Attachment 1 SOR_Magnet IDIQ.docx
DOCX document 52 KB Posted
- Attached to
- Magnet Forensics IDIQ Federal contract opportunity
- Solicitation number
- 70US0924R70094667
About this file
This document is a Statement of Requirements (SOR) for a commercial Indefinite Delivery Indefinite Quantity (IDIQ) contract to acquire four types of forensic software products and training, brand name or equal, in support of the United States Secret Service (USSS) National Computer Forensics Institute (NCFI). The required products are: (1) AXIOM with in-person instruction and 2 years of software maintenance, (2) DVR Examiner with in-person instruction, (3) Outrider with 2 years of software maintenance, and (4) Griffeye Advanced with 2 years of software maintenance. This is a 5-year IDIQ contract with a small business set-aside under NAICS code 513210. The government will place delivery orders every 4 months to support the NCFI class schedule, with the first order potentially awarded at the time of IDIQ contract award. The software licenses shall not activate until the first day of each class. The USSS technical point of contact will coordinate deliveries and review/accept each deliverable.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 Provisions and Clauses.docx | DOCX document | |
| Attachment 4 Instructions to Offerors.docx | DOCX document | |
| Attachment 3 Pricing Sheet.xlsx | XLSX spreadsheet | |
| Attachment 5 Basis of Award.docx | DOCX document | |
| (1a) Solicitation letter_Interested Parties.pdf | ||
| Attachment 6 Question Answer Matrix.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
70US0924R70094667, Magnet IDIQ
ATTACHMENT 1
UNITED STATES SECRET SERVICE
Magnet Software IDIQ (Brand Name or Equal)
STATEMENT OF REQUIREMENTS
The purpose of this Statement of Requirements (SOR) is to acquire four forensics software products and training, brand name or equal, on an as needed basis in support of the United States Secret Service (USSS) National Computer Forensics Institute (NCFI).
These products are utilized within training courses offered by the NCFI to law enforcement personnel, judges, and prosecutors from around the country. The products are transitioned from the classroom to the students for use within their law enforcement jurisdictions to support their on-going and future law enforcement cyber and digital forensics investigations.
1.0 Purpose:
The USSS was established as a law enforcement agency in 1865. While most people associate the USSS with Presidential protection, our original mandate was to investigate the counterfeiting of U.S. currency--which we still do. Today, our primary investigative mission is to safeguard the payment and financial systems of the United States. This has been historically accomplished through the enforcement of the counterfeiting statutes to preserve the integrity of United States currency, coin, and financial obligations. Since 1984, our investigative responsibilities have expanded to include crimes that involve financial institution fraud, computer and telecommunications fraud, false identification documents, access device fraud, advance fee fraud, electronic funds transfers, and money laundering as it relates to our core violations. Today’s high-tech environment presents new challenges to law enforcement as cyber criminals and others increasingly exploit computers and the internet to threaten our banking, financial, and critical infrastructures.
The NCFI provides training to state/local law enforcement, prosecutors, and judges in many areas of digital forensics and cyber investigations. To assist in investigating and prosecuting Law Enforcement cases, the USSS NCFI requires commercial forensic software products to support its Congressional mandate. All items are to be brand name or equal.
This is a commercial Indefinite Delivery Indefinite Quantity (IDIQ) contract to acquire four types of forensic software, on an as needed basis, in support of the NCFI. This IDIQ has a 5-year ordering period.
2. Scope
The contractor shall deliver the following four types of forensic software products (brand name or equal) to the NCFI located in Hoover, Alabama:
| (1) | AXIOM with in-person instruction by Magnet Forensics with two (2) years Software Maintenance Services (SMS) |
| (2) | DVR Examiner with in-person instruction by Magnet Forensics |
(3) Outrider by Magnet Forensics with two (2) years Software Maintenance Services (SMS)
(4) Griffeye Advanced by Magnet Forensics with two (2) years Software Maintenance Services (SMS) Each set of software shall contain the required, brand name or equal items (as appropriate) as listed within the tables in Section 3 of this document. If substitutes are offered, the contractor shall notify the government by providing manufacturer specification sheet(s) for government evaluation and agreement the “or equal” offered is equivalent to the brand name items requested (see paragraph 4.2 for further details regarding this process).
3. Requirements: Products/Services
In accordance with the ordering procedures, the contractor shall provide the following products/ services, as defined in this SOR, as orders are placed on the IDIQ.
