BlackBag’s BlackLight 2016 R3 is Now Available!

BlackBag Technologies is pleased to announce the third major release of BlackLight for 2016. This comprehensive Windows, Android, iPhone/iPad and Mac forensic analysis software just keeps getting better. Update your software now!

BlackLight 2016 R3 implements several new features and improvements, including the following:

– Windows 8 and 10 hiberfil.sys and Raw Memory Parsing, Searching, and Analysis
– Windows Event Log and Apple System Log Parsing and Analysis
– iOS and OS X Recents Database Parsing
– Additional iOS 10 Encrypted Backup Support
– New Data Structure Templates

Plus:

– Windows Hash Set Included
– Type-down Feature in List Views
– Go To Position (Offset) in Hex View
– Internet History Parsing for Internet Explorer 10, 11, and Edge
– Social Media Parsing of ooVoo, Kik attachments, iOS Messsage GPS
– Time Machine Folder Hard Links Now Resolved


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

View a more detailed description of the features on our blog or attend our webinar for a live demonstration.WINDOWS 8 AND 10 MEMORY PARSING, SEARCHING AND ANALYSIS
Up until now no one has figured out how to parse Windows 8 and 10 memory and extract meaningful data. BlackLight 2016 R3 can now provide a wealth of information previously unavailable. These memory files are parsed within the “Advanced Processing Options” in the same manner as with Windows Vista and 7.

Just as with earlier versions of BlackLight, files can be carved from within these Windows 8 and 10 memory files and revealed in BlackLight’s Browser view. Searches are run for important items of interest such as, internet searches, Facebook addresses, internet domains, phone and credit card numbers, and more.

OPERATING SYSTEM LOG FILE PARSING (WINDOWS – EVT/EVTX & APPLE – ASL)
Both Windows and Apple Operating Systems have system logging functionality used to record events. Windows event logs are typically maintained in three files: Application, System, and Security. Windows Vista and later use the XML Event log format (EVTX). Events of interest can be found by browsing, using the Find function, and using the View Filter.

Apple System Logs are binary files controlled by a system daemon. ASL logs are stored in private/var/log/asl/ and other directories, but information can also output to the system.log. Here, we use the Find function to look for the term “iCloud”. The full information for any system log is revealed in the Full Fields Content view.

RECENTS DATABASE PARSING (IOS 6 & NEWER/OS X 10.10 & NEWER)
BlackLight shows the “Recents” information that iOS and OS X capture within its databases. The information is revealed in BlackLight’s Mail, Messages, Contacts and Location Views. Some of the more interesting items are recently e-mailed addresses (including ones that are not recorded in the “Contacts” app). In the “Contacts” and Recents” tables are contact points that can be lined up with the “Recents” table to see when the last 5 communications were between individuals and groups. The metadata table contains metadata from recent communications as well. Here we see the “Recents” information, as seen within an iPhone’s messages.

Depending on which data type is being reviewed, BlackLight’s existing ability to reveal “deleted” records in sqlite databases can show information that no longer exists within the database’s active records.

IOS 10 ENCRYPTED BACKUP SUPPORT
Apple has changed the method in which they protect the iOS backups with iOS 10 and iOS 10.1. BlackLight handles both of these methods but you must know the users password in order to decrypt. It is important to note that AFC is no longer available with iOS 9 and 10 and the only way to get data from the device is by forcing a backup through BlackLight or using iTunes.

NEW DATA STRUCTURE TEMPLATES
BlackBag is supplying templates for parsing MFT records, HFS Catalog records, partition tables, boot sectors, and various files types. Templates for ZIP, TAR, BMP, JPG, GIF, PNG, AVI, MP4, and LNK files are included. As an example, when a zip archive is located, the Data Structure view shows each file that is a part of the archive, as well as the file system date associated with each file. With the file of interest highlighted in the Browser view, we go to the Hex view and select Data Structure.

In this example, a zip archive was created from several pictures. As shown, the Data Structure view provides the file name of each file, date and time attributes, and additional information about each file contained in the zip. When a particular field is highlighted, its corresponding information in both the Hex and ASCII windows are highlighted so they can easily be located by the examiner. Similarly, if the user selects data in Hex, the corresponding Data Structure item will be highlighted.

Learn more information about the new features by attending our webinar on December 14th at 9am PST.

About the Company

BlackBag Technologies is a developer of innovative forensic acquisition, triage, and analysis software for Windows, Android, iPhone/iPad, and Mac OS X devices. The company’s flagship product, BlackLight, has been adopted worldwide by many digital forensics examiners as a primary analysis tool. Mobilyze, BlackBag’s groundbreaking mobile device triage tool, empowers virtually all law enforcement personnel, with or without specialized experience, to capably triage and report on data from smartphones.

