What's new in Belkasoft X v.1.13

Belkasoft X v.1.13: Support for nested archives review and analysis, checkm8-based acquisition for iOS 15.5, Tableau TX1 integration, iOS screen capturing, BTRFS support, advanced eDiscovery filters, automatic UTC to local time recalculation, more Android APK downgrade applications, in-depth support for Photos.sqlite on iOS, and many more

What's new in Belkasoft X v.1.13 Jun 7, 2022

Belkasoft Evidence Center X (Belkasoft X) is Belkasoft's flagship product for digital forensics, cyber incident response and eDiscovery.

Major updates for v.1.13:

  • Nested archives review and analysis
  • Seamless integration of Tableau TX1
  • checkm8-based acquisition of iOS 15.* (including devices running the newest iOS 15.5)
  • New iOS acquisition method: iOS screen capturer
  • BTRFS file system support including snapshots analysis
  • Advanced filters for improved eDiscovery productivity
  • UTC to local time recalculation
  • Extended Android APK downgrade method
  • In-depth support for iOS' Photos.sqlite analysis
  • New and updated artifacts for mobile and computer sources (including new versions of WhatsApp, Facebook, Snapchat, Mega, Evernote, ICQ, Gmail, Kate Mobile, Twitter and other apps)
DOWNLOAD A TRIAL
REQUEST A QUOTE

Upgrading from previous versions of Belkasoft X to v.1.13 is free to all customers with an active Software Maintenance and Support (SMS) contract. Customers with SMS contracts that have expired or are near expiration, may review and renew from your Customer Portal.

An affordable training with an optional certification is also available including the on-demand options.

New features details

  • Nested archives review and analysis. With the new functionality, Belkasoft X will help you to analyze data inside archives, automatically located inside your data sources. Once the ZIP, TAR, 7z, RAR, etc. file has been identified, Belkasoft X will unpack its contents and automatically analyze them for the set of 1500+ artifacts supported in Belkasoft X. Nested archives (i.e. archives inside archives) are also supported and analyzed.
  • Tableau integration. Belkasoft X v.1.13 streamlines investigations for Tableau TX1 devices owners. Now you can acquire images, automatically add them to your Belkasoft X case and analyze acquired elements with just a few clicks—all without operating Tableau! All you have to do is perform a one-time set up of your TX1 options, including your user and shared folder.
  • Major iOS acquisition update. Industry-first support for checkm8-based acquisition on iOS 15.5 devices and iOS screen capturer (a new acquisition method, previously only available for Android devices).

  • BTRFS support. BTRFS is a file system for Linux, which is gaining traction and of specific interest and importance for a DFIR investigator or eDiscovery specialist. BTRFS support also includes snapshot analysis.
  • Advanced filters. Further improvements to the advanced filter capabilities in the Belkasoft File System window. Utilize any number of simple criteria, join them using AND or OR conjunctions, use NOT clauses and named filters, and combine these capabilities to build even more complex filters for improved eDiscovery productivity.
  • UTC to local time recalculation. The Belkasoft X File System window and Artifacts display UTC time columns and their local time equivalent calculated based on the case timezone and data source timezone settings. These times are recalculated upon timezone changes, whether it is the entire case timezone or a single data source timezone. For all recalculated times, a hint is shown to emphasize that this time is not original, and an explanation of which timezone was used to obtain the displayed local time.
  • Android APK downgrade method is extended. Additional applications are supported: Badoo, Likee, Pinterest, QQ, SHAREit, Sina Weibo, Via Browser, Yandex Browser, and Zoom.
  • iOS Photos.sqlite analysis supported. Analysis of Photos.sqlite allows to track origins of photos on an iOS device, including camera (front/rear) or third-party application, time of creation, whether it was modified on the device or not, whether it was deleted or stored as a favorite.

New and Updated Artifacts

  • iOS
    • Gmail (updated)
    • WhatsApp (updated)
  • Android
    • Evernote (updated)
    • Facebook (updated)
    • ICQ (updated)
    • Kate Mobile (updated)
    • Mega (updated)
    • Snapchat (updated)
    • Twitter (updated)
    • WhatsApp (updated)
  • macOS
    • Telegram (new)

Updated User interface

  • Email viewer added
  • Created date is shown for volume shadow copy snapshots
  • Export to Evidence Reader can now be done from the Artifacts window (Structure pane)
  • Improvements for color blind users, including hints on bookmark color categories

Issues fixed

  • Fixed: iCloud Notes acquisition restored
  • Fixed: Office 365 acquisition restored
  • Fixed: 'Go to original item' from search results to bookmarks
  • Fixed: Reports in VICS 1.3 and 2.0 formats
  • Fixed: Re-attaching of nested data sources in the File System window
  • Fixed: Conversion to IP v.4 and Unix time is lost for Type Converter of HexViewer

DOWNLOAD A TRIAL
REQUEST A QUOTE

See also:

Belkasoft X 1.12
Belkasoft X 1.11
Belkasoft X 1.10
Belkasoft X 1.9
Belkasoft X 1.8
Belkasoft X 1.7
Belkasoft X 1.6
Belkasoft X 1.5
Belkasoft X 1.4
Belkasoft X 1.3
Belkasoft X 1.2
Belkasoft X 1.1
Belkasoft X 1.0
Belkasoft Evidence Center 9.9
Belkasoft Evidence Center 9.8
Belkasoft Evidence Center 9.7
Belkasoft Evidence Center 9.6
Belkasoft Evidence Center 9.5
Belkasoft Evidence Center 9.4
Belkasoft Evidence Center 9.3
Belkasoft Evidence Center 9.2
Belkasoft Evidence Center 9.1
Belkasoft Evidence Center 9.0
Belkasoft Evidence Center 8.6
Belkasoft Evidence Center 8.5
Belkasoft Evidence Center 8.4
Belkasoft Evidence Center 8.3
Belkasoft Evidence Center 8.2
Belkasoft Evidence Center 8.1
Belkasoft Evidence Center 8.0
Belkasoft Evidence Center 7.5
Belkasoft Evidence Center 7.4
Belkasoft Evidence Center 7.3
Belkasoft Evidence Center 7.2
Belkasoft Evidence Center 7.1
Belkasoft Evidence Center 7.0
Belkasoft Evidence Center 6.3.1
Belkasoft Evidence Center 6.3
Belkasoft Evidence Center 6.2
Belkasoft Evidence Center 6.1
Belkasoft Evidence Center 6.0
Belkasoft Evidence Center 5.4
Belkasoft Evidence Center 5.3
Belkasoft Evidence Center 5.2
Belkasoft Evidence Center 5.1
Belkasoft Evidence Center 5.0
Belkasoft Evidence Center 4.2
Belkasoft Evidence Center 4.1
Belkasoft Evidence Center 4.0
Belkasoft Evidence Center 3.9
Belkasoft Evidence Center 3.8
Belkasoft Evidence Center 3.7
Belkasoft Evidence Center 3.6
Belkasoft Evidence Center 3.5
Belkasoft Evidence Center 3.0
Belkasoft Evidence Center 2.0