3.1 Magnet AXIOM. AXIOM by Magnet Forensics, brand name or equal, shall meet the following technical parameters:
· Three days in-person classroom instruction by Magnet Forensics representatives at the NCFI facility in Hoover, AL for every 20 or more licenses activated covering the use of the tool for criminal investigations.
· Two years software maintenance services including software updates and support.
· One platform for analysis – smartphone, computer, cloud, IoT, and the ability to ingest third-party image data in a single case file.
· Acquisition & Analysis – the ability to acquire and analyze in one tool.
· Supported Image formats – E01/Ex01/L01/Lx01, AD1, RAW/DD/IMG/BIN/VFD/FLP/BIF/DMG/DMP/MEM, VMDK/VDI/VHD/XVA/VMEM/, CRASH/VMSS/HPAK/VMSN/ELF, 000/001/0000/00001, ZIP/ZIP.001/7z/7z.001/RAR/ CPIO/CPIO.GZ/TAR/TAR.GZ/ DOCX/PPTX/XLSX/AB/UFD
· File System Support – NTFS, FAT32/16/12, ExFAT, HFS+, HFS/X, EXT2, EXT3, EXT4, YAFFS2, Flash Friendly File System (F2FS).
· Robust Artifact Support – over 750 internet and mobile device related artifacts.
· Browsers: Chrome, Firefox, Internet Explorer/Edge, Safari, Opera, Xbox Internet Explorer, Google Searches
· Cloud Data: Dropbox, Google Drive, OneDrive, Sharepoint, Skydrive
· Documents: Excel, Powerpoint, Text Files, RTF Files, CSV, Word, Writer, Calc, Impress, PDF, Hangul
· Chat: WhatsApp, Kik, Skype, Grindr/Growlr, Chatstep, SMS/MMS, iMessage, Android Messages, QQ, WeChat, Facebook Messenger
· Email: OST/PST files, EML/EML(x), Gmail, Yahoo, Outlook/Hotmail, GMX webmail
· IoT: Amazon Alexa, Fitbit, Nest, Pebble
· Transport: OnStar, Uber
· P2P: Ares, Shareaza, Limewire, Bittorrent, Emule,
· Windows OS: USB History, Event Logs, Prefetch, LNK files, Jumplists, Shellbags, AutoRuns, $Logfile, AmCache, MRU, Virtual Machines, Recycle Bin, SRUM, Windows Timeline
· Views – Ability to view the data in a file system, registry, artifact, chat threading, picture thumbnail, timeline, mapped geolocation view.
· AI (machine learning) – Automatically identify and categorize chat and picture-based evidence. Identify conversations that indicate potential child luring and sexual conversations. Identify pictures containing nudity, weapons, drugs, child abuse material, documents, identification documents, screenshots.
· Memory Analysis – recover and analyze memory with Volatility integration (processes, connections, etc.) as well as common artifact data found only in memory, such as private browsing, webmail, etc.
· Mobile Backup Analysis – Automatically analyze Android and iOS backups found on a computer.
· Android Password Bypass – tool to recover full physical images from locked Samsung devices using recovery images, LG devices, and Motorola Android devices with advanced extraction capabilities for MTK based chipsets, and Qualcomm chipsets using Emergency Download Mode (EDL).
· Media Transfer Protocol (MTP) Mobile Acquisitions- be able to acquire mobile device data through non typical methods such as MTP when traditional acquisitions methods fail.
· Graykey Integration – ingest iPhone images from Graykey with a simple 1 step process. Ingest memory and plist into tool in order to analyze more data/artifacts.
· JTAG/ISP/Chipoff Images – ingest images created via various physical extraction techniques such as JTAG/ISP/Chipoff.
· Visual Relationship links – automatically discover where a file came from and where it went visually between artifacts, files and users. Builds connections between files in the file system and common OS artifacts such as LNK files, Jumplists, Shellbags, etc. Conduct analytics on files and artifacts, based on key information about the files and artifacts across multiple platforms including Mobile, Cloud, Computer, and IOT. Analytics across platforms allows for a reveal of the full picture of the scenario surrounding the suspect information automatically without tying up the time of an examiner.
· Automatic Database Discovery – automatically find databases that are of interest that are not supported as an artifact to help uncover unknown or new data that may be important to your investigation.
· Internal SQL Viewer – viewing Databases within the forensic tool ensures proper application of dates and times as well as reducing laborious workflows for examiners.
· Internal PLIST Viewer – Viewing MAC and iOS plist files internally within the forensic tool ensures proper application of dates and times and interpretation of the data.
