最新版 Belkasoft X Forensic v.2.6 更新於 2024/10/22
Belkasoft X Forensic (原為 Belkasoft Evidence Center X)
數位證據採集分析、網路安全、電腦鑑識 最佳軟體工具
Belkasoft X Forensic 是 Belkasoft 的旗艦工具,用於電腦、行動裝置、無人機、汽車和雲端取證。它可以幫助您獲取和分析各種行動和電腦設備、運行各種分析任務、執行案例範圍的搜尋、為工件添加書籤以及建立報告。
讓調查員容易去搜索、分析、儲存及共享,在硬碟或電腦的揮發性記憶體(volatile memory)所發現到的數位證據。Evidence Center 將幫助調查員快速地定位分析在社群網路的殘留、即時通訊日誌、網際網路瀏覽器紀錄、受歡迎的電子郵件信箱、點對點對等數據、多玩家遊戲的聊天紀錄、辦公室文件、圖片、影片、加密檔案、手機備份、系統及註冊檔案。
隨著智慧型手機普及和廣泛的使用,促使發展手機的數位鑑證分析,Belkasoft Evidence Center 可從Windows 作業系統、Linux、MacOS X、以及智慧型手機 iOS 、Android、Windows Phone 和黑莓機 Blackberry 提取資料數據,有效協助鑑識人員進行數位證據資料的採集分析。
綜合調查
Belkasoft X Forensic 以取證方式從主要來源(電腦、行動裝置、RAM、汽車、無人機和雲端服務)取得、檢查、分析和呈現數位證據。如果您需要與同事分享案件詳細信息,請使用免費的便攜式證據閱讀器。
方便使用
Belkasoft X Forensic 開箱即用,可以輕鬆整合到客戶工作流程中。軟體介面非常用戶友好,您可以在 Belkasoft X Forensic 部署後立即開始處理您的案例。
快速、智能
在執行證據搜尋任務時,Belkasoft X Forensic 使用的方法使其能夠快速找到最具取證意義的工件,而不是將時間浪費在冗餘操作上。連接圖、時間軸以及進階圖片和影片分析等強大的分析功能可幫助您快速發現事實。
節省您的時間和精力
Belkasoft X Forensic 有效率地自動執行提取和分析任務。該產品可以在無人值守的情況下運行,也可以使用命令列實現自動化,從而使您可以同時處理多項任務並更快地完成調查。
根據您的需求量身定制
無論您是聯邦執法機構數位取證實驗室的專家、地方或州警察局調查員,我們的永久許可和實惠的價格都將完全滿足您的需求和預算。
經過時間考驗
Belkasoft X Forensic 擁有多年的經驗、優秀的專業團隊、大量的用戶回饋以及來自執法部門和企業界眾多調查人員的專家建議。
MOBILE AND COMPUTER ACQUISITION
The product allows you to acquire data from a computer, a laptop or a mobile device. Hard and removable drives are acquired into DD and E01 formats with optional hash calculation and verification. For mobile devices running iOS, Belkasoft X Forensic acquires iTunes backup and full file system copy with keychain by means of agent-based and checkm8-based methods or when a device is jailbroken; for Android devices there are multiple approaches to data acquisition: standard ADB or agent-based backup, Qualcomm and MTK-specific dumps, physical and logical backup for rooted devices, APK downgrade and other methods.
- E01/DD imaging
- checkm8
- Jailbreak support
- Agent-based acquisition
MOBILE AND COMPUTER DEVICE EXAMINATION
Supporting all major desktop and mobile operating systems, Belkasoft X Forensic is suitable for mobile and computer forensics. It can parse real and logical drives and drive images, virtual machines, mobile device backups, UFED and GrayKey images, JTAG and chip-off dumps.
- Chat apps
- Browsers
- Mailboxes
- Documents
- Pictures & videos
- Audio
- System files
- Mobile apps
- Payment apps
- Online games
- Clouds
- P2P
SMART AND COMPREHENSIVE ANALYSIS
The product looks everywhere on the device completely automatically and can successfully identify thousands types of digital artifacts. Convenient artifact search, sorting, bookmarking and filtering help to narrow down the findings.
- File system explorer
- Artifacts viewer
- SQLite viewer
- Registry viewer
- Plist viewer
- Hash set analysis
- Advanced picture and video analysis
- WDE and file decryption
- Timeline
- Connection graph
NATIVE SQLITE PARSING
Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files. Processes freelists, write-ahead logs, journal files, and SQLite unallocated space.
