Meet Belkasoft Evidence Center 3.0! Yuri Gubanov CEO, Belkasoft What's new in the recent Belkasoft release?

Slides:



Advertisements
Similar presentations
Managing References : Mendeley
Advertisements

Microsoft ® Office OneNote ® 2007 Training Using your Notebook to its fullest potential Kent School District presents:
How to Use Stowe School District
Services Course Windows Live SkyDrive Participant Guide.
Google Chrome & Search C Chapter 18. Objectives 1.Use Google Chrome to navigate the Word Wide Web. 2.Manage bookmarks for web pages. 3.Perform basic keyword.
V.2010 | © OverDrive, Inc | Page 1 v | © OverDrive, Inc | Page 1v | © OverDrive, Inc | Page 1 Learn how to browse,
Copyright © 2012 Certification Partners, LLC -- All Rights Reserved Lesson 4: Web Browsing.
Effective Discovery Techniques In Computer Crime Cases.
Operating System Customization
XP Browser and Basics1. XP Browser and Basics2 Learn about Web browser software and Web pages The Web is a collection of files that reside.
Computer & Network Forensics
Microsoft Office Illustrated Using Advanced Features.
Your online classroom. Powerhouse Campus o Custom Class dashboards o Links with Moodle, Studywiz, Bb, ClickView & all web apps o Links your school library.
Secure Private Cloud Storage for Business. The Market Trend File Sharing Any Device Any Where Public clouds are good enough to personal users but security.
Local Health Department Contact Tracking Database An easy to use, efficient way to track the contacts, inquiries and complaints your local health department.
1 New : Create your own message starting from scratch 2 New From Template: add professionally designed templates provided exclusively by Gorilla Contact.
Integrate your people maximize your knowledge Tel SalesBase Customer.
IMonitor Software About IMonitorSoft Since the year of 2002, coming with EAM Security Series born, IMonitor Security Company stepped into the field of.
PASSWORD MANAGEMENT MADE EASY A Project Play Date - September 26, 2008 Beth Carpenter, Library Services Manager, Outagamie Waupaca Library System.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
SmartLog X 3 TEAM Basic SmartLog X 3 TEAM Basic DescoEMIT.com USER STATUS USER EDIT TEST LOG ADMIN TEST MACHINE SCHEDULE INSTALL System Requirements:
For SharePoint 2010 In This Presentation: Connect Overview Connect Requirements Connect Installation Connect Initial Launch Explore SharePoint Upload.
INTERNET CHAPTER 12 Information Available The INTERNET contains a huge amount of information a huge amount of information information on any topic you.
Topics Basic Internet Concepts. Types of Information. Search Tools & Techniques. Managing Internet Resources. Browsing a mail. Composing a mail. Attaching.
How to discover ephemeral evidence with Live RAM analysis.
© 2006 Global Knowledge Training LLC All rights reserved. Deploying Outlook 2003 Configuring Clients Outlook 2003 Security and Performance New Outlook.
Introduction to QuoteWerks QuoteWerks allows companies in every industry to create detailed quotes with speed and efficiency. If you want to save time.
Backup Local Online For secure offsite storage of your , and making it available from any computer or smart phone. Backup accessed with.
Hands-On Virtual Computing
Belkasoft Evidence Center Yuri Gubanov CEO, Belkasoft What the flagship Belkasoft product can do for you?
How to make your investigation more complete in less time.
Introducing Dreamweaver MX 2004
MEAP Applications.
XP New Perspectives on Browser and Basics Tutorial 1 1 Browser and Basics Tutorial 1.
New Features in Release 9.2 (July 27, 2009). 2 Release 9.2 New Features Updated Shopping Experience Home/Shop page Shop at the top search New Hosted Supplier.
1 and Internet Evidence Mark Pollitt Associate Professor, Engineering Technology.
Created by Bonnie Smith SimNet Registration and Overview Created for Fresno City College CIT 12 – Computer Literacy Students.
1 OPOL Training (OrderPro Online) Prepared by Christina Van Metre Independent Educational Consultant CTO, Business Development Team © Training Version.
GSA’s Vendor and Customer Self Service (VCSS). Login to VCSS  To login to VCSS, perform the following steps: 1.Go to the GSA launch page (
Training Guide for Inzalo SOP Users. This guide has been prepared to demonstrate the use of the Inzalo Intranet based SOP applications. The scope of this.
Downloading and Installing Autodesk Inventor Professional 2015 This is a 4 step process 1.Register with the Autodesk Student Community 2.Downloading the.
June 14, 2007 © 2007 Bill Barnes Own Your Computer Presented for the PCCC Own Your Computer Demonstrated on Windows XP and Office 2003 Presented to Personal.
Presented By: Manpreet Singh Randhawa CSc 253. Chat Forensics Traditional Chat Forensics Web-based Chat Forensics IM Comparison Skype Security Skype Communication.
Meetingangels.com Service Buyer. Front Page 2created by ilancecustomization.com.
Copyright © 2002 Pearson Education, Inc. Slide 3-1 Internet II A consortium of more than 180 universities, government agencies, and private businesses.
T29 Upgrade changes. WebEx is changing in the latest release. From 19 th February WebEx will be upgraded to the latest version. Cisco introduces several.
Microsoft Office 2008 for Mac – Illustrated Unit D: Getting Started with Safari.
COM: 111 Introduction to Computer Applications Department of Information & Communication Technology Panayiotis Christodoulou.
Virtual Machines Module 2. Objectives Define virtual machine Define common terminology Identify advantages and disadvantages Determine what software is.
© 2014 VMware Inc. All rights reserved. Cloud Archive for vCloud ® Air™ High-level Overview August, 2015 Date.
Fab25 User Training Cerium Labs LabCollector - LIMS Lynette Ballast.
How to Use an Android Tablet Well Come To You few Steps For How to Use an Android Tablet?
Main Features of iSafe All-in-One Keylogger Universal keylogger of isafe, Inc. Suitable for home parental control,corporate employee monitoring and cheating.
Unit Unit 4 – Windows OS File Structure Introducing Your Computer Widows File Types, Trees & Explorer.
Responder Field Edition & Pro
CaRT eCapacity Initiative Ghana Productivity Apps
MICROSOFT OUTLOOK and Outlook service Provider
Introduction to QuoteWerks
Key Feature of Gen PC Spy
Responder Field Edition & Pro
Services Course 9/9/2018 3:37 PM Services Course Windows Live SkyDrive Participant Guide © 2008 Microsoft Corporation. All rights reserved.
Smart Org Charts in Microsoft Office 365: Securely Create, Collaborate, Edit, and Share Org Charts in PowerPoint and Online with OrgWeaver Software OFFICE.
(Includes setup) FAQ ON DOCUMENTS (Includes setup)
Skype For Business SUMMER OF SKYPE 2018.
InLoox PM Web App product presentation
software & cloud computing
(Includes setup) FAQ ON DOCUMENTS (Includes setup)
Presentation transcript:

