62,649,383 Items Fully Processed in 6 Days!
In testing, AccessData fully processed
a massive data set, including 62,649,383items, of which there were well over
2 million emails and a total of 97,431
archive files that needed to be broken out.
The compressed size of this data set was
1.28 terabytes. A data set this large
would normally be divided into batches,
with each batch being processed
separately on stand-alone machines.
This could take a month to process,
using traditional tools, depending on the
hardware used. However with AccessData’s
distributed processing technology, it only
took 6 days, 5 hours.
Computer Forensics Software Solutions to Ease the Burden on Computer Forensics Labs Everywhere.
AccessData® enables computer forensics labs of all sizes, facing an array of challenges, to work more effectively. A single person lab can radically speed up the processing of cases with the 4-worker distributed processing available with FTK. Computer forensics labs handling a greater number of cases with larger data sets will benefit significantly from the distributed processing and collaborative analysis capabilities found in FTK Pro. Finally, large labs handling massive data sets, utilizing a distributed workforce, or looking to collaborate with lawyers, HR personnel and other non-forensic parties can step up to AccessData Lab. AD Lab adds powerful and intuitive web-based review functionality, expanded distributed processing capabilities with a centralized processing farm, and a centralized database infrastructure. Regardless of the size, scope or mission of your computer forensics lab, AccessData has a solution that will meet your needs.
Which solution is right for you?
FUNCTIONALITY
FTK
FTK PRO
AD LAB
Distributed Processing
4 WORKERS
4 WORKERS
EXPANDED
Job Queuing for Distributed Processing Farm
NO
NO
YES
Share a Centralized Database Infrastructure
NO
NO
YES
FTK Investigator Collaboration
NO
4 SIMULTANEOUS
UNLIMITED
Case and Task Management
NO
NO
YES
Role-based Permissions to
Control Access & Activity
NO
NO
YES
Near Native Web Review
NO
NO
YES
Active Directory Integration
for Authentication
NO
NO
YES
Load File and Responsive
Data Set Production
NO
NO
YES
eDiscovery De-Duplication
NO
NO
YES
ACCESSDATA LAB Product Features
A Secure Computer Forensics Lab Solution
Electronic evidence can be fully secured at the case or file level.
Granular role-based administration allows administrators to assign users to a given case or set of data within a case.
Users can be restricted by feature, so only qualified users can access more advanced functions.
Centralized logging ensures accountability.
Active Directory integration for authentication.
Web browser can use SSL for secure communication.
Manage Multiple Cases and Examiners
Multiple examiners share a centralized database for collaboration and review.
Centralized processing, indexing and data storage, with the ability to queue jobs into the distributed processing farm.
Custom data views allow administrators to define which items reviewers can see (e.g. analyst can only look at email from drive one in case abc123).
Simultaneous collaboration between Web reviewers and FTK forensic analysts.
Ease of Use and Efficiency
Leverage a shared distributed processing farm to processing massive data sets in a fraction of the time it would take using traditional tools.
Distributed Processing obviously requires powerful hardware and networking technology. Processing evidence is very disk IO intensive and requires fast drives. In addition, the machine that runs the Processing Manager must be the fastest computer (CPU) speed in the processing group. Finally, you will need the fastest networking technology available to you. For details on configuring distributed processing, please see the following documents. However, Lab customers will receive configuration assistance from our engineering team to ensure optimized functionality.
User friendly web interface enables true native review without having to convert to html or image format.
Easily overcome the bandwidth constraints of distributed labs with centralized or distributed databases and web-based analysis, enabling efficient sharing of workload.
De-duplicate data by custodian/evidence group or across entire case/matter.
Email discussion threads.
Integrates with both FTK® and AD Enterprise to streamline investigations for law enforcement, government and corporate labs.
Fully leverage the cutting-edge analysis capabilities of Forensic Toolkit® computer forensics software.
Produce responsive-only documents and email (reduced PST/NSF) in native format or an AD1 forensic archive, organized by custodian or as a single instance, with options to preserve the original folder structure.
Generate load files for export to popular third-party review tools, including Concordance, EDRM XML, Summation, iCONECT and Introspect.