Some products are launched, polished, and then left to coast. TaskForce has never been that kind of product.
When the first generation was released in 2018, it was built to solve one problem exceptionally well: acquire forensic evidence faster than anything else on the market. Eight years later, speed is still part of its DNA, but it has become only one piece of a much bigger story.
Since that first release, every major firmware update has been driven by real-world challenges faced by forensic laboratories. Whether it was automating repetitive workflows, reconstructing increasingly complex RAID systems, adding logical imaging, integrating with enterprise authentication, or eliminating network bottlenecks, each milestone addressed a practical limitation investigators were encountering in the field.
Here is how TaskForce has developed over the years in response to new storage technology, changing forensic workflows, and the growing demands of digital investigations.
2018. Building a New Performance Baseline
TaskForce made its debut in May 2018 with capabilities that immediately stood out. TaskForce’s first generation boasted 18 imaging ports and up to 15 TB/hour of cumulative throughput, powered by server-grade hardware, which gave forensic laboratories something they had been missing: a practical way to tackle ever-growing evidence backlogs without compromising reliability.
The response was immediate. Laboratories that had struggled to keep pace with increasing storage capacities suddenly had a tool designed for exactly that challenge.

But launch day was only the beginning.
Within months, firmware updates added workflow presets that allowed investigators to standardize acquisition procedures across multiple devices. Sector export reports improved documentation and auditability, while support for imaging only sectors containing data significantly reduced acquisition times whenever full bit-by-bit imaging wasn’t required or time pressure required focusing on only the essential data.
By the end of the year, an M.2 extension module brought NVMe support to the platform, ensuring TaskForce could keep pace with one of the industry’s fastest-growing storage technologies.
2019. Web API and Express Mode
The second year marked one of the biggest shifts in TaskForce’s history.
Raw imaging performance was no longer the only objective. As laboratories became more efficient, new bottlenecks appeared elsewhere in the workflow. The focus naturally shifted from imaging drives faster to helping investigators process more evidence with less manual effort.
Several important additions arrived during the year, including compressed E01 imaging, imaging directly to files, drive temperature monitoring, and lifetime analysis. Each made investigations more flexible, but one feature fundamentally changed what a forensic imager could be.
The introduction of the Web API transformed TaskForce from a standalone acquisition device into a key component of larger forensic workflows.
For the first time, forensic laboratories could integrate hardware imaging directly into automated processing pipelines using platforms such as Magnet AUTOMATE. Instead of waiting for an examiner to manually launch every acquisition, entire workflows could now begin automatically.
Express Mode built on that idea by enabling fully automated, zero-click imaging. What had previously required repeated user interaction became a repeatable workflow that laboratories could deploy at scale.

All these upgrades helped TaskForce users optimize their workflows and achieve unprecedented data processing speeds!
Another major addition, Selective Head Imaging, brought advanced data recovery techniques directly into forensic acquisition. Since damaged read/write heads are among the most common causes of imaging failures, investigators could often recover critical evidence that would otherwise remain inaccessible.
2020. Automated RAID Reassembly
By 2020, forensic laboratories were dealing with more encrypted drives, more damaged media, and increasingly sophisticated storage architectures. TaskForce evolved accordingly.
Encrypted VeraCrypt destination drives gave investigators a secure way to transport evidence outside controlled laboratory environments, a feature requested by customers handling sensitive investigations.
Segmented E01 files simplified evidence management, while segmented hashing made it possible to validate acquisitions even when working with unstable or partially damaged media.
The year’s defining milestone, however, was Automated RAID reassembly.
TaskForce became capable of identifying unknown RAID parameters, reconstructing arrays automatically, and imaging the reconstructed logical volume, even when some member drives were missing or damaged.
For many investigators, this eliminated one of the most time-consuming stages of RAID acquisition. Instead of reconstructing arrays manually with separate software before imaging could even begin, TaskForce handled the process itself.
Its server-grade processing power made RAID configuration searches so fast that customers were amazed at the new capability in their possession!

2021. Multi-Launch mode and AFF4
By 2021, imaging a single drive quickly was no longer the biggest challenge. Most laboratories had reached a different stage of maturity: the real bottleneck was managing dozens of acquisitions at once without tying up valuable examiner time.
TaskForce evolved to meet that reality: Multi-launch capabilities allowed investigators to start imaging, hashing, wiping, or diagnostics across multiple drives simultaneously. Rather than treating each device as an individual task, laboratories could initiate entire batches of work with a single action, reducing repetitive manual steps and making better use of available hardware.
Many of the year’s improvements came directly from customer feedback. Support for the AFF4 evidence format, Secure Erase wiping, signature statistics during imaging, additional file systems including ExFAT, HFS/HFS+, and XFS, new RAID configurations, and the Browse Files function all reflected practical requests from investigators looking to streamline everyday work.
Another impactful optimization came in the form of locally saved imaging presets.