Meet Belkasoft Evidence Center 3.0! Yuri Gubanov CEO, Belkasoft What's new in the recent Belkasoft release?

Previous forensic software  Belkasoft Evidence Center 1.0, 1.1 and 2.0.  Evidence Center is successor for Belkasoft Forensic Studio  3 separate products in 1: chats, browsers, s Belkasoft Forensic IM Analyzer  Chats Belkasoft Forensic Carver  Chats, Browsers New Belkasoft release: Belkasoft Evidence Center 3.0

Major Evidence Center features  Search and extraction for chats, browser history and s  Carving, Live RAM and Network traffic analysis  Mounting drive and Live RAM images  Case and User management  Bookmarking  Reports in text, xml, html, csv, pdf  Hash calculation  No Internet connection required (included in previous v.2.0) New Belkasoft release: Belkasoft Evidence Center 3.0

Major improvements to 3.0  Not just Windows anymore MacOS support added  Not just histories anymore Picture and video support added  Not just history extraction anymore Analysis added Also: Option to carve allocated/unallocated Hibernation and page file analysis Thunderbird client support New Belkasoft release: Belkasoft Evidence Center 3.0

MacOS support  Mounting HFS/HFS+ drives and drive images supported Encase, SMART, DD  Carving and regular history extraction, Instant Messengers only  Currently supported:  More history types to come New Belkasoft release: Belkasoft Evidence Center 3.0 Adium AIM Brosix Fire iChat ICQ InstantBird Mail.Ru Agent Mercury Nimbuzz Trillian Yahoo! Messenger

Picture support  Search for pictures  Extracting and showing EXIF and other properties  Filtering by various properties  Showing pictures with GPS coordinates on Google Maps and Google Earth New Belkasoft release: Belkasoft Evidence Center 3.0

Picture analysis  Pornography detection (beta)  Face detection Both frontal and profile  Text detection English Russian New Belkasoft release: Belkasoft Evidence Center 3.0

Video support  Search for video  Extracting key frames Saves time for video analysis: only significantly changed frames need review Less emotional stress for an investigator  Only need to see a set of pictures  The same analysis available for key frames as for pictures New Belkasoft release: Belkasoft Evidence Center 3.0

Filters  Powerful filter manager  Allows to create filters on one or more criteria Arithmetic, boolean and string operations AND/OR conjunctions Negating criterion using NOT  Applied to pictures and videos New Belkasoft release: Belkasoft Evidence Center 3.0

Carving  Previously: carving all drive/image  Now 3 options: Carve allocated Carve unallocated Carve both  Why carving allocated? E.g. corrupted files (e.g. met with IE dat files) Renamed files  Also: "mounting does not work under some XP machines" problem fixed New Belkasoft release: Belkasoft Evidence Center 3.0

