BlackLight 2017 R 1.1 Is Now Available

We are pleased to announce an update for BlackLight is now available. Following the major 2017 release of BlackLight in November, the latest release includes enhancements and fixes, such as:

– Added new High Sierra FSEvents ‘inode’ reference number to ‘System Logs’ view
– Support for Windows 10 Fall Creators Update (Version 1709) memory images
– Enhanced Volume Shadow Copy (VSC) display
– EWMounter support for Mac OS 10.13 and the ability to mount images with a 4096 block size

Learn more about the latest BlackLight release.

New Feature Highlights

Updated Parsing For FSEvent Files

BlackLight 2017 R1.1 can now parse out the unique identifier, or ‘inode’ number, for the item that the FSEvent record refers to, which is present in High Sierra (10.13). By adding this reference number identification field, examiners can track a file or folder through moves and name changes. A new ‘inode’ column is displayed in the ‘System’ category ‘System Logs’ view and the examiner can sort, hide/show and filter on this column. In addition, the ‘inode’ number is listed in the Tag container and displayed in the report for tagged FSEvents items when generated by users.

Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.

Unsubscribe any time. We respect your privacy - read our privacy policy.

Windows 10 Fall Creators Update

Here at BlackBag, supporting our customers in the field with the ongoing challenge of new operating systems and updates to versions is a top priority. BlackLight 2017 R1.1 supports the Windows 10 Fall Creators Update and ensures that the significant changes to this new version of Windows do not affect our customers’ ability to process memory images from this operating system.

Improved Volume Shadow Copy (VSC) Display

BlackLight 2017 R1.1 provides an improved Volume Shadow Copy display. The enhanced display allows an examiner the ability to identify the file history more easily.

If the examiner chooses to process Volume Shadow Copies, a new top level aggregate partition is displayed in BlackLight 2017 R1.1 under Evidence. This can be expanded to show or hide the individual volume shadow copies. When the top-level ‘Active & VSCs’ partition is selected, all active files and all processed VSC files can be examined. Alternatively, an examiner could select just the active files partition to show only the active (current) files, or select an individual Volume Shadow Copy to show only the files for that specific VSC instance.

EWMounter Additional Drive Support

To assist with examining Apple’s new file system (APFS), EWMounter v1.9 (included with BlackLight 2017 R1.1 Mac version) is supported on High Sierra 10.13 with enhanced features. EWMounterv1.9 allows examiners to select the appropriate block sizes, which includes mounting images with a 4096 block size from newer Mac computers on High Sierra. EWMounter v1.9 can also assist with mounting images for unlocking FileVault 2 and merging Fusion drives.

Learn more about BlackLight

To learn more about BlackLight, including more about these features, check out our comprehensive training options; including free, self-paced or in-depth courses at Our Instructors have years of law enforcement and digital forensics experience and actively support investigators in the field.

Get your free fully-functional demo license today!

Leave a Comment

Latest Videos

Digital Forensics News Round-Up, May 22 2024 #dfir #computerforensics

Forensic Focus 22nd May 2024 6:03 pm

Podcast Ep. 85 Recap: AI-Powered License Plate Reading With Amped DeepPlate #dfir #digitalforensics

Forensic Focus 21st May 2024 1:57 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feeds settings page to add an API key after following these instructions.

Latest Articles