Belkasoft Evidence Center 6.3.1: Photo Forgery Detection Plugin updated and a ton of bugfixes
Belkasoft Evidence Center 6.3.1: Photo Forgery Detection Plugin updated and a ton of bugfixes
Belkasoft releases new version of Evidence Center 2014. In version 6.3.1, developers massively improved Photo Forgery Detection Plugin, supported ext4 file system for Linux, added Plist viewer and fixed a lot of issues reported by our customers.
Improved Photo Forgery Detection
One of most sophisticated functions which developers offer our customers is Photo Forgery Detection, which helps to robustly determine, whether a photo was changed after leaving a digital camera or smartphone. With v.6.3.1 developers enhanced this function even more:
- New cameras added. Belkasoft Evidence Center supported 300 more cameras and now the total amount of supported devices exceeds 3300!
- New algorithm introduced: Error Level Analysis. Error level analysis (ELA) identifies areas within an image that are at different compression levels. With JPEG images, the entire picture should be at roughly the same level. If a section of the image is at a significantly different error level, then it likely indicates a digital modification.
- New algorithm introduced: Double Quantization Tables. Double Quantization Tables (DQT) algorithm determines whether the picture was compressed in the JPEG format more than once. If the JPEG file was opened, edited and saved, some compression artifacts will inevitably appear.
With all these improvements, Belkasoft Forgery Detection Plugin becomes more powerful and robust than ever. More information: http://belkasoft.com/forgery-detection.
New features in Belkasoft Evidence Center v.6.3.1
There are a number of new and updated functions in Belkasoft Evidence Center:
- Android analysis extended: Firefox, Dolphin, Mercury and Baidu browser analysis supported; Vipole, Line and ICQ instant messengers added
- Ext4 filesystem supported. This is widely used Linux/Unix file system which now can be processed even without drivers
- Apple DMG disk image format supported
- Automatic virtual machine drives mounting. Now, if a folder inside a drive or drive image contains virtual machine files, they will be mounted as a data source automatically. You don't have to search Virtual Machines and add their files manually. Moreover, the product will process nested virtual machines, so that you can automatically add, for example, a pagefile inside virtual machine, which was kept inside another virtual machine.
- Mac OS X property list (PList) viewer added
Updated features
A huge amount of existing functions was updated:
- Facebook, Gmail, Twitter, Mail.Ru, Brosix, Skype and WhatsApp analyzers updated
- HFS/HFS+ file systems support improved
- A pack of reporting improvements done
- ICQ8/Mail.Ru search improved
- GUI and performance enhancements done
The complete information is available at http://belkasoft.com/bec/en/whats_new_in_version_6.3.1
Belkasoft Acquisition & Analysis Suite Update
With the release of Evidence Center 6.3.1, developers updated our all-in-one toolkit, Belkasoft Acquisition & Analysis Suite, with all the features of the updated Evidence Center.
Belkasoft Acquisition & Analysis Suite includes all the hardware and software tools required to acquire a live PC, including tools for capturing memory dumps, imaging hard drives and acquiring USB devices. During the analytic stage, you can discover existing, hidden and destroyed evidence, analyze data and perform a comprehensive investigation. The Suite comes with full reporting capabilities and allows sharing, archiving and managing evidence. Read more about Belkasoft Acquisition & Analysis Suite at http://belkasoft.com/baas
Belkasoft User Refresher Course
Are you lost after updating Belkasoft Evidence Center to the latest version? With many features being constantly added to our forensic tool, it's easy to lose track of what's available and how to use it. Discover the latest additions to Belkasoft Evidence Center and learn how to use them effectively in a single online training session! The interactive online Belkasoft User Refresher Course is only 1.5 hours long. After taking this course, you'll be able to use all the functions of Belkasoft Evidence Center in your investigations. Subscribe online ($299.95)
You can also purchase full one-day training. Please contact at contact@belkasoft.com.
