Ditto x86 BE Kit|Digital investigation|eDiscovery|forensic data acquisition
Forensic USB device for booting a computer into the Ditto environment for digital investigation, eDiscovery, and data capture
No disassembly required - image laptops and ultrabooks
Forensically examine and image the most portable modern devices running Windows, macOS, and Linux without taking them apart via a bootable version of the Ditto environment.
Harness your target system's own CPU to image its data. Real-world tests in the lab and in the field have yielded imaging speeds of up to 50GB per minute.
Time-saving logical imaging
Drive capacties are rapidly increasing, making it impractical to image an entire drive, which makes logical imaging more vital than ever. Ditto x86 logical imaging slashes the time required to acquire needed evidence and makes it easy to see what's happening on a drive without imaging every byte first.
The included hub accessory includes a Gigabit Ethernet port to facilitate remote operation. The easy-to-use Ditto web browser graphical interface supports remote operation via network or VPN, providing access to Ditto configuration, user administration and user rights, as well as direct operation of Ditto cloning and imaging operations.
Data acquisition modes
Clone, DD, E01, L01 with MD5, SHA-1, or SHA-256 hashing. Ditto x86 also offers a combined mode that captures a clone and DD or E01 (to different destination drives) in a single pass reading of the suspect drive.
Pause and Resume
The Ditto family of imagers was the first to include a pause and resume feature. When creating a Physical Image DD, the investigator may pause the imaging process, disconnect everything for secure storage and then come back later to resume the image without losing any previous work.
Restore an image to a Destination drive to create a bootable clone of the original drive.
S.M.A.R.T. and hdparm Data
Ditto x86 allows investigators to collect S.M.A.R.T and hdparm data for any connected device.
Hard Drive Password Lock/Unlock and Encryption
Ditto x86 automatically identifies drives that are firmware password protected. The investigator may enter the password if known to unlock the drive. Ditto x86 also supports whole disk encryption using the AES 256 OPAL encryption schema. If known, the investigator can enter the passphrase to decrypt the drive for imaging.
A USB port for every occassion.
The included hub accessory provides (3) USB Type-A ports, (1) USB Type-C (for charging only), and connects to computers via USB Type-C (or Type-A with adapter). The hub also has a (1) Gigabit Ethernet port to facilitate remote operation.
Complete and Secure Erasure
Ditto x86 can sanitize drives with preset erase modes or a user configurable pattern. NVMe devices and other drives can be securely wiped using a variety of sanitization modes including DOD Clear and Sanitize modes plus NIST800-88 Clear and Purge. The drive can also be formatted after the erase is complete.
Free one-year subscription
Each Ditto x86 comes with a renewable one-year subscription. Receive ongoing technical support and upgrades while your subscription is active. We regularly update the Ditto environment with useful features that our customers request. Plus, we're always available to offer technical support should the need arise.
- Easily image Windows, macOS, and Linux 64-bit systems without taking the case apart
- Boot a suspect device into the Ditto environment for digital investigation
- Palm-sized, rugged, and portable