Belkasoft Evidence Center Features

Case management
The product allows you to manage information for different cases. You can add information you are working with to a named case, give a name and a description to a case, create, edit and delete a case. This is handy when you work with multiple cases at a time.

Information persistence
All found information is now stored in a database. Unlike the older products, this product allows you to safely shut it down because all data is stored right after it is extracted. This enables you to work with multiple cases and handle big cases, for example, those involving multiple huge Outlook mailboxes. The product does not have a limit of 2Gb of Outlook mailbox space which the previous products have.

Integration
Unlike Belkasoft Forensic Studio which is a bundle of 3 products, Belkasoft Evidence Center integrates all the work with Instant Messengers, Browsers and Email in one user interface. You can perform all operations with a piece of evidence in a uniform way: it is possible, for example, to search through all found chats, URLs and emails in a single search operation. 
 

Multiple monitor support
The product has a number of windows showing various aspects of a case you are working with: Case Explorer, Item List, Item Properties, Task Manager and Search Results, to name just a few. To make it more efficient to work with this number of windows, the product supports multiple monitors so you can arrange windows and resize them as you find convenient. The product will remember your preferences and automatically restore window positions and sizes the next time you run product.

MultipleMonitors.jpg

 Search a seized drive for histories
There is a seized hard drive in your lab and you want to find all history files contained there. You do not know which means of online communication the suspect has been using. The product allows you to search the whole hard drive for all supported types of histories: Instant Messenger chats, Browser URLs history, various mailboxes:

•All drives or particular ones may be selected

•You can select a particular folder to search through

•Histories to be looked for may be limited to a particular type (e.g. Skype files only)

•You can search a drive connected via Encase

•It is possible to manually select a history to analyze

After the software found history profiles for you, it is possible to select any of them and add to a case. At this point you can instruct the software to calculate profiles hash values to make sure they are not changed during the investigation. 
 Analyze found histories
The product does all the analysis with two mouse clicks:

•No password required

•You do not have to be logged under a history owner

•No write access required. The product works with write-blocking devices

Retrieving deleted history
If some history was deleted by a user, chances are that part of it can still be found on the drive. In order to do it the product uses so-called 'carving' techniques which helps to retrieve deleted conversations.

The following features are supported:

•Carving FAT and NTFS drives

•Carving drives attached through write-blocking device

•Carving drive images (Encase, SMART or DD format)

•Live memory investigation (carving RAM image made in win32dd/win64dd or FTK Imager)

Note! This feature allows to retrieve conversations, deleted from a drive. It will not help you in case some history was never stored on that drive, except for RAM image carving.

Explore extracted histories
The product shows extracted information in a user-friendly form:

EvidenceCenter.jpg

Within the user interface you can:

•See all found history profiles

•See all contacts belonging to a chat profile

•See all mail folders belonging to an email profile

•See all conversations with a selected contact

•See all emails within a selected mail folder

•See a profile's original hash value and current hash value to make sure nothing was changed since the profile was added to a case

•Sort by various criteria

•Search history. Do simple searches through history and advanced searches using a file with a set of words to look for. Experienced users can benefit from searching by regular expressions, which is very useful while searching for templates or phrases with fuzzy structure, for example, credit card numbers

Bookmarking
You can mark any extracted information by using named bookmarks. Bookmarks are persistent and stored in the same database as the case is. You can see all pieces of information in a bookmark, go to the original item and, vice versa, from an item to any bookmark which contains that item. Bookmarked items are highlighted with another color, so you will not miss them in an item list.

Export history After completing your investigation, you need to export histories of interest in a readable form. The product allows you to:

Export histories

 to plain text, HTML, XML, CSV and PDF.

•Limit exported histories to selected dates and contacts

•Split huge histories into separate files, broken by contact or mail folder

•Split reports into smaller files by specifying a number of items to be included in the report, for example, 50 messages per report file

Instant Messengers supported
The following IMs are supported (regular file analysis):

•ICQ (all versions from 97a to ICQ 7)
•Microsoft MSN/LiveMessenger
•Skype versions 2, 3, 4, 5
•Skype chatsync
•Yahoo! Messenger
•MySpace IM
•&RQ
•Miranda
•SIM
•Google Hello
•QIP
•QIP Infium
•Trillian
•QQ 2008 and earlier
•QQ 2009, 2010, 2011
•Digsby
•Rambler Virtus
•Mail.Ru Agent
•Pidgin
•AIM
•Gadu-Gadu (version 6)
•Qutim
Deleted history carving support:

•Skype 3
•Skype 4, 5
•Digsby
•ICQ Lite
•ICQ 7
•Miranda IM
•Windows Live Messenger
•QIP Infium/2010
•SIM
•AIM
•Virtus
•Pidgin
•Trillian
•Mail.ru Agent 5
•Gajim
•Emesene
•Yahoo! Messenger
Live memory images carving:

•AIM
•AIM Express
•ICQ 7
•Yahoo! Messenger
•Skype
•Gmail
•Windows Live Messenger
•Meebo
•Google Talk
•Facebook (personal messages)
•Vkontakte.ru (personal messages)
•e-Buddy
•YaOnline
Browsers supported
The following browsers are supported:

•Microsoft Internet Explorer
•Mozilla Firefox starting version 2
•Opera
•Google Chrome
•Apple Safari (except for password recovery)
Mailboxes supported
The following mailbox types are supported:

•Microsoft Outlook 2003, 2007 and 2010
•Microsoft Outlook Express
•RITLabs The Bat! (beta version)
Product editions
The product is available in the following of editions:

Standard - this edition is a desktop product using local database.

•Enterprise - this edition is a client-server product allowing to store case information centrally on a dedicated server, so that different people can work with the same case simultaneously