From ForensicsWiki
Jump to: navigation, search

About Belkasoft

Belkasoft is a computer and mobile phone forensic software manufacturer since 2002. The company develops a range of forensic products aimed at law enforcement officials, investigators and experts in IT security and intelligence. The company delivers solutions that work right out of the box, without requiring a steep learning curve or any specific skills to operate.


The company’s flagship product is Belkasoft Evidence Center, an all-in-one solution for acquiring, extracting and analyzing digital devices such as hard drives, mobile devices and RAM, as well as for performing cloud forensics. After the acquisition, the product can extract or recover deleted data from the acquired image. Supported types of evidence analyzed out of the box include office documents, mailboxes of popular email clients, instant messenger logs, Internet browser histories, social network remnants, peer-to-peer data, multi-player game chats, pictures, videos, encrypted files, mobile backups, system files and so on. The product is equipped with a number of low-level viewers, such as Hex Viewer, Plist Viewer, Registry Viewer and SQLite Viewer. High-level analysis with the help of built-in Connection Graph Viewer is available.

Belkasoft Forgery Detection offers the ability to discover digital pictures that were altered, modified or otherwise manipulated. The tool applies a range of image analysis algorithms and a decisive neural network to produce a single numeric estimate of images’ authenticity.

In addition to commercial products, Belkasoft offers a range of free forensic tools.

Belkasoft Live RAM Capturer is a tiny free forensic tool to reliably extract the entire content of the computer's volatile memory - even if protected by an active anti-debugging or anti-dumping system. Separate 32-bit and 64-bit builds are available in order to minimize the tool's footprint as much as possible. Memory dumps captured with Belkasoft Live RAM Capturer can be analyzed with any forensic tool including Live RAM Analysis in Belkasoft Evidence Center.

Belkasoft Evidence Reader enables Evidence Center users to share evidence collected with the main suite. Users of Evidence Reader can access evidence collected during an investigation from any computer, even if Belkasoft Evidence Center is not installed on that PC.

Belkasoft Acquisition Tool (or BelkaImager) is a free utility to acquire a wide range of data sources: hard drives, running computers RAM memory, modern smartphones, and various types of clouds. The output can be analyzed with both Belkasoft and third-party tools.

Customer Base

Belkasoft customers include government and private organizations in more than 130 countries, including the FBI, US Army, US AirForce, DHS, Secret Service, police departments in Germany, Norway, Australia and New Zealand, all of the "big four" (PricewaterhouseCoopers, Ernst & Young, Deloitte, KPMG).


Belkasoft D-U-N-S number is 502889466. Belkasoft NATO Commercial and Government Entity (NCAGE, also CAGE) code is SKF09. Belkasoft is also registered within Central Contractor Registration (CCR), ORCA and WAWF. Belkasoft is a registered trademark.

External Links