In addition to software, BlackBag also develops and delivers expert forensic training and certification programs, designed to meet the needs of law enforcement, military and private sector examiners. Taught by an elite team with considerable law enforcement and digital forensics experience, the courses are tailored to address realistic, multi-platform scenarios simulating the daily challenges of digital evidence.

To learn more about BlackBag®’s software and training, please contact us at 855-844-8890, or visit us at blackbagtech.com.

Leave a Comment

Latest Videos

In this episode of the Forensic Focus podcast, Desi and Si discuss different online programming courses and what they think about the popular platform, Udemy. They also talk about Flipper, Dev boards, and Raspberry Pi, and delve into the fascinating phenomenon of running the classic game Doom on unlikely devices.

Throughout the episode, Desi and Si share their digital forensics expertise, referencing some of the cases they have been working on and highlighting particular methodologies and technologies that have an impact on cybersecurity.

Show Notes:

100 Days of Code: The Complete Python Pro Bootcamp for 2023 - https://www.udemy.com/course/100-days-of-code/

Domestika - https://www.domestika.org/en

MIT OpenCourseWare - https://www.youtube.com/@mitocw 

MasterClass - https://www.masterclass.com/

Raspberry Pi 400 Complete Kit - https://core-electronics.com.au/raspberry-pi-400-kit.html

Flipper Discord - https://discord.com/invite/flipper

Flipper Zero - https://flipperzero.one/

This Programmer Figured Out How to Play Doom on a Pregnancy Test - https://www.popularmechanics.com/science/a33957256/this-programmer-figured-out-how-to-play-doom-on-a-pregnancy-test/

Here’s a dude playing Doom Eternal on his fridge - https://www.polygon.com/2020/10/13/21514933/doom-eternal-refrigerator-door-samsung-smart-refrigerator-xbox-game-pass-richard-mallard

Doom hacker gets Doom running in Doom - https://www.pcgamer.com/doom-hacker-gets-doom-running-in-doom/

Doom Running On A Calculator Powered By Old Potatoes - https://kotaku.com/doom-running-on-a-calculator-powered-by-old-potatoes-1845374069

GoldenEra - https://www.imdb.com/title/tt11753760/

Racing the Beam - https://en.wikipedia.org/wiki/Racing_the_Beam

High Score (TV series) - https://en.wikipedia.org/wiki/High_Score_(TV_series)

Microcontroller Courses (Udemy) - https://www.udemy.com/topic/microcontroller/

The story of Final Fantasy XIV’s renegade do-good modders - https://www.pcgamesn.com/final-fantasy-xiv/ffxiv-modders-renegade-do-gooders

Logical fallacies - https://yourlogicalfallacyis.com/

In this episode of the Forensic Focus podcast, Desi and Si discuss different online programming courses and what they think about the popular platform, Udemy. They also talk about Flipper, Dev boards, and Raspberry Pi, and delve into the fascinating phenomenon of running the classic game Doom on unlikely devices.

Throughout the episode, Desi and Si share their digital forensics expertise, referencing some of the cases they have been working on and highlighting particular methodologies and technologies that have an impact on cybersecurity.

Show Notes:

100 Days of Code: The Complete Python Pro Bootcamp for 2023 - https://www.udemy.com/course/100-days-of-code/

Domestika - https://www.domestika.org/en

MIT OpenCourseWare - https://www.youtube.com/@mitocw

MasterClass - https://www.masterclass.com/

Raspberry Pi 400 Complete Kit - https://core-electronics.com.au/raspberry-pi-400-kit.html

Flipper Discord - https://discord.com/invite/flipper

Flipper Zero - https://flipperzero.one/

This Programmer Figured Out How to Play Doom on a Pregnancy Test - https://www.popularmechanics.com/science/a33957256/this-programmer-figured-out-how-to-play-doom-on-a-pregnancy-test/

Here’s a dude playing Doom Eternal on his fridge - https://www.polygon.com/2020/10/13/21514933/doom-eternal-refrigerator-door-samsung-smart-refrigerator-xbox-game-pass-richard-mallard

Doom hacker gets Doom running in Doom - https://www.pcgamer.com/doom-hacker-gets-doom-running-in-doom/

Doom Running On A Calculator Powered By Old Potatoes - https://kotaku.com/doom-running-on-a-calculator-powered-by-old-potatoes-1845374069

GoldenEra - https://www.imdb.com/title/tt11753760/

Racing the Beam - https://en.wikipedia.org/wiki/Racing_the_Beam

High Score (TV series) - https://en.wikipedia.org/wiki/High_Score_(TV_series)

Microcontroller Courses (Udemy) - https://www.udemy.com/topic/microcontroller/

The story of Final Fantasy XIV’s renegade do-good modders - https://www.pcgamesn.com/final-fantasy-xiv/ffxiv-modders-renegade-do-gooders

Logical fallacies - https://yourlogicalfallacyis.com/

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_5f72B6DD5wk

Programming Languages, Flipper And Gaming

Forensic Focus 24th May 2023 11:43 am

In this episode of the Forensic Focus podcast, Si and Desi talk to Mackenzie Jackson, Developer Advocate at Git Guardian. 

