Belkasoft Evidence Center 數位證據採集分析、網路安全、電腦鑑識 最佳軟體工具
讓調查員容易去搜索、分析、儲存及共享，在硬碟或電腦的揮發性記憶體(volatile memory)所發現到的數位證據。Evidence Center 將幫助調查員快速地定位分析在社群網路的殘留、即時通訊日誌、網際網路瀏覽器紀錄、受歡迎的電子郵件信箱、點對點對等數據、多玩家遊戲的聊天紀錄、辦公室文件、圖片、影片、加密檔案、手機備份、系統及註冊檔案。
隨著智慧型手機普及和廣泛的使用，促使發展手機的數位鑑證分析，Belkasoft Evidence Center 可從Windows 作業系統、Linux、MacOS X、以及智慧型手機 iOS 、Android、Windows Phone 和黑莓機 Blackberry 提取資料數據，有效協助鑑識人員進行數位證據資料的採集分析。
Evidence Center 2017 新版特色
Mobile and Computer device examination. Supporting all major desktop and mobile operating systems, Belkasoft Evidence Center is suitable for mobile and computer forensics. It can parse real and logical drives and drive images, virtual machines, mobile device backups, UFED images, JTAG and chip-off dumps.
Smart and Comprehensive Analysis. The product looks everywhere on the device completely automatically and can successfully identify over 700 types of digital artifacts. Convenient Evidence Search feature helps to narrow down the findings using filters, pre-defined search, or other options.
Powerful Carving. Data carving allows to locate evidence that was deleted, destroyed, or never stored on the hard drive at all (page file, hibernation file, RAM contents). Besides, advanced carving mode called BelkaCarving™ is available, making it possible to reconstruct fragmented chunks into contiguous pieces of information that would otherwise not be accessible at all.
Native SQLite Parsing. Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files. Prosesses freelists, write-ahead logs and journal files, and SQLite unallocated space.
Live RAM Analysis. Evidence Center can extract potentially crucial information from volatile memory, such as: in-private browsing and cleared browser histories, online chats and social networks, cloud service usage history, and much more. Belkasoft Live RAM Capturer is a powerful tool for creating memory dumps, and it is complimentary.
Handy Built-in Tools. PList, Registry, and SQLite viewers allow you to work more thoroughly with particular types of data and find even more evidence than automatic search was able to discover.
Low-level Investigations. Equipped with File System Explorer, Hex Viewer, and Type Converter, Belkasoft Evidence Center will allow you to perform deep examination of the contents of files and folders on the device.
Extendable with BelkaScript. Free scripting module allows user to write their own custom scripts in order to automate some of the routine and further extend the product's functionality.
- Case Management
- Evidence can be stored broken by cases
- Evidence Reader
- Allows unlimited sharing of discovered evidence at no extra charge
- Data Carving and Live Memory Analysis
- Recovers deleted and destroyed evidence as well as evidence stored in memory dumps, page and hibernation files. More on Live memory (RAM) analysis and page/hibernation file analysis
- Native SQLite parsing with freelist support and built-in viewer
- Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files.
- Enhanced Live RAM Analysis with BelkaCarving™
- Sophisticated BelkaCarving algorithm carefully reconstructs fragmented chunks into contiguous pieces of information, allowing the tool to extract broken pieces such as databases, recently viewed images, documents and other types of data that no other tool can access.
