Rocket: Enterprise Remote Forensic Software & Technical Specs
CORE ENGINE ARCHITECTURE
Technical Specification Pipeline
Every collection follows a precise, fully auditable workflow from start to finish. Here’s a look under the hood at how Rocket collects, encrypts, and verifies digital evidence down to the block level.
Windows E01 Bit-Level Imaging
Sector-by-sector physical imaging produces industry-standard compressed E01 forensic files over the network — no local bridge device required. Lossless and verifiable at every block.
WINDOWS · E01 · NETWORK
BitLocker Key Capture & Decryption
Recovery keys and protectors are extracted directly from volatile memory, bypassing the need for pre-imaging manual decryption. Encrypted volumes are accessed transparently during collection.
BITLOCKER · MEMORY · DECRYPTION
iOS iTunes Backup Extractions
Remote-triggered iTunes-style backup acquisitions capture full logic structures and system state data without any local storage footprint on the target asset. Forensically sound and repeatable.
iOS · ITUNES · LOGIC BACKUP
Targeted Filtering
Granular date, participant, and contact filtering across WhatsApp, WeChat, iMessage, and SMS scopes messaging data prior to collection—drastically reducing ESI volumes and accelerating review for legal, compliance, and investigative teams.
WHATSAPP · IMESSAGE · SMS · ESI
SHA-256 Cryptographic Chain of Custody
Every data block is hashed in-flight. An immutable, automatically signed Chain of Custody log is generated with each acquisition, independently verifiable via SHA-256 absolute matching — ready for court.
SHA-256 · HASH · CHAIN OF CUSTODY
FIPS 140-2 AES-256 Data Encryption
End-to-end AES-256 encryption governs all ESI in transit and at rest using FIPS 140-2 validated cryptographic modules. Enterprise compliance requirements are satisfied without additional configuration.
AES-256 · FIPS 140-2 · IN-TRANSIT · AT-REST
Zero-Footprint Deployment Architecture
Rocket executes entirely without an installed application on any device. No files are written to disk at any stage. Upon acquisition completion, every execution artifact is deterministically overwritten — the source machine returns to its exact pre-collection state. This eliminates spoliation risk and satisfies the most demanding chain-of-custody standards for enterprise, legal, and government deployments.
VOLATILE RAM ONLY · NO DISK WRITES · ANTI-SPOLIATION · ENTERPRISE COMPLIANT