None of these features made headlines on their own. Together, however, they made TaskForce significantly more capable and more convenient to use throughout the entire acquisition process.
2022. Entering the Logical Imaging Era
Digital investigations increasingly demanded something more selective than full disk acquisitions.
Investigators often knew exactly what they were looking for but still had to image entire storage devices simply to reach a handful of relevant files. That approach consumed valuable time, storage capacity, and processing resources.
Logical imaging fundamentally changed that workflow.
For the first time, TaskForce could selectively acquire individual files, folders, or complete directory structures from both standalone drives and reconstructed RAID arrays. Instead of copying everything, investigators could focus on the evidence that actually mattered.
This was particularly valuable in situations where storage space was limited, acquisition windows were short, or rapid triage was essential.

Support for Apple’s APFS file system further strengthened the platform’s capabilities, while continued improvements to RAID autoreassembly enabled increasingly reliable reconstruction of damaged arrays, incomplete RAID sets, and storage systems with missing members.
TaskForce was no longer simply acquiring storage devices. It was helping investigators make smarter acquisition decisions.
2023. The Arrival of TaskForce 2
Five years after the original release, digital storage looked very different.
NVMe drives had become commonplace. Enterprise SSDs were replacing traditional hard drives. Large RAID systems were appearing in more investigations, and laboratories increasingly wanted to process multiple high-speed devices in parallel.
The original architecture had served investigators remarkably well, but the industry’s expectations had outgrown it.
TaskForce 2 was designed from the ground up to meet those new demands.
The new server-rack platform increased the number of imaging ports from 18 to 26 while introducing native support for four hot-swappable NVMe drives. Combined with a new hardware architecture capable of up to 25 TB/hour of cumulative throughput, TaskForce 2 was built for forensic laboratories where parallel processing had become the norm rather than the exception.
The rack-mounted design also reflected how many laboratories had evolved, integrating naturally into server rooms and dedicated forensic workspaces where reliability, accessibility, and scalability mattered as much as raw performance.

Firmware innovation continued alongside the new hardware. RAID 6 reconstruction joined the growing list of supported storage configurations, allowing investigators to tackle increasingly sophisticated enterprise storage systems with the same streamlined workflow.
2024. Synology NAS RAID Support
As enterprise storage continued to diversify, forensic tools needed to keep pace.
Network-attached storage systems had become a routine source of evidence, bringing proprietary RAID implementations and modern file systems into everyday forensic work.
Support for Synology NAS reconstruction (including both SHR and SHR-2 configurations with Btrfs) extended TaskForce into another important area of digital investigations, enabling investigators to reconstruct and acquire storage systems that previously required additional specialist tools.

The year also brought dozens of refinements across RAID handling, Express Mode, logical imaging, workflow management, and the user experience.
Some of the most valuable improvements were almost invisible.
For example, the ability to automatically resume imaging after a power interruption sounds like a small convenience. In reality, when imaging multi-terabyte drives over many hours (or even days!) it can save investigators from repeating an acquisition from the beginning after an unexpected outage.
Sometimes the features users appreciate most are the ones they only notice when something goes wrong.
2025. Enterprise Integration and Remote Acquisition
As forensic laboratories grew larger and more interconnected, TaskForce continued moving beyond the boundaries of a standalone imaging appliance.
Support for remote acquisition via iSCSI allowed investigators to image storage devices that were no longer physically attached to the system, opening new possibilities for distributed forensic workflows.

Performance improvements continued as well. NVMe-to-NVMe imaging throughput doubled, making full use of increasingly capable solid-state storage.
Integration with LDAP and Active Directory enabled centralized authentication and user management, allowing organizations to apply existing IT policies and simplify administration across multiple examiners and systems.
System-wide ZFS support further expanded compatibility with modern storage environments, ensuring investigators could work confidently across an even broader range of enterprise infrastructure.
2026. 25Gb Network Performance + Bonding
By 2026, imaging itself was no longer the limiting factor.
Many forensic laboratories had invested heavily in centralized storage, high-performance networks, and automated workflows. Some were already deploying 100 Gb infrastructure. Moving evidence across the network (not acquiring it from the drive) had become the next challenge to solve.
The 25G Fiber Extension addressed that bottleneck directly.
Dual 25 Gbit/s SFP28 interfaces, combined with network bonding support, enabled up to 50 Gbit/s of network throughput, allowing acquisition performance and network performance to remain in balance even in demanding enterprise environments.

Meanwhile, the Web API continued to grow.
New endpoints for case management, workflow orchestration, and automation reinforced a direction that had been developing for years. TaskForce was no longer simply performing acquisitions, it had become an integral part of larger forensic ecosystems, capable of integrating seamlessly with laboratory infrastructure and automated evidence-processing pipelines.
Looking Ahead
Looking back over eight years, one pattern stands out: every major TaskForce release has removed a different bottleneck or hurdle.
First, it was acquisition speed. Then workflow consistency. Automation. RAID reconstruction. Logical imaging. Enterprise deployment. Remote acquisition. And now network throughput.
What began as a high-performance forensic imager has steadily evolved into a comprehensive forensic acquisition platform.
The next chapter is already taking shape. Storage technologies will continue to change. Investigation workflows will continue to evolve. New challenges will emerge, just as they have over the past eight years.
Our goal remains the same as it was in 2018: to identify the next bottleneck before our customers have to live with it. And build the tools that remove it.





