PRODUCTS
Solve your cases faster with the fitting tools!
Mobile And Computer Acquisition
The product allows you to acquire data from a computer, a laptop or a mobile device. Hard and removable drives are acquired into DD and E01 formats with optional hash calculation and verification. For mobile devices running iOS Belkasoft X acquires iTunes backup and full file system copy by means of agent-based and checkm8-based methods or when a device is jailbroken; for Android devices there are multiple formats: standard ADB or agent-based backup, EDL and physical backup for rooted devices.
E01/DD imaging
Agent-based acquisition
checkm8
Jailbreak support
Mobile And Computer Device Examination
The product looks everywhere on the device completely automatically and can successfully identify thousands types of digital artifacts. Convenient Evidence Search feature helps to narrow down the findings using filters, pre-defined search, or other options.
Chat apps
Browsers
Mobile apps
System files
Mailboxes
Documents
Online games
Payment apps
Pictures & videos
Audio
P2P
Clouds
Smart And Comprehensive Analysis
The product looks everywhere on the device completely automatically and can successfully identify thousands types of digital artifacts. Convenient Evidence Search feature helps to narrow down the findings using filters, pre-defined search, or other options.
File System Explorer
Artifacts viewer
WDE and file decryption
Advanced picture and video analysis
SQLite viewer
Registry viewer
Connection graph
Timeline
Plist viewer
Hash set analysis
E01/DD imaging
Incident investigations
Cross-case analysis
Features
Native SQLite parsing
Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files. Processes write-ahead logs, journal files, and SQLite unallocated space.
Live RAM analysis
Belksoft Evidence Center X can extract potentially crucial information from volatile memory, such as: in-private browsing and cleared browser histories, online chats and social networks, cloud service usage history, and much more. Belkasoft Live RAM Capturer is a powerful tool for creating memory dumps, and it is complimentary.
Handy built-in tools
PList, Registry, and SQLite viewers allow you to work more thoroughly with particular types of data and find even more evidence than automatic search was able to discover.
Low-level investigations
Through its File System window, Hex Viewer, and Type Converter tools, Belkasoft Evidence Center X allows you to perform deep examinations into the contents of files and folders from devices. With its customizable File and Data carving functions, you get to recover deleted and hidden artifacts and perform memory process analysis to view alive and dead processes in memory dumps. You can also use its hash algorithms to run searches against hash sets (NSRL and ProjectVic formats included).
Editions
X Computer edition
X Computer edition is a cost-effective solution developed specifically for investigators in local police departments, experts in small to medium consulting companies providing digital forensic and incident response services, and individual customers such as private investigators or digital forensic consultants.
Customers who typically deal with only a few computer-related cases per year and/or have a limited budget will enjoy the very affordable price of X Computer edition.
When you purchase this edition, you get to:
Use analytical features:
X Mobile
X Mobile edition is a cost-effective solution developed specifically for investigators in local police departments, experts in small to medium consulting companies who provide digital forensic and incident response services, as well as individual customers (i.e. private investigators or digital forensic consultants).
Customers who typically deal with just few cases per year involving unlocked mobile devices, and usually have limited budgets will enjoy the affordable price of X Mobile edition.
When you purchase this edition, you get to:
X FORENSIC
X Forensic editionis the complete solution for conducting in-depth investigations on all types of digital media devices and data sources, including computers, mobile devices, RAM and the cloud. It is an irreplaceable analytical tool for digital forensic laboratories of federal law enforcement agencies and state-level police departments.
When you purchase this edition, you get all the features available in X MOBILE and X COMPUTER editions.
Additionally, you get to:
X CORPORATE
X Corporate edition is the digital forensic and incident response solution with enhanced analytical functionality specifically developed to meet the business requirements of large corporate organizations, which prefer to have a DFIR team in-house or provide DFIR services. Corporate incident responders can take advantage of a combination of X Forensic capabilities and advanced X Corporate features incorporated into the product specifically to respond to the demands of corporate customers.
When you purchase this edition, you get all the features available in X FORENSIC edition.
Additionally, you get to:
Belkasoft Evidence Center X Allows Data Extraction From Multiple Sources
COMPUTER
- Windows (all versions, including Windows 10), macOS, Unix-based systems (Linux, FreeBSD, etc.)
- Storage devices: hard drives and removable media
- Disk images EnCase, AD1 AFF4, L01/Lx01, FTK, DD, SMART, X-Ways, Atola, DMG, archive files (such as tar, zip and others)
- Virtual machines: VMWare, Virtual PC/Hyper-V, VirtualBox, XenServer
- Memory: RAM dumps, Hibernation files, Page files
- File systems: APFS, FAT, exFAT, NTFS, HFS, HFS+, ext2, ext3, ext4
- Acquisition:Available to DD or E01 images with optional hash calculation and verification
MOBILE Operating systems:
- iOS (iPhone/iPad), Android, Windows Phone 8/8.1, Blackberry
Data sources
Mobile backups, UFED and OFB images, GrayKey, chip-off dumps, TWRP images, JTAG dumps, Blackberry IPD and BBB backups, Android physical dumps, Xiaomi MIUI backups, Huawei HiSuite backups
File systems:
F2FS, YAFFS, YAFFS2
Acquisition
- iOS: iTunes, agent-based, checkm8-based, lockdown file support, PTP/MTP, jailbreak support
- Android: ADB backup, agent-based backup, physical backup (rooted Android), PTP/MTP, MTK
CLOUD
- Email: Yahoo, Hotmail, Opera, Yandex, Mac.com and 25 more webmail clouds
Owerview
Easy to use
Belkasoft Evidence Center X works out of the box and can be easily integrated into customer workflows.
The software interface is so user-friendly that you can start working with your cases right after the Belkasoft X deployment.
Comprehensive investigations
Belkasoft Evidence Center X acquires, examines, analyzes, and presents digital evidence from major sources—computers, mobile devices, RAM and cloud services—in a forensically sound manner. If you need to share the case details with your colleagues, use a free-of-charge portable Evidence Reader.
Quick and smart
While performing search tasks for evidence, Belkasoft Evidence Center X uses approaches that enable it to find the most forensically significant artifacts quickly instead of wasting time on redundant operations.
Powerful analytical features such as a connection graph, a timeline and advanced picture and video analysis help you to uncover facts rapidly.
Save your time and efforts
Belkasoft X automates search tasks, and thus the product can run unattended, you can multitask and complete an investigation at a quick pace.
Tailored to your needs
You can select a product edition that suits your workflow, whether you are an expert in a digital forensic laboratory of a federal law enforcement agency or in a digital forensic and incident response consulting company, an investigator in a local or state police department, or a private practitioner.
Thanks to the flexible price structure you will find the product edition which perfectly fits your needs and budget.
Time-proven
Report
Customizable reports in multiple formats
Reports in numerous formats such as text, HTML, XML, CSV, PDF, RTF, Excel, Word, EML, KML.
Free portable case viewer
Contact persons
Our experts are happy to help you.
Jonathan Graeff
License & Technical Sales
E-MAIL: jonathan.graeff@mh-service.de
PHONE: +49 (0) 7275 40444-53
Johannes Seitz
License & Technical Sales
E-MAIL: johannes.seitz@mh-service.de
PHONE: +49 (0) 7275 40444-52