Hibernation and page files  Support for carving hibernation and page files hiberfil.sys pagefile.sys  LiveRAM analysis available Instant Messenger artifacts Social network artifacts (Facebook) Browser artifacts (IE, Firefox) Gmail letters and drafts  Regular carving available All supported types New Belkasoft release: Belkasoft Evidence Center 3.0

Thunderbird support  Search and extraction of Thunderbird mailboxes msf format SQLite format is on the way  Huge mailboxes supported Tested on 3Gb mailbox: 30 minutes to extract New Belkasoft release: Belkasoft Evidence Center 3.0

Smaller enhancements  New Windows messengers: Paltalk (LiveRAM) Gajim emClient Nimbuzz Qutim Gadu-Gadu (old and new versions)  MacOS: see previous slides New Belkasoft release: Belkasoft Evidence Center 3.0

Smaller enhancements  Social networks: Facebook IE remnants Live RAM: chats and group chats  Better Gmail support Live RAM: Not only s, but also drafts extracted  Better Skype group chats extraction  Better ICQ 6 and 7 file transfer extraction  Multiple usability improvements E.g. Reporting now considers From/To dates inclusively  Possibility to tweak report templates E.g. put own logo instead of Belkasoft's one, tweak colors, fonts etc. New Belkasoft release: Belkasoft Evidence Center 3.0

Smaller enhancements  The Bat! mailbox analysis no more fails on big mailboxes (previously was failing on 1Gb sized ones)  Outlook mailbox analysis no more fails on 10Gb mailboxes  Sample histories included to setup Before one had to download manually from site  Setup on a machine without Internet connection supported 4 predefined setup packages for various Windows versions: English/German 32/64 bit Other Windows languages are also supported New Belkasoft release: Belkasoft Evidence Center 3.0

Price enhancements  More clear price structure Every additional feature cost the same  $250 per feature (floating license)  $200 per feature (fixed license)  More features in the base configuration Browser cache and passwords included  Previously were additional features Basic picture and video support included New Belkasoft release: Belkasoft Evidence Center 3.0

Available features 1.Deleted information retrieval (carving) 2.Live RAM dump analysis 3.Mounting images such as Encase evidence files, SMART, DD, mounting MacOS drives 4.Network traffic analysis for chat artifacts 5.Picture analysis 6.Video analysis New Belkasoft release: Belkasoft Evidence Center 3.0

More convenient registration process  No more entering licenses and mistakes in this  All feature and license information is included to a single file features.xml Sent to customer right after purchase Just put it in the product folder and product will register automatically  As previously, no Internet required for registration New Belkasoft release: Belkasoft Evidence Center 3.0

Less Hardware ID pain  Previously every change in hardware lead to new Hardware ID Even adding virtual device in VMWare!  Now less hardware changes count Customers will ask for new keys less frequently New Belkasoft release: Belkasoft Evidence Center 3.0

Comprehensive help  Read online at _Center_Help_Contents.asp _Center_Help_Contents.asp  Download PDF from 3.0_Help.pdf 3.0_Help.pdf New Belkasoft release: Belkasoft Evidence Center 3.0

Belkasoft customers  See for morehttp://belkasoft.com/home/en/Customers.asp

Why Belkasoft Evidence Center?  Reduced cost of investigation  Reduced investigation time  Less specific knowledge required for investigator  Ideal for triage  Simultaneous work of several analysts on the same case New Belkasoft release: Belkasoft Evidence Center 3.0

Where to get the product?  Product page:  Direct download link:  Registration page:  This presentation: New Belkasoft release: Belkasoft Evidence Center 3.0

About Belkasoft  Belkasoft – computer forensics software vendor  Site –  Founded at 2002  Contacts – product support – all questions – business-related  DUNS:  NCAGE: SKF09  CCR: see  We are also in ORCA and WAWF New Belkasoft release: Belkasoft Evidence Center 3.0

Customer problems solved New Belkasoft release: Belkasoft Evidence Center 3.0  Computer forensic investigation Is there any evidence on a suspect's computer?  Out-of-the box solution for a number of evidence types How to find such evidence quickly, without too much manual work?  Corporate security Did a fired employee unveil commercial secrets? Are current employees use computer only for business needs?  Intelligence and counterintelligence Are there any suspicious chats made in an internet café?  Parental control Is a child safe during web surfing and chatting?

Training  Belkasoft can handle online and onsite trainings if a customer requires this  Online training delivered via GoToMeeting (WebEx analogue)  Onsite training requires travel, accommodation and meal expenses to be covered by a customer  More details: New Belkasoft release: Belkasoft Evidence Center 3.0

Contact us!  Interested? Drop us an at right now!  Add Belkasoft CEO in LinkedIn: New Belkasoft release: Belkasoft Evidence Center 3.0