· Full Disk Decryption – Passware partnership to be able to recover data from drives encrypted with TrueCrypt, Bitlocker, McAfee, Veracrypt.
· Visual Chat Analysis – Visually display chat conversation threads allowing for easier analysis and presentation to non-technical stakeholders.
· Various Export Options – HTML, PDF, Excel, CSV, Project VIC, PST, Portable Case, XML
· .PST Export – Export .pst files to give investigators a realistic view into the original source material.
· Enhanced Searching – Search, sort and filter artifact data for relevant keywords, time/date stamps, tags, or comments, or layer filter criteria to pinpoint items in a natural interface.
· File Hashing – Calculate hashes of files for simplified verification and searching. Additional support for Project VIC hash sets and PhotoDNA.
· Custom Artifacts – create custom artifact definitions to add extensibility and find more data. Artifacts must be easy to create by either following an XML template or common scripting language such as Python.
· Portable Case – Utilizing a portable case methodology to share the workload and intelligence back to stakeholders is an important part of the forensic workflow. Non-technical stakeholders can view a portable case with the ability to search and further refine results for inclusion into the final report based on information they possess that may not have been shared with the examiners.
· Timeline Feature -use of timeline feature which allows to be viewed results in a graphical timeline with the ability to import .tln files. It has the capability to drill down to isolate webmail, chat messages, browser history and more during a specific time-frame and zero-in on specific dates in time, or spikes in a suspect's online activity.
3.2 DVR Examiner. DVR Examiner by Magnet Forensics, brand name or equal, shall meet the following technical parameters:
· One day in-person classroom instruction by Magnet Forensics representatives at the NCFI facility in Hoover, AL for every activation of 20 or more licenses purchased covering the use of the tool for criminal investigations.
· One year software maintenance services including software updates and support.
· Capable of recovering video and metadata from password protected, broken, and burnt CCTV and surveillance DVRs in most cases, even when data is deleted or inaccessible.
· Allows users to connect directly to a DVR hard drive or forensic image, bypassing passwords and menus.
· Allows users to build a case including incident details as well as multiple locations, device, and sources.
· Capable of ingesting multiple hard drives and/or image files into a single case, and easily follow a suspect from camera to camera, location to location.
· Provides an easy-to-use interface and intuitive workflow that is understood by non-technical users.
· Allows users to preview clips and export in proprietary formats or convert to easily playable AVI files.
· Allows users to correct dates and times
3.3 Outrider. Outrider by Magnet Forensics, brand name or equal, shall meet the following technical parameters:
· Two years software maintenance services including software updates and support.
· Capable of performing quick triage of Mac and Windows computers, iOS and Android mobile devices, and external drives for illicit content such as child sexual assault material (CSAM), usernames, and contacts in the field or the lab with automated insights.
· Automatically uncover SMS/MMS messages, illicit apps, device ID, recently used apps, contact list, call logs, and more, in under six minutes.
· Scan multiple mobile devices at the same time.
· Detect the presence of secure folders and multiple user accounts.
· Scan internet browser history, text messages, recent activity, and account information for keywords, specific URLs and file names from an imported NCMEC CyberTip report, or load targeted URLs and keywords that are relevant to a case.
· Use MD5 and MAG24 hash matching to locate files from known hashsets like VICS or CAID.
· Has a machine learning classification model to predict the likelihood that a file contains imagery of child sexual abuse.
· Scans for encrypted files and encryption keys.
· Performs live system scans with the option to collect:
· Operating system artifacts
· Random Access Memory (RAM)
· Screenshots of the desktop
· External IP address for the system
3.4 Griffeye Advanced. Griffeye Advanced by Magnet Forensics, brand name or equal, shall meet the following technical parameters:
· Two years software maintenance services including software updates and support.
· Swiftly process and analyze vast amounts of images and videos.
· Utilizes artificial intelligence and machine learning models to automatically detect and classify various objects in large image sets and identify and flag previously unseen images and videos depicting child sexual abuse.
· Quickly find and match all images and videos featuring different individuals, and search between the data to identify matching faces of suspects or victims.
· Rapidly and accurately review hours of video footage in a fraction of the time using advanced filtering capabilities such as motion, facial, and object-based searches.
· Enhance investigator well-being with multiple features designed to minimize exposure to harmful material.
· Establish connections to multiple GID databases, including external sources such as NCMEC, to seamlessly collaborate with investigators on a national or international scale.
