Belkasoft Evidence Center 2018 v.8.6 Supports More Cloud and Memory Forensics
SUMMARY
Belkasoft rolls out an update to Belkasoft Evidence Center 2018. The new release
adds remote extraction ability for more than 30 unique cloud services, enhances
hibernation file analysis for Windows 10 computers, and adds support for the latest
encryption standard in WhatsApp messenger.
Sign up for a webinar on new BEC!
Belkasoft updates Belkasoft Evidence Center 2018 with multiple improvements,
offering remote extraction from more than 30 cloud services, adding support for
Windows 10 hibernation files and decrypting WhatsApp databases protected with the
latest crypt12 encryption. The new release also makes a number of improvements to
usability, bringing the Timeline as a top-level tab on the user interface and introducing
a new bubble mode for the chat view.
Remote Data Extraction with Cloud Support
The updated Belkasoft Evidence Center can remotely extract evidence from a wide
range of remote locations including Instagram, WhatsApp, Google Timeline as well
as all major email cloud services such as AOL, Comcast, Inbox.com, Qip, and many
others. The user’s authentication credentials are required to sign in to online
services. In many cases, these credentials can be extracted with Belkasoft Evidence
Center by analyzing the content of the suspect’s computer, hard drive or forensic
disk image.
The ability to access data stored in popular cloud services can significantly
increase the amount of evidence available to the investigator, often returning information
that is not available or has been deleted from the suspect’s PC.
Improved Volatile Evidence Support: Windows 8 and 10 Hibernation Files
Belkasoft pioneered volatile evidence carving in Evidence Center, offering experts
the ability to access evidence stored in the computer’s volatile memory (RAM) by
analyzing live memory dumps, hibernation and paging files. The analysis of volatile
data could lead to the discovery of essential evidence including the content of
recent chat conversations, recently viewed pictures or email messages sent or received
via a Web browser. In addition, the computer’s volatile memory may contain cryptographic
keys protecting encrypted PGP, BitLocker and TrueCrypt volumes.
In this release, Belkasoft Evidence Center further improves the analysis of hibernation
files produced by computers running Windows 10. Since the Windows hibernation format
incurred significant changes in Windows 8, previous versions of Evidence Center
were limited to analyzing hibernation files of Windows 7 PCs. Belkasoft Evidence
Center 8.6 adds support for the new hibernation file format introduced in Windows
8 and used in Windows 10.
Latest WhatsApp Encryption Support
WhatsApp is constantly working to improve security. Recent versions of WhatsApp
started using a new encryption algorithm dubbed as crypt12. Belkasoft Evidence Center
8.6 now supports crypt12 encryption for Android WhatsApp client as well as for WhatsApp
stand-alone cloud backups. A physical image of the Android device or a rooted Android
device is required in order to obtain the decryption key.
Sign up for a webinar on new BEC!
About Belkasoft Evidence Center
Belkasoft Evidence Center is a world-renowned tool used by thousands of customers
for conducting computer and mobile forensic investigations. Belkasoft Evidence Center
can automatically discover, extract and analyze evidence from a wide range of sources
including computer hard drives and disk images in all popular formats, memory dumps,
mobile backups and chip-off dumps. The tool can capture and analyze volatile evidence
stored in the computer’s RAM, identify encrypted files, carve Internet chat logs,
Web browsing history and email communications including information stored in digital
pictures and videos. The ability to process office documents in a wide range of
formats enables investigators to perform near-instant full-text search among all
the documents discovered on the suspect’s PC.
Low-level access to hard disk and system structures means that even data that
has been deleted by the suspect cannot escape from investigators. Supporting Windows,
Unix/Linux, Android and Mac OS X file systems, natively mounting images created
in EnCase, FTK, X-Ways, DD and SMART formats, UFED and chip-off binary dumps, and
many popular virtual machines without using these or any third-party tools, Belkasoft
Evidence Center can collect more evidence than any single competing tool in its
class.
About Belkasoft
Founded in 2002, Belkasoft is a global leader in digital forensics technology,
known for their sound and comprehensive forensic tools. With a team of professionals
in digital forensics, data recovery and reverse engineering, Belkasoft focuses on
creating technologically advanced yet easy-to-use products for investigators and
forensic experts to make their work easier, faster, and more effective.
With this focus in mind, Belkasoft introduces their flagship product, Belkasoft
Evidence Center – an easy-to-use, integrated solution for collecting and analyzing
digital evidence from mobile and computer devices. Customers in law enforcement,
police, military, business, intelligence agencies, and forensic laboratories in
70+ countries worldwide use Belkasoft Evidence Center to fight homicide, crimes
against children, drug trafficking, data leakage, fraud, and other online and offline
crimes.
Belkasoft D-U-N-S number 683524694.
Belkasoft NATO Commercial and Government Entity (NCAGE, also CAGE) code SKF09.
Belkasoft is also registered within Central Contractor Registration (CCR), ORCA
and WAWF.
Belkasoft is a registered trademark.
More information about the company and its products at
https://belkasoft.com
# # #
Information on Belkasoft Evidence Center as well as the free demo download are
available at https://belkasoft.com/get
The complete change log is available at https://belkasoft.com/new