Our dev team has decided to celebrate 2021 with a new software update. With this release, Atola Insight Forensic has become the first forensic hardware imager in the world that is capable of imaging into AFF4 files!

AFF4 imager

AFF4 image file

So what’s the big deal about AFF4? This file format has several upsides:

  • Open-source format: it can be described in a court
  • Fast compression methods: Snappy and LZ4
  • Block hashes
  • Binary zeroes are stored as spans (in a “sparse file” manner)
  • Vendor-neutral

Since our team is always focused on performance and AFF4 is a highly optimized file format, Insight’s imaging speed will be as impressive as ever!

Another thing worth mentioning is the rapid proliferation of this file format in the industry. AFF4 is already supported by various forensic image analysis tools: Magnet Forensics AXIOM and AUTOMATE, X-Ways Forensics, Cellebrite Blacklight, AccessData FTK.

To learn more about AFF4, visit the official website: AFF4 -The Advanced Forensics File Format

Imaging report for an AFF4 image file

AFF4 imager

Note: AFF4 block hashes feature is not supported yet. It will be added in the next release. Until then, we recommend using segmented hashing.

Entropy calculation while imaging

The DiskSense hardware unit used for Atola Insight is a powerful box. Not only does it calculate linear & segmented hashes in the course of imaging, it can also perform various data analyses with no penalty on imaging performance. In the earlier versions of the software, we added file signatures & artifacts. Now it’s time to show the big picture of source drive data with an entropy map.

Entropy shows the degree of data randomness across the whole space of the source evidence drive. By opening the Entropy tab, you can overview the data distribution. The light pink color means a low entropy level close to 0%. Most likely, you have sectors filled with binary zeroes or a pattern there. Whereas the dark purple color indicates the maximum data randomness. Based on experience, it is a sign of:

  • encrypted files or partitions
  • compressed videos, photos, audio files
  • compressed archive files
Imaging engine is calculating entropy on-the-fly
Entropy. Imaging to AFF4

Changelog

New Features

AFF4 image file support 

New imaging option: Calculate entropy. It enables data randomness analysis in the course of imaging.

Link to the new imaging Cheat sheet added to a few screens

If SATA target is limited via HPA at the start of imaging, a corresponding log message is added

Changed parameters of a new image file are saved and applied during the following imaging

Bugfixes

Blue screen on Windows 10 October update during Atola Insight installation process

Imaging. ‘Disabled read-look ahead’ option was not working

Minor UI bugfixes

Download

You can download the latest update here: Insight Forensic 4.17

Where to buy

If you still do not have an Atola Insight Forensic and would like to place an order, this can be done directly via Atola Technology, or from a distributor near you:

https://atola.com/wheretobuy/

Please contact Atola Technology sales department to receive more specific information:

  • Call us: +1 888 540-2010, +1 416 833-3501  10am – 6pm ET
  • Or email us

P.S. Dear customers, we appreciate your feedback and take it into consideration when updating our products. Please feel free to write your thoughts and ideas in the comments section below.

Vitaliy Mokosiy

Vitaliy Mokosiy

Atola CTO He believes in saving time & energy of people doing mission-critical work. Therefore, all his efforts are focused on leading R&D of innovative Atola products. Gamification enthusiast. Agile development proponent.