· Automated processes and functionality to detect critical content in unseen material, reducing manual work and exposure.
· Advanced analysis such as Facial Recognition, a robust Video Utility Pack, and additional matching and searching functions.
· Library of apps and plugins, including AI tools and other third-party options, for customizable extension.
· Seamless workflows for investigative work, including easy import/export across units.
· Dedicated support team to assist with any inquiries by the user.
3.5 Product Activation Timing. NCFI operates on a trimester system. Class trimesters are from October through January, February through May, and June through September. The following trimester’s course schedule is announced at the beginning of the proceeding trimester. (e.g., October through January’s course schedule is announced in June; February through May’s course schedule is announced in October, etc.) The NCFI COR will coordinate with the vendor 60-90 days prior to the course start date, to assure ample quantity of the software line items are ordered, delivered, and on hand to support the class start date. However, the software line item (license) shall NOT activate or start until the first day of class. Note: There are typically 25 students per course, yet not all will attend, therefore the government COR will work with the vendor to assure only the required number of licenses are activated at the class start date. The governments’ goal is to provide as much advanced notice as possible.
4. Acceptance:
4.1 *Each software package shall be packaged in a courier shippable cardboard box with contents labeled on the outside indicating the contents and type of software. Each box should not be more than 40 pounds in weight.
4.2 All deliveries are the contractor’s responsibility. The contractor shall coordinate the deliveries with the Contracting Officer’s Representative (COR) or Office Point of Contact (POC) prior to the delivery, specifying the date and time (see paragraph 7 for the POC information). The contractor shall be responsible for off and on loading equipment and materials. Coordination of deliveries shall follow the process noted below:
(a). Vendor shall email a detailed shipment tracking spreadsheet to Michael.Searcy@usss.dhs.gov and Robert.peterson@usss.dhs.gov when items are shipped and when delivery service verifies delivery.
(b). Software packages shall not be shipped until complete. To do otherwise, requires written approval from the COR (Michael Searcy).
(c). No substitutions are allowed without written approval from the COR.
(d). Contractor shall email a detailed shipment tracking spreadsheet to Michael.Searcy@usss.dhs.gov and Robert.Peterson@usss.dhs.gov when items are shipped and when delivery service verifies delivery.
(e) Vendor shall email a courtesy copy of all invoices uploaded to IPP to Michael.Searcy@usss.dhs.gov and Robert.Peterson@usss.dhs.gov.
4.3 Software Packages shall be delivered no later than the dates indicated within each Delivery Order awarded on this contract. Deliveries MUST be scheduled. If the delivery has to be turned away the vendor will incur the cost for return and reshipment to destination. * Hours of Delivery: 0800-1500 CST (-6 UTC)
| 4.4 Place of Delivery: | NCFI | |
| Attn: Michael Searcy | ||
| 2020 Valleydale Road, Suite 209 | ||
| Hoover, AL 35244 |
4.5 Within each delivery order issued on the IDIQ, the contractor will be required to coordinate and work closely with the USSS technical point of contact for the duration of the project.
4.6 The USSS technical point of contact will notify the contractor in writing of the acceptance or rejection of each deliverable. The review time by the Government will vary based on the size and complexity of the deliverable. Rejected deliverables shall be returned and corrected by the contractor within ten (10) working days of return receipt from the USSS technical point of contact. To assure success with resolving issues promptly, the Contractor shall provide the Government with a support process (help desk or other such process). Hours of availability shall be at a minimum of 8:00 am to 4:00 pm CST, Monday through Friday.
5. Contract Type and Ordering Procedures.
5.1 Type of Contract: The Government will award a commercial IDIQ with an ultimate completion date of 60 months from the date of contract award. This is a firm-fixed price IDIQ with a 5-year ordering period from date of award through 60 months.
5.2 Contract Attachment 3, Approved Pricing Table: This contract attachment establishes the pricing and anticipated delivery order data (across the ordering periods), for each software package. This table shall be used when placing delivery orders as it specifies the approved firm fixed price per line item.
5.3 Ordering Procedures: The complete ordering procedures are contained within Contract Attachment 2, Clauses. As stated above, the FFP price per line item is contained within Attachment 3. The initial delivery order may be executed (awarded) at time of the IDIQ award. When executing subsequent delivery orders the government shall supply the contractor the type of software being acquired, the quantity of each being acquired, the required dates of delivery and send the draft order to the contractor for review and agreement. Once agreement is received, the Government will award the delivery order and provide the Contractor with the final approved copy to execute deliveries against.
