Belkasoft X 2.12: A Sneak Peak
Belkasoft X 2.12 is on the way, with major advances in AI-assisted analysis, mobile acquisition, SQLite forensics, and support for Windows and mobile artifacts.
This release continues to expand BelkaGPT, our fully offline AI assistant, into new parts of the investigative workflow. It can now help investigators understand unfamiliar SQLite databases and translate evidence without sending case data to external services. At the same time, we have made it easier to deploy distributed AI processing entirely within the local network.
Beyond AI, 2.12 brings a major overhaul of MediaTek acquisition and decryption, a more comprehensive Android agent-based acquisition method, custom SQLite artifacts, offline maps, and more.
Find relevant SQLite databases with BelkaGPT
A data source can contain dozens or even hundreds of SQLite databases. File names and paths sometimes make their purpose obvious. Quite often, they do not.
BelkaGPT can now automatically classify SQLite databases based on what is stored inside them. Instead of relying on the database name, BelkaGPT examines a representative sample of records and determines what kind of information the database appears to contain.

Classified databases display on the Overview tab under the detected class names
You can use predefined categories to identify databases containing data such as communications, locations, financial information, or credentials. More importantly, you can create custom categories for the specific evidence you are looking for.
This can be particularly useful when examining an unfamiliar or proprietary application. Even if Belkasoft X does not yet have a dedicated parser for it, BelkaGPT can help point you toward databases worth investigating instead of requiring you to inspect every database manually.
And, as with other BelkaGPT capabilities, database classification runs entirely offline.
Translate evidence offline
Multilingual evidence should not require investigators to choose between convenience and data confidentiality. BelkaGPT translation in 2.12 works locally and is integrated directly into the normal artifact review workflow.

Translated messages in the bubble chat view
You can:
- Mass-translate chat and SMS messages
- Translate individual messages
- Translate text from all artifacts across the case
This makes translation useful not only for a dedicated language-analysis stage, but also for everyday review. An investigator who encounters a message, note, document fragment, or other text in an unfamiliar language can translate it immediately and continue working without moving evidence outside the forensic environment.
Easier deployment of BelkaGPT Hub
Keeping AI processing offline is important. Deploying the infrastructure needed to process large volumes of data should not become an IT project of its own.
Belkasoft X 2.12 introduces a BelkaGPT Hub installer for Windows, simplifying deployment of distributed AI processing within a local network.
BelkaGPT Hub allows investigators to offload AI processing from individual forensic workstations to other machines with more suitable hardware, including GPU-equipped workstations and servers. The new installer gives you flexible control over available computing resources. You can select one or multiple GPUs for processing and engage the CPU to add even more capacity.

BelkaGPT Worker configuration options
This makes offline AI easier to scale across a team: organizations can make better use of existing hardware, share processing resources between investigators, and increase capacity without equipping every forensic workstation with a high-end GPU.
A revamp for MediaTek (MTK) brute-force and acquisition
We have redesigned the MTK Dump acquisition workflow, making it more flexible and easier to use.
- Dump acquisition and decryption are now separate operations. Once a dump has been acquired, you can decrypt it with a known passcode or brute-force an unknown one.
- Passcode brute-force now supports unknown passcode lengths and dictionary-based attacks on alphanumeric passwords.
- Additional MTK-based device models are supported for brute-force, acquisition, and decryption
These changes are especially useful with damaged or non-booting phones, where the investigator may have little information about the device before acquisition. Capture the available data first, then determine the appropriate decryption strategy.
More reliable Android agent-based acquisition
Belkasoft X 2.12 brings major improvements to Android backup and Agent backup via SD card acquisition methods, with better stability on recent Android versions and access to a broader set of device data.
The goal is straightforward: make agent-based acquisition a more dependable option on current Android devices while extracting more useful evidence in a single workflow.
Turn unsupported SQLite databases into custom artifacts
With custom SQLite artifacts, you can define how an unfamiliar database should be interpreted by mapping its tables and columns to familiar Belkasoft X artifact fields—for example, timestamps, participant names, message text, identifiers, and other common evidence attributes.
Once the mapping is configured, the data is presented as a Belkasoft X artifact. That means the resulting evidence can be searched, filtered, correlated, and reviewed together with automatically parsed artifacts elsewhere in the case.
Combined with BelkaGPT database classification, this creates a useful workflow for unsupported applications: find potentially relevant databases with AI, inspect them, and turn important data structures into investigator-defined artifacts.
Windows Remote Desktop Cache
Windows Remote Desktop can retain bitmap fragments of the remote screen on the client computer. These cached fragments are commonly stored as small tiles and can preserve visual traces of a remote session even after the connection has ended.
Belkasoft X now extracts Remote Desktop cache tiles and automatically groups visually similar fragments into rows to assist in reconstruction.
Instead of reviewing a collection of isolated image squares, investigators get a much more practical starting point for determining what may have been visible during an RDP session.
System Resource Utilization Monitor (SRUM)
Belkasoft X 2.12 also parses System Resource Utilization Monitor (SRUM) data.
SRUM can provide historical information about network usage by individual applications, together with timestamps and related system information. For incident response, this can help investigators understand which applications communicated over the network and when, adding another source of evidence for reconstructing activity on a Windows endpoint.
ChatGPT and Claude mobile artifacts
AI applications are becoming even more ubiquitous than web searches—and potentially more revealing. Their data may provide insight into a user’s interests, concerns, plans, research topics, and other activities.
Belkasoft X 2.12 adds artifact extraction support for the ChatGPT and Claude mobile apps, bringing locally available data from these apps into the same investigative environment as messages, browser activity, documents, and other digital evidence.
Maps for fully offline investigations
Internet access is not always available—or permitted—on forensic workstations.
Belkasoft X 2.12 can work with a locally deployed map server, allowing investigators to retain map-based evidence review in isolated and restricted environments.
You can download map tiles, deploy the Belkasoft Offline Map Server inside your network, and specify its address in Belkasoft X settings, location evidence can then be displayed on maps without contacting an external mapping service.
For labs that keep all operations offline, this means one less investigative capability that has to depend on an internet connection.
More to come
These are only some of the improvements coming in Belkasoft X 2.12.
The release brings together several areas we have been steadily developing: more capable AI that remains completely offline, acquisition workflows that accommodate imperfect real-world conditions, deeper support for mobile and Windows evidence, and more ways for investigators to work with data that does not fit a predefined parser.
Full details are coming with the release of Belkasoft X 2.12 in just a few weeks. Stay tuned!