LIVE RAM ANALYSIS
Belkasoft X Forensic can extract potentially crucial information from volatile memory, such as: in-private browsing and cleared browser histories, online chats and social networks, cloud service usage history, and much more. Belkasoft Live RAM Capturer is a powerful tool for creating memory dumps, and it is complimentary.
HANDY BUILT-IN TOOLS
Plist, Registry, and SQLite viewers allow you to work more thoroughly with particular types of data and find even more evidence than automatic search was able to discover.
LOW-LEVEL INVESTIGATIONS
Through its File System window, Hex Viewer, and Type Converter tools, Belkasoft X Forensic allows you to perform deep examinations into the contents of files and folders from devices. With its customizable File and Data carving functions, you get to recover deleted and hidden artifacts and perform memory process analysis to view alive and dead processes in memory dumps. You can also use its hash algorithms to run searches against hash sets (NSRL RDSv3 and ProjectVic formats included).
CUSTOMIZABLE REPORTS IN MULTIPLE FORMATS
Reports in numerous formats such as text, HTML, XML, CSV, PDF, RTF, Excel, Word, EML, KML, ProjectVIC JSON, Relativity Short Message Format, Semantics21 and others.
FREE PORTABLE CASE VIEWER
Free Evidence Reader allows sharing your findings with your colleagues with or without Belkasoft X Forensic installed.
版本介紹
X Forensic
Belkasoft X Forensic is the complete solution for conducting in-depth investigations on all types of digital media devices and data sources, including computers, mobile devices, RAM, drones, car images, and the cloud. It is an irreplaceable analytical tool for digital forensic laboratories of federal law enforcement agencies and state-level police departments.
When you purchase this product, you get to:
- Computer Forensics:
- Extract data from hard drives, mount and analyze hard drives, disk images, virtual machines, and RAM
- Examine and analyze hundreds of artifacts: instant messengers, browsers, mailboxes, documents, images and videos, system files, online games, and payment applications, cloud artifacts
- Mobile Forensics:
- Brute-force passcodes for a range of iOS and Android devices
- Acquire images of multiple iOS and Android device models by means of several acquisition methods such as standard backups, agent-based dumps, lockdown files, checkm8, application downgrade and others
- Analyze older models of Blackberry and Windows phones
- Examine and analyze mobile artifacts—calls and messages, mailboxes, messenger apps data (WhatsApp, Signal, Telegram, Snapchat, WeChat, etc.), social media apps (Facebook, Twitter, Tinder, etc.), cryptocurrencies, browsers, and many more
- Utilize Belkasoft X functionality to mount third-party tools images (UFED, GrayKey, etc.), mobile backups, chip-off dumps, TWRP images, JTAG dumps, etc.
- Cloud Forensics: Acquire and analyze data from cloud sources
- Car Forensics: Analyze Berla images to add digital artifacts from a car to your single case timeline
- Drone Forensics: Examine digital artifacts from dozens of supported drone models
- Analytical features:
- Connection graph to reveal connections between artifacts and people in a case
- Timeline to identify all the events within a specific timeframe
- Smart and powerful carving feature to locate evidence that was deleted, destroyed, or never permanently stored on the hard drive at (page file, hibernation file, RAM contents)
- Perform in-depth examinations into the contents of files and folders on the device with File System Explorer
- Built-in Viewers: Find even more evidence with Plist, Registry, and SQLite Viewers; MFT and Alternate Data Stream Viewers, as well as low-level Hex Viewer
- Decryption: Access devices encrypted with whole device encryption (WDE), such as APFS, Bitlocker, TrueCrypt and others
- Automation: Streamline your processes and parallelize your work across different workstations
- Cloud-based image analysis: Easily share larger images inside your Amazon S3-compatible private or government cloud
- Perpetual, not a term-based license!