5.4 Note: The government anticipates procuring a full complement of each software line item to support the course schedule (see trimester plan, SOW paragraph 3.7) by placing an order every 4 months or three times per year at the start of each trimester, dependent on government funding flow. If funding does not flow in this steady fashion, the government may place large orders (April – September) and a number of smaller orders (October – March) to assure the annual needs are met for the calendar year. All orders will be placed IAW FAR 52.216-19 in Attachment 2 of the contract. Regardless if funds flow in a steady or unsteady state, the NCFI goal is to order enough licenses to assure the vendor has 60 days’ notice to meet the required delivery dates.
5.5 Delivery Requirements: All products/services procured through delivery order shall be delivered in accordance with the delivery schedule contained within the order.
5.6 Technology Refresh: If technology evolves over the course of the contract, technology refresh negotiations may occur every 12 months from time of contract award to assure Government receipt of the latest technology.
6. Period of Performance: The delivery date and period of performance will be annotated within the CLIN Structure and the deliverables table contained within delivery order issued.
7. United States Secret Service Technical Point of Contact
NCFI
Attn: Michael Searcy 2020 Valleydale Rd., Suite 209 Hoover, AL 35244 Michael.searcy@usss.dhs.gov Phone: 404-783-5956
PART 2
DEFINITIONS & ACRONYMS
2. DEFINITIONS AND ACRONYMS:
2.1. DEFINITIONS:
Software Maintenance Services (SMS), also known as Software Maintenance and Support, provides technical support, bug fixes, software updates and software upgrades to the customer for the licensed software.
2.1.1. CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the Government. The term used in this contract refers to the prime.
2.1.2. CONTRACTING OFFICER (C.O.). A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the Government. Note: The only individual who can legally bind the Government.
2.1.3. DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.
2.1.4. KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the SOW. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.5. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
2.2. ACRONYMS: [As needed, list all acronyms used in the SOW and what they represent. At a minimum, insert the acronyms provided below].
| CFR | Code of Federal Regulations | |
| CO | Contracting Officer | |
| CONUS | Continental United States (excludes Alaska and Hawaii) | |
| COR | Contracting Officer Representative | |
| COTS | Commercial-Off-the-Shelf | |
| CPFF | Cost Plus Fixed Fee | |
| FAR | Federal Acquisition Regulation | |
| FFP | Firm Fixed Price | |
| GFP | Government Furnished Property | |
| HSAR | Homeland Security Acquisition Regulation | |
| LH | Labor Hour | |
| NCR | National Capital Region | |
| OCI | Organizational Conflict of Interest | |
| OCONUS | Outside Continental United States (includes Alaska and Hawaii) | |
| ODC | Other Direct Costs | |
| PIPO | Phase In/Phase Out | |
| POC | Point of Contact | |
| PM | Program Manager | |
| SMS | Software Maintenance Services | |
| SOW | Statement of Work | |
| TE | Technical Exhibit | |
| TM | Time and Material | |
| TPOC | Technical Point of Contact |
Section 508 Requirements
Section 508 of the Rehabilitation Act (classified to 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Appendixes A, C & D, and available at https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards. ICT includes IT and other equipment.
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018, or any successor publication.
Section 508 Requirements for Technology Products
Section 508 applicability to Information and Communications Technology (ICT): software licenses
Applicable Exception: N/A Authorization #: N/A
Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.
Applicable 508 requirements for electronic content features and components: Does not apply
Applicable 508 requirements for software features and components (including but not limited to Other): All requirements in Chapter 5 apply, including all WCAG 2.0 Level A and AA Success Criteria Apply except 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation, 3.2.4 Consistent Identification, 502 Interoperability with Assistive Technology, 503 Application, 504 Authoring Tools
Applicable 508 requirements for hardware features and components (including but not limited to Peripheral Equipment (ex. keyboards)): All requirements in Chapter 4 apply
Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply
Section 508 Deliverables
Section 508 Accessibility Conformance Reports: For each ICT item offered through this contract (including commercially available products, and solutions consisting of ICT that are developed or modified pursuant to this contract), the Offeror shall provide an Accessibility Conformance Report (ACR) to document conformance claims against the applicable Section 508 standards. The ACR shall be based on the Voluntary Product Accessibility Template Version 2.0 508 (or successor versions). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed by following all of the instructions provided in the template, including an explanation of the validation method used as a basis for the conformance claims in the report.
File details come from the government source that posted it. Updated .