What's New in Belkasoft X v2.12
Belkasoft Evidence Center X (Belkasoft X) is Belkasoft's flagship product for digital forensics, cyber incident response, and eDiscovery.
Belkasoft X v2.12 brings a broad set of new features and improvements in AI-assisted analysis, Android acquisition, SQLite forensics, artifact extraction, and offline operation:
- Offline evidence translation with BelkaGPT for chats, messages, and other artifact text
- BelkaGPT-powered SQLite database classification with predefined and custom categories
- Custom SQLite artifacts for structuring and analyzing data from unsupported databases
- BelkaGPT Hub installer for Windows for easier deployment of distributed offline AI processing
- Improved Android acquisition, including the redesigned MTK workflow and more flexible agent-based acquisition
- Belkasoft Offline Map Server for reviewing geolocation evidence without internet access
- Expanded Android and iOS artifact support, including lots of new and updated application parsers
- New Windows artifacts, including BAM/DAM, SRUM, and Remote Desktop Cache reconstruction
- Improved System Event Log analysis with event clustering and clearer log presentation
- RSMF 2.0 support and export splitting for large datasets
Upgrading from previous versions of Belkasoft X to v2.12 is free for all customers with an active Software Maintenance and Support (SMS) contract. Customers with expired or expiring SMS contracts can review and renew them through the Customer Portal.
Important: Customers with the BelkaGPT module also need to download and install the new BelkaGPT version available in the Downloads section of the Customer Portal.
New feature details
BelkaGPT
SQLite database classification
BelkaGPT can now classify SQLite databases by their contents, helping you zero in on relevant databases even when file names and paths give no clue to their purpose. It scans a representative sample of database records and assigns them with matching categories—predefined ones such as communications, locations, financial information, or credentials—or custom categories built around the evidence you are after.
This new feature is especially useful with unfamiliar or proprietary applications for which Belkasoft X does not yet have a dedicated parser. Instead of exploring every SQLite database by hand, you can quickly flag the ones most likely to hold relevant evidence and prioritize them for review.
Offline evidence translation
You can now translate evidence directly within Belkasoft X, with all processing performed locally and built directly into the normal artifact review workflow:
- Bulk translate chat and SMS messages
- Translate individual messages or conversations
- Search translated messages and add them to reports
- Translate text from all artifacts across the case, instantly, as you come across them
- Translate text directly in the BelkaGPT window
BelkaGPT automatically detects the source language and supports translation from more than 200 languages and dialects into over 100 target languages.
When you come across a message, note, document fragment, or other text in an unfamiliar language, you can translate it on the spot and keep working without moving evidence outside the forensic environment.
BelkaGPT Hub installer for Windows
Introduced in 2.12, BelkaGPT Hub installer for Windows simplifies deployment of distributed AI processing in a local network. Setup is designed for self-service: you can deploy BelkaGPT Hub components with little to no assistance from Belkasoft support.
BelkaGPT Hub lets you offload AI processing from individual forensic workstations to other machines better suited for the job, such as GPU-equipped workstations and servers. The installer gives you flexible control over available computing resources: you can select one or multiple GPUs for processing and engage the CPU for even more capacity.
This makes offline AI easier to scale across a team. Organizations can make better use of hardware they already own, share processing resources between investigators, and add capacity without equipping every forensic workstation with a high-end GPU.
Custom SQLite artifacts
Belkasoft X now lets you turn data from unfamiliar or unsupported SQLite databases into custom artifacts by mapping database tables and columns to standard Belkasoft X artifact fields, such as timestamps, participant names, message text, identifiers, geolocation fields, and other common evidence attributes.
Once the mapping is configured, Belkasoft X presents the selected data similarly to a regular artifact. You can then search, filter, review, report, and otherwise work with it alongside automatically parsed evidence elsewhere in the case.
Combined with BelkaGPT SQLite database classification, custom artifacts provide a practical workflow for unsupported applications: identify potentially relevant databases, inspect their contents, and map important data structures into investigator-defined artifacts for further analysis.
Belkasoft Offline Map Server
Belkasoft X 2.12 adds support for a locally deployed map server, allowing you to review geolocation evidence on maps without connecting forensic workstations to online mapping services.
The setup is straightforward: download the required map tiles, deploy the server within your network, and specify its address in Belkasoft X settings. This addition allows forensic laboratories to retain convenient geolocation analysis without relying on external services.
Mobile acquisition
Redesigned MTK Dump acquisition method
The workflow for MediaTek (MTK) device dumps has been redesigned to provide more flexibility for decryption and brute-force.
- Acquisition and decryption are now separate operations. After acquiring a dump, you can return to it later and decrypt the user data partition using a known passcode or run a brute-force attack if the passcode is unknown.