Mackenzie discusses the problem of hard-coded and leaked credentials in Git repositories, the task of scanning Git repositories for leaked credentials, and how that’s helped by the setup of GitHub and Git. 

He also looks at some public and private cases of security breaches through Git repositories and recommends tools you can use to combat attackers on Git. 

Show Notes:

Toyota Suffered a Data Breach by Accidentally Exposing A Secret Key Publicly On GitHub (GitGuardian) - https://blog.gitguardian.com/toyota-accidently-exposed-a-secret-key-publicly-on-github-for-five-years/

GitHub.com rotates its exposed private SSH key (Bleeping Computer) - https://www.bleepingcomputer.com/news/security/githubcom-rotates-its-exposed-private-ssh-key/

Conpago - https://www.conpago.com.au/

Source Code as a Vulnerability - A Deep Dive into the Real Security Threats From the Twitch Leak (GitGuardian) - https://blog.gitguardian.com/security-threats-from-the-twitch-leak/

Teenagers Leveraging Insider Threats: Lapsus$ Hacker Group (Forbes) - https://www.forbes.com/sites/emilsayegh/2023/03/15/teenagers-leveraging-insider-threats-lapsus-hacker-group

Lapsus$: Oxford teen accused of being multi-millionaire cyber-criminal (BBC) - https://www.bbc.co.uk/news/technology-60864283

Dynamic Secrets (HashiCorp) - https://developer.hashicorp.com/vault/tutorials/getting-started/getting-started-dynamic-secrets

Crappy code, crappy Copilot. GitHub Copilot is writing vulnerable code and it could be your fault (GitGuardian) - https://blog.gitguardian.com/crappy-code-crappy-copilot/

trufflesecurity/trufflehog (GitHub) - https://github.com/trufflesecurity/trufflehog

gitleaks/gitleaks (GitHub) - https://github.com/gitleaks/gitleaks

Git (Wikipedia) - https://en.wikipedia.org/wiki/Git

awslabs/git-secrets (GitHub) - https://github.com/awslabs/git-secrets

In this episode of the Forensic Focus podcast, Si and Desi talk to Mackenzie Jackson, Developer Advocate at Git Guardian.

Mackenzie discusses the problem of hard-coded and leaked credentials in Git repositories, the task of scanning Git repositories for leaked credentials, and how that’s helped by the setup of GitHub and Git.

He also looks at some public and private cases of security breaches through Git repositories and recommends tools you can use to combat attackers on Git.

Show Notes:

Toyota Suffered a Data Breach by Accidentally Exposing A Secret Key Publicly On GitHub (GitGuardian) - https://blog.gitguardian.com/toyota-accidently-exposed-a-secret-key-publicly-on-github-for-five-years/

GitHub.com rotates its exposed private SSH key (Bleeping Computer) - https://www.bleepingcomputer.com/news/security/githubcom-rotates-its-exposed-private-ssh-key/

Conpago - https://www.conpago.com.au/

Source Code as a Vulnerability - A Deep Dive into the Real Security Threats From the Twitch Leak (GitGuardian) - https://blog.gitguardian.com/security-threats-from-the-twitch-leak/

Teenagers Leveraging Insider Threats: Lapsus$ Hacker Group (Forbes) - https://www.forbes.com/sites/emilsayegh/2023/03/15/teenagers-leveraging-insider-threats-lapsus-hacker-group

Lapsus$: Oxford teen accused of being multi-millionaire cyber-criminal (BBC) - https://www.bbc.co.uk/news/technology-60864283

Dynamic Secrets (HashiCorp) - https://developer.hashicorp.com/vault/tutorials/getting-started/getting-started-dynamic-secrets

Crappy code, crappy Copilot. GitHub Copilot is writing vulnerable code and it could be your fault (GitGuardian) - https://blog.gitguardian.com/crappy-code-crappy-copilot/

trufflesecurity/trufflehog (GitHub) - https://github.com/trufflesecurity/trufflehog

gitleaks/gitleaks (GitHub) - https://github.com/gitleaks/gitleaks

Git (Wikipedia) - https://en.wikipedia.org/wiki/Git

awslabs/git-secrets (GitHub) - https://github.com/awslabs/git-secrets

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_BX15Z_xF8mA

Preventing Data Leaks With Git Guardian

Forensic Focus 3rd May 2023 11:07 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...