- Offers an aggregated view of all user activities regardless of data source including all supported email clients, instant messengers, social networks etc. in both textual and graphical representation
- Windows Registry support
- Automatically locates, parses and carves registry hives, extracting many types of valuable evidence. Handy built-int regedit-like viewer shows even badly damaged or corrupted files, particularly those resulting from carving of registries from unallocated space
- Kernel-Mode RAM Capturer
- Portable kernel-mode Live RAM Capturer available free of charge to acquire system memory sets protected with active anti-dedugging systems
- Industry standard
- Mounts EnCase, AFF, SMART and DD images including Windows, Linux and Mac OS X drives as well as virtual machine drives, such as VMWare and Virtual PC. Integrated with EnCase v.7 and Passware Kit Forensic
- Large case support
- Cases containing hundreds of gigabytes of evidence are supported
- Easy collaboration
- Enterprise edition allows for multi-user simultaneous work
- Persistent data analysis
- Analyzed data will be persistently stored in the database
Belkasoft Evidence Center offers an easy-to-use, integrated solution for collecting and analyzing digital evidence. The product is a perfect match for law enforcement, military, intelligence and business customers.
- Forensically sound solution
Does not alter or modify data on hard drives or disk images being investigated.
- Looks everywhere
Analyzes hard drives, Live RAM captures, page and hibernation files, Windows Registry, the content of virtual machines, forensic disk images, Android, iOS and Blackberry backups.
- Sophisticated analysis
Enables full-text search through all acquired evidence. Offers comprehensive analysis of time periods of interest via a graphic Timeline.
- Comprehensive examination
Discovers more than 430 types of artifacts, supporting all major instant messengers, browsers, email clients, social networks, P2P and file transfer tools etc. The search includes unallocated and re-allocated disk space, Volume Shadow Copy and other special Windows areas.
- Less missing evidence
Looks for hidden data, searches unusual places and examines files in little-known formats to discover more evidence than ever.
- Blazing fast operation
Analyzes information at the rate of disk data transfer, utilizing today's multi-core CPU's to their max.
- Easy to share evidence
The free Evidence Reader add-on offers an easy way to to transfer or share collected evidence at no extra charge.
- Quick to learn and easy to use
Designed to be usable in the field, Belkasoft Evidence Center is extremely easy to operate, and feasible even for single-incident investigations.
- Usable in the field
Portable edition can be plugged into any PC with no installation or configuration required.
- Reports can be presented in court
Generates clean and concise reports that can be presented to the court.
- Recovers destroyed evidence
Data carving allows locating evidence that was deleted, destroyed, or never stored on the hard drive at all (page file, hibernation file and live RAM analysis).
- Collaboration support
Enterprise edition allows working on cases together with set permissions and centralized data storage.
- Trusted solution
Forensic investigators all over the world, Fortune 500 companies and multiple private security specialists use Belkasoft software. Customers include the FBI, the US Army, German police, and more than thousand government organizations from over 50 countries.
Less Missed Evidence
Belkasoft Evidence Center can locate a huge number of artifacts, retrieving user’s chats, communications, Web browsing and file sharing activities occurring in a wide range of software. These artifacts include:
- All major office document types (Microsoft Office, OpenOffice, PDF, RTF)
- All major 80+ instant messengers (Windows, Mac OS X and Linux)
- All major Web browsers
- All popular email clients
- Major peer-to-peer (P2P) software
- Social networks and cloud applications
- Encrypted files detection for more than 150 encrypted file types
- Popular online multi-player games
- Still images and video files analyzed for pornography, faces and embedded text (e.g. scanned documents) in more than 90 picture formats
- Mobile device backups (iPhone, iPad, Android and Blackberry). Android UFED physical backups are supported
- System files including Jumplists, Thumbnail files (Windows 10 and older), SQLite databases
- Windows registry files
If you plan working with small or medium sized cases or deal with chats or Web browsers only, and if the amount of extracted data is relatively small, you can use your regular workstation to work with the product. There are no special hardware requirements. The software has been tested on regular computers, and it can handle cases of up to 10G of extracted evidence.
If you plan working with large cases, or if you are using the Enterprise edition, we recommend upgrading the hardware to match or exceed the following specifications:
- More RAM, the better. We recommend at least 4 GB of RAM.
- Fast CPU. A multi-core processor or a multi-processor PC is recommended.
- A dedicated SSD drive is preferred for SQL Server (or a fully dedicated physical hard drive).
Belkasoft Evidence Center 版本比較