- Passcode brute-force is more flexible. Belkasoft X can work with an unknown passcode length and supports dictionary-based attacks against alphanumeric passwords. When passcode properties such as type and length can be recovered from the device data, Belkasoft X uses them to perform the brute-force attack more efficiently.
The improved workflow lets you acquire the device data first and determine how to access encrypted user data afterward. You can revisit the same dump as new information becomes available, try a different brute-force strategy, or decrypt it once the passcode is known.
Support has also been added for more chipsets: MT3369, MT6762, MT6880, MT6883, MT6889, MT6890, MT8765, MT8766B, and MT8768T.
Improved Android agent-based acquisition
Belkasoft X 2.12 makes the Android backup and Agent backup via SD card acquisition methods more reliable on recent Android versions and expands the range of data they can collect, including SMS messages and call history.
The Agent backup via SD card method is not limited to SD cards. The acquisition agent can be run on an Android device using other external storage media, such as a USB flash drive connected through a USB-C adapter. The new agent also allows you to select or create a folder within the device itself or on the storage media to save acquired data. This makes this method particularly useful for on-site acquisitions.
Artifacts
Android
Version 2.12 brings one of the largest Android artifact extraction updates in recent releases, with support for numerous new applications and improvements to existing parsers.
New
- Burner v5.10.5
- FairEmail v1.2313
- Google Play (library.db) v52.6.26-34
- Google Quick Search Box v11.26.7.21
- Google Voice v2024.01.29.603156670
- GroupMe v6.111.1
- Life360 v24.28.0
- Mastodon v2.5.0
- MeWe v8.1.16.99
- Microsoft Teams v1416/1.0.0.2024073501
- TeleGuard v4.0.1
- Waze v4.105.0.2
- Wire v3.81.15
Updated
- Facebook v559.0.0.49.75: Improved chat thread presentation; contact information is now available under Contacts in Overview
- Imgur v7.7.5.0: Improved video extraction
- Instagram v25.0.0.47.61: Improved conversation extraction, including threads and reactions
- Telegram v12.6.4: Added account owner name, replies, reactions, service messages, and call duration
- Viber v27.6.2.0: Added replies, reactions, call duration, and picture captions
- WhatsApp v2.26.19.73: Improved contact merging and reply visualization; added support for more system messages and shared vCard contacts
- X (Twitter) v11.86.0: Separated one-to-one and group chats from feed content; added extraction of pictures, voice messages, and reactions
iOS
Belkasoft X 2.12 also expands artifact extraction from iOS devices, adding support for ChatGPT and improving extraction and presentation for several other popular apps.
New
- ChatGPT v1.2026.160
Updated
- Apple Unified Logs: The Info field in Timeline now includes application names and other relevant details
- Imgur v2023.08.0: Improved video extraction
- Instagram v436.0.0: Improved contact and chat thread names and presentation of chat interactions
- WeChat v8.0.70: Improved extraction of messages, reactions, and media files
- Zalo v25.11.01: Added audio artifacts and corrected artifact counts
Windows
BAM/DAM artifact extraction
Belkasoft X 2.12 extends existing support for Background Activity Moderator (BAM) and Desktop Activity Moderator (DAM) artifacts to Windows 10 version 1809 and later. BAM/DAM data can provide evidence of executable activity on a Windows system, including executable paths and associated timestamps.
Remote Desktop Cache reconstruction
Belkasoft X can now extract and automatically reconstruct visual data from the Windows Remote Desktop bitmap cache.
During a Remote Desktop session, Windows caches portions of the remote screen as small bitmap tiles and updates the cache as displayed content changes. Belkasoft X extracts these cached fragments and automatically combines visually matching tiles into larger image sequences, making the recovered visual evidence easier to examine.
SRUM artifact extraction
Belkasoft X 2.12 now parses System Resource Usage Monitor (SRUM) data that provides historical information about application resource and network usage. Belkasoft X extracts application network activity together with associated timestamps, helping investigators determine which applications used network resources and when.
Improved System Event Log analysis
The System Event Log artifacts now include the Event cluster property, which groups events into meaningful activity categories such as system logon or logout, software installation, remote access, Wi-Fi connections, and system startup or shutdown. This makes large event logs easier to navigate and helps you quickly focus on specific types of system activity without reviewing individual Event IDs one by one.
The presentation of System Event Logs in the Incident Investigations window has also been redesigned. Clearer event log names in the artifact tree help you distinguish relevant log sources more quickly during malware analysis and corporate security investigations.
Clearer task statuses
Belkasoft X 2.12 revamps task statuses in the Dashboard and Tasks windows to provide a clearer picture of analysis progress and results. Parent tasks now summarize the statuses of their child operations, while revised labels and color-coded indicators make it easier to spot tasks that require attention or encounter problems.
