Reliable end-to-end solution to accelerate digital forensic and cyber incident response investigations
Overview
Belkasoft X Forensic (Belkasoft Evidence Center X) is a flagship tool by Belkasoft for computer, mobile, drone, car, and cloud forensics. It can help you to acquire and analyze a wide range of mobile and computer devices, run various analytical tasks, perform case-wide searches, bookmark artifacts, and create reports.
This tool is offered to Government customers only.
Easy-to-use
Belkasoft X Forensic works out of the box and can be easily integrated into customer workflows. The software interface is so user-friendly that you can start working with your cases right after the Belkasoft X deployment.
Comprehensive investigations
Belkasoft X Forensic acquires, examines, analyzes, and presents digital evidence from major sources—computers, mobile devices, RAM, cars, drones, and cloud services—in a forensically sound manner. If you need to share the case details with your colleagues, use a free-of-charge portable Evidence Reader.
Quick and smart
While performing search tasks for evidence, Belkasoft X Forensic uses approaches that enable it to find the most forensically significant artifacts quickly instead of wasting time on redundant operations.
Powerful analytical features such as a connection graph, a timeline and advanced picture and video analysis help you to uncover facts rapidly.
Save your time and efforts
Belkasoft X automates search tasks, and thus the product can run unattended, you can multitask and complete an investigation at a quick pace.
Tailored to your needs
You can select a product edition that suits your workflow, whether you are an expert in a digital forensic laboratory of a federal law enforcement agency or in a digital forensic and incident response consulting company, an investigator in a local or state police department, or a private practitioner.
Thanks to the flexible price structure you will find the product edition which perfectly fits your needs and budget.
Time-proven
Belkasoft X Forensic encompasses many years of experience, a team of outstanding professionals, a large amount of user feedback, and expert suggestions from numerous investigators in both law enforcement and the corporate world.
Features
Mobile and Computer Acquisition
The product allows you to acquire data from a computer, a laptop or a mobile device. Hard and removable drives are acquired into DD and E01 formats with optional hash calculation and verification. For mobile devices running iOS Belkasoft X acquires iTunes backup and full file system copy with keychain by means of agent-based and checkm8-based methods or when a device is jailbroken; for Android devices there are multiple approaches to data acquisition: standard ADB or agent-based backup, Qualcomm and MTK-specific dumps, physical and logical backup for rooted devices, APK downgrade and other methods.
E01/DD imaging
checkm8
Jailbreak support
Agent-based acquisition
Mobile and Computer Device Examination
Supporting all major desktop and mobile operating systems, Belkasoft X Forensic is suitable for mobile and computer forensics. It can parse real and logical drives and drive images, virtual machines, mobile device backups, UFED and GrayKey images, JTAG and chip-off dumps.
Chat apps
Browsers
Mailboxes
Documents
Pictures & videos
Audio
System files
Mobile apps
Payment apps
Online games
Clouds
P2P
Smart and Comprehensive Analysis
The product looks everywhere on the device completely automatically and can successfully identify thousands types of digital artifacts. Convenient Evidence Search feature helps to narrow down the findings using filters, pre-defined search, or other options.
File system explorer
Artifacts viewer
SQLite viewer
Registry viewer
Plist viewer
Hash set analysis
Advanced picture and video analysis
WDE and file decryption
Timeline
Connection graph
Native SQLite parsing
Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files. Processes write-ahead logs, journal files, and SQLite unallocated space.
Live RAM analysis
Belkasoft X Forensic can extract potentially crucial information from volatile memory, such as: in-private browsing and cleared browser histories, online chats and social networks, cloud service usage history, and much more. Belkasoft Live RAM Capturer is a powerful tool for creating memory dumps, and it is complimentary.
Handy built-in tools
Plist, Registry, and SQLite viewers allow you to work more thoroughly with particular types of data and find even more evidence than automatic search was able to discover.
Low-level investigations
Through its File System window, Hex Viewer, and Type Converter tools, Belkasoft X Forensic allows you to perform deep examinations into the contents of files and folders from devices. With its customizable File and Data carving functions, you get to recover deleted and hidden artifacts and perform memory process analysis to view alive and dead processes in memory dumps. You can also use its hash algorithms to run searches against hash sets (NSRL RDSv3 and ProjectVic formats included).
Customizable reports in multiple formats
Reports in numerous formats such as text, HTML, XML, CSV, PDF, RTF, Excel, Word, EML, KML, ProjectVIC JSON, Relativity Short Message Format, Semantics21 and others.
Free portable case viewer
Free Evidence Reader allows sharing your findings with your colleagues with or without Belkasoft X Forensic installed.
Belkasoft X Forensic is the complete solution for conducting in-depth investigations on all types of digital media devices and data sources, including computers, mobile devices, RAM, drones, car images, and the cloud. It is an irreplaceable analytical tool for digital forensic laboratories of federal law enforcement agencies and state-level police departments.
When you purchase this product, you get to:
Computer Forensics:
Extract data from hard drives, mount and analyze hard drives, disk images, virtual machines, and RAM
Examine and analyze hundreds of artifacts: instant messengers, browsers, mailboxes, documents, images and videos, system files, online games, and payment applications, cloud artifacts
Acquire images of multiple iOS and Android device models by means of several acquisition methods such as standard backups, agent-based dumps, lockdown files, checkm8, application downgrade and others
Analyze older models of Blackberry and Windows phones
Examine and analyze mobile artifacts—calls and messages, mailboxes, messenger apps data (WhatsApp, Signal, Telegram, Snapchat, WeChat, etc.), social media apps (Facebook, Twitter, Tinder, etc.), cryptocurrencies, browsers, and many more
Utilize Belkasoft X functionality to mount third-party tools images (UFED, GrayKey, etc.), mobile backups, chip-off dumps, TWRP images, JTAG dumps, etc.
Cloud Forensics: Acquire and analyze data from cloud sources
Car Forensics: Analyze Berla images to add digital artifacts from a car to your single case timeline
Drone Forensics: Examine digital artifacts from dozens of supported drone models
Analytical features:
Connection graph to reveal connections between artifacts and people in a case
Timeline to identify all the events within a specific timeframe
Smart and powerful carving feature to locate evidence that was deleted, destroyed, or never permanently stored on the hard drive at (page file, hibernation file, RAM contents)
Perform in-depth examinations into the contents of files and folders on the device with File System Explorer
Built-in Viewers: Find even more evidence with Plist, Registry, and SQLite Viewers; MFT and Alternate Data Stream Viewers, as well as low-level Hex Viewer
Decryption: Access devices encrypted with whole device encryption (WDE), such as APFS, Bitlocker, TrueCrypt and others