has moved to this site, For information, please join the Google Group forensicswiki-reborn

Belkasoft Acquisition Tool

From Forensics Wiki
Jump to navigation Jump to search
Belkasoft Acquisition Tool
Maintainer: Belkasoft
OS: Windows
Genre: Disk imaging
License: Commercial

The Belkasoft Acquisition Tool (BelkaImager) is a free forensic imaging utility distributed by Belkasoft. It helps investigators to complete one of the most important steps of investigation: obtaining data from a data source. Four types of data sources are currently supported:

  • Hard or removable drives
  • Mobile devices
  • Computer RAM memory
  • Cloud data

The acquired image can be then analyzed with Belkasoft Evidence Center or any third-party tool.

Hard and removable drive imaging

BelkaImager can acquire hard drives, SSD drives and removable drives connected to your computer, laptop or tablet. The drive can be acquired as DD or E01 image. Physical acquisition is performed.

Mobile device acquisition

The product acquires data from Android and iOS devices (iPhones, iPads), including iOS 10. Logical image is acquired.

RAM capturing

RAM memory of a running Windows computer, laptop or tablet can be dumped in a raw format.

Cloud data downloading

BelkaImager can download data from most important clouds such as iCloud, Google Drive and Google Plus.