic investigation process.

      Take the next step

      Ready to strengthen your forensic capabilities? Contact us today to explore the right OpenText Forensic Equipment for your team or request a customized demo.

      Contact us