The updated statuses also reflect artifact extraction results more accurately:
- Completed with warnings: The profile was processed, and some expected artifacts were extracted, but others could not be parsed.
- Completed with errors: The relevant profile was detected, but no artifacts could be extracted from it.
- Failed to complete: The operation itself failed and could not be completed.
Together, the revised statuses and visual indicators make it easier to identify problematic tasks, distinguish partial extraction from complete failure, and decide which task logs require review.
Updated YARA analysis
YARA analysis in Belkasoft X 2.12 has been reworked to improve reliability when processing large rule databases and partially malformed rules. The update also improves YARA task logging, making rule-processing issues easier to diagnose, and adds support for index files to simplify working with large or structured rule sets.
Together, these changes make YARA analysis more robust and easier to manage in complex investigations.
RSMF 2.0 and export splitting
Belkasoft X 2.12 adds support for RSMF 2.0 and introduces new options for splitting RSMF exports. You can now divide exports by a specified number of items or by maximum file size.
This makes it easier to prepare large RSMF datasets for import into platforms such as Relativity, where limits may apply to individual import files.
Other improvements
Belkasoft X 2.12 includes a number of refinements that make analysis, navigation, and evidence review more consistent.
- Clearer BelkaGPT options: BelkaGPT analysis option selection in the Add data source wizard is now better organized, while BelkaGPT commands in Artifacts context menus are grouped into dedicated sections.
- Improved device properties: Device information shown in File System is now aggregated from all relevant source files, with matching properties merged into a single value where appropriate.
- Better artifact navigation: Attachments can now be opened both in Structure and File System. Audio artifacts also include additional context-menu commands, including Go to parent.
- More consistent File System presentation: Symlinked folders are now displayed consistently.
- Expanded search coverage: Artifacts from bt_config files are now indexed and available for search.
- Restored macOS autorun parsing: Correct parsing of macOS Autorun agents and macOS Autorun daemons from their .plist files has been restored.
See also
Belkasoft X 2.11
Belkasoft X 2.10
Belkasoft X 2.9
Belkasoft X 2.8
Belkasoft X 2.7
Belkasoft X 2.6
Belkasoft X 2.5
Belkasoft X 2.4
Belkasoft X 2.3
Belkasoft X 2.2
Belkasoft X 2.1
Belkasoft X 2.0
Belkasoft X 1.17
Belkasoft X 1.16
Belkasoft X 1.15
Belkasoft X 1.14
Belkasoft X 1.13
Belkasoft X 1.12
Belkasoft X 1.11
Belkasoft X 1.10
Belkasoft X 1.9
Belkasoft X 1.8
Belkasoft X 1.7
Belkasoft X 1.6
Belkasoft X 1.5
Belkasoft X 1.4
Belkasoft X 1.3
Belkasoft X 1.2
Belkasoft X 1.1
Belkasoft X 1.0
Belkasoft Evidence Center 9.9
Belkasoft Evidence Center 9.8
Belkasoft Evidence Center 9.7
Belkasoft Evidence Center 9.6
Belkasoft Evidence Center 9.5
Belkasoft Evidence Center 9.4
Belkasoft Evidence Center 9.3
Belkasoft Evidence Center 9.2
Belkasoft Evidence Center 9.1
Belkasoft Evidence Center 9.0
Belkasoft Evidence Center 8.6
Belkasoft Evidence Center 8.5
Belkasoft Evidence Center 8.4
Belkasoft Evidence Center 8.3
Belkasoft Evidence Center 8.2
Belkasoft Evidence Center 8.1
Belkasoft Evidence Center 8.0
Belkasoft Evidence Center 7.5
Belkasoft Evidence Center 7.4
Belkasoft Evidence Center 7.3
Belkasoft Evidence Center 7.2
Belkasoft Evidence Center 7.1
Belkasoft Evidence Center 7.0
Belkasoft Evidence Center 6.3.1
Belkasoft Evidence Center 6.3
Belkasoft Evidence Center 6.2
Belkasoft Evidence Center 6.1
Belkasoft Evidence Center 6.0
Belkasoft Evidence Center 5.4
Belkasoft Evidence Center 5.3
Belkasoft Evidence Center 5.2
Belkasoft Evidence Center 5.1
Belkasoft Evidence Center 5.0
Belkasoft Evidence Center 4.2
Belkasoft Evidence Center 4.1
Belkasoft Evidence Center 4.0
Belkasoft Evidence Center 3.9
Belkasoft Evidence Center 3.8
Belkasoft Evidence Center 3.7
Belkasoft Evidence Center 3.6
Belkasoft Evidence Center 3.5
Belkasoft Evidence Center 3.0
Belkasoft Evidence Center 2.0