X Corporate
All editions of Belkasoft X Corporate contain the following features:
- Computer Forensics
- Mobile Forensics
- Drone Forensics
- Memory Forensics
- Incident Investigations module
- Remote Acquisition module
Belkasoft X Small Business Simple and cost-effective edition for occasional use |
Belkasoft X Scale Scalable solution for corporate digital investigators' teams |
Belkasoft X Enterprise All-in-one solution adjustable for your company's needs |
Belkasoft X Site Everything you need and customizable |
This includes: – Belkasoft R with 2 endpoints – Number of concurrent users—1 – WDE Decryption (only with annual contract) – 1 onboarding session – 1 corporate training course access |
This includes: – Belkasoft R with 10 endpoints – Number of concurrent users—2 – Mobile device passcode brute-force (only with annual contract) – Automation – WDE Decryption (only with annual contract) – Free access to all corporate and digital forensics on-demand courses – 2 onboarding sessions |
This includes: – Belkasoft R with 100 endpoints – Number of concurrent users—5 – Mobile device passcode brute-force (only with annual contract) – Automation – S3 support – WDE Decryption (only with annual contract) – File Decryption (only with annual contract) – Premium support – Dedicated account manager and support team member – Interface localization by request – Onsite installation and configuration (only with annual contract) – Free access to all corporate and digital forensics on-demand training courses – Сertification training, 10 people—online or onsite (only with annual contract) – 10 onboarding sessions (valid 90 days only) – Annual refresher webinar |
This includes: – Unlimited number of concurrent users – Mobile device passcode brute-force (only with annual contract) – Automation – S3 support – Belkasoft R with unlimited endpoints – WDE Decryption (only with annual contract) – File Decryption (only with annual contract) – Software customization – Possibility to work offline – Premium support with dedicated account manager and support team member – Interface localization by request – Free access to all corporate and digital forensics on-demand training courses – Certification training, unlimited number of participants—online or onsite – 10 onboarding sessions (valid 90 days only) – Annual refresher webinar |
Technical specifications
Belkasoft X allows data acquisition and analysis from multiple sources
COMPUTER
- Operating systems: Windows (all versions, including Windows 11), macOS, Unix-based systems (Linux, FreeBSD, etc.)
- Storage devices: hard drives and removable media
- Disk images: EnCase, FTK, X-Ways, AFF4, L01/Lx01, DD, SMART, Atola, DAR, DMG, archive files (such as tar, zip and others)
- Virtual machines: VMWare, Virtual PC/Hyper-V, VirtualBox, XenServer
- Cloud storage: Amazon S3-based images
- Memory: RAM dumps, hibernation files, page files
- File systems: APFS, BTRFS, FAT, exFAT, NTFS, HFS, HFS+, ext2, ext3, ext4, XFS
- Acquisition: Available to DD or E01 images with optional hash calculation and verification
MOBILE
- Operating systems: iOS (iPhone/iPad), Android, Windows Phone 8/8.1, Blackberry
- Data sources: Mobile backups, GrayKey, UFED and OFB images, UFDR reports, chip-off and JTAG dumps, TWRP images, Blackberry IPD and BBB backups, Android physical and logical dumps, Xiaomi MIUI backups, Huawei HiSuite backups
- File systems: APFS, HFS+, F2FS, YAFFS, YAFFS2, ext2, ext3, ext4
- Acquisition
- iOS: iTunes, agent-based, checkm8-based, lockdown file support, AFC, jailbroken devices support, crash logs, screen capture
- Android: ADB backup, advanced ADB backup, agent backup, rooted devices support, PTP/MTP, EDL for Qualcomm, APK downgrade, agent-based/logical/physical MTK acquisition, Spreadtrum acquisition, automated screen capture, wireless acquisition via an agent on an SD card
- SIM cards: SIM cards cloning through a SIM reader device and through native Android means
CLOUD
- Google Clouds: Google Drive, Google Sync, Google Keep, GMail, Google Timeline, Google MyActivity
- iCloud
- Email: Yahoo, Hotmail, Opera, Yandex, Mac.com and 25 more webmail clouds
- Huawei
- Microsoft 365
- WhatsApp: backups downloading and QR code-based chat downloading
- Telegram
- VK
DRONES
- Supported models: ArduPilot DIY Drone, DJI Agras MF-1S, DJI Matrice, DJI Mavic, DJI Phantom 3, DJI Phantom 4, DJI Spark, Parrot Anafi, Qysea Fifish P3, Ryze Tello, Sense Fly, Sky Viper, Yuneec H520, Yuneec Typhoon Q500 and other compatible models
- Supported artifacts: drone geolocation and tracks, operator logs and tracks, pictures, videos
- Visualization: Drone flight route maps and operator route maps in a built-in Maps window
CAR IMAGES
- Supported images: Berla .ivo export for Belkasoft
- Supported artifacts: geolocation and tracks, chats, SMSes, and calls, contacts, media, and other information from the infotainment system
- Visualization: Drive routes in a built-in Maps window