Collecting Evidence From Google Accounts Gets Easier

ElcomSoft Co. Ltd. updates Elcomsoft Cloud eXplorer, a digital forensic tool for remotely acquiring information from Google accounts. In its first major update, the tool gains Gmail acquisition support via Google’s proprietary API, adds printable reports for a wide range of data categories, and extracts information on who requested access to the Google account being investigated.

Elcomsoft Cloud Explorer is an all-in-one solution for acquiring and analyzing information collected and stored by Google in the user’s Google Account. The tool offers forensic specialists access to users’ search history, up to 6 years of detailed location history, contacts, email communications, Chrome browsing history, notes, messages, and much more. Featuring selective access and blazing fast acquisition, Elcomsoft Cloud Explorer is world’s most advanced tool for Google forensics.[image]

“We’re working on making Elcomsoft Cloud Explorer a one-stop tool for investigating Google accounts”, says Vladimir Katalov, ElcomSoft CEO. “It’s hard to underestimate just how much Google knows about its users. We offer forensic specialists a single point of access to data that’s normally scattered around the many Google servers with unique APIs and data formats. With Gmail support and comprehensive reporting, Cloud Explorer gets one step closer to becoming truly irreplaceable for digital investigations.”

Background: What Google Knows About Its Users

Google is a dominant force in many areas. The search market, the Android platform, Google Photos, mail and cloud storage services are just a few to mention. Each and every service provided by Google contributes to Google’s insight about the users, collecting their current location and IP address, storing their search requests and taking a note on Web sites they visit via Google Chrome.

Google knows which search results are opened even if a third-party Web browser was used to fire a Google search. Android smartphones routinely report the user’s location to Google servers. Email messages, contacts, calendar events and a lot more data is synced via the user’s Google Account.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Most of this data can be extracted from Google servers. However, the information is provided in a wide range of data formats, and accessible via a number of different APIs. Acquiring Google data with bare hands is a lengthy and labour-consuming procedure. Elcomsoft Cloud Explorer was designed specifically to make it easy to acquire, view and analyze information stored in Google Accounts.

Gmail Acquisition and Analysis

Elcomsoft Cloud Explorer 1.10 offers investigators the convenience of fast Gmail acquisition and detailed analysis. The tool can download all or some email messages from the user’s Gmail account, allowing investigators specifying the exact period to acquire. Access to messages is implemented via Google’s proprietary Gmail API, which makes it possible to achieve unprecedented acquisition speed of about 3000 email messages per minute (subject to message size and connection speed). Putting things into perspective, this is approximately 5 times faster than Google Takeout, and about 3 times faster compared to a commercial IMAP client on the same Internet connection. Selective access to messages during the acquisition stage and unbeatable acquisition speed make Elcomsoft Cloud Explorer one of the fastest Gmail analytic toolkits on the market.

The built-in Gmail analyzer offers detailed searching and filtering through all downloaded messages, and provides valuable insight about downloaded messages. Thanks to the use of Google’s Gmail API instead of the commonly available POP3 or IMAP protocols allows the tool to distinguish between Read, Unread and Archived messages, recognize Gmail categories, labels, folders and conversation threads. Users can automatically filter messages that contain media attachments such as pictures, videos or documents. Complete message threads are instantly available as investigators search or browse through downloaded mail.

HTML Reporting

Version 1.10 adds a number of HTML reports, including User Infо, History, Chrome, Dashboard, Media, Locations, Calendars, Notes, Chats, Google Keep, and Contacts. Gmail reports are planned for the next release. HTML reports can be easily printed or viewed in any Web browser.

About Elcomsoft Cloud Explorer

Elcomsoft Cloud Explorer makes it easier to download, view and analyze information collected by the search giant, providing convenient access to users’ search and browsing history, Gmail messages and contacts, detailed location history going back up to 6 years, Google Keep notes, Hangouts messages, as well as images stored in the user’s Google Photos account. Google collects massive amounts of information from registered customers. Elcomsoft Cloud Explorer extracts information from the many available sources, parses and assembles the data, presenting information in human-readable form.

System Requirements

Supports Windows Vista, Windows 7, 8, 8.1, and 10, as well as Windows 2003, 2008 and 2012 Server.

Pricing and Availability

Elcomsoft Cloud Explorer is immediately available. North American pricing starts from $1995. Local pricing may vary. Elcomsoft Cloud Explorer is available stand-alone or as part of Elcomsoft Mobile Forensic Bundle ($2995), which includes a comprehensive range of mobile acquisition and analysis tools for devices running Apple iOS, BlackBerry 10, Windows Phone and Windows 10 Mobile.

About ElcomSoft Co. Ltd.

Founded in 1990, ElcomSoft Co. Ltd. develops state-of-the-art computer forensics tools, provides computer forensics training and computer evidence consulting services. Since 1997, ElcomSoft has been providing support to businesses, law enforcement, military, and intelligence agencies. ElcomSoft tools are used by most of the Fortune 500 corporations, multiple branches of the military all over the world, foreign governments, and all major accounting firms. ElcomSoft is a Microsoft Partner (Gold Application Development), Intel Premier Elite Partner and member of NVIDIA’s CUDA/GPU Computing Registered Developer Program.

Leave a Comment

Latest Videos

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification 

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_VKk-mhlae1c

Becoming An Amped FIVE Certified Examiner (AFCE)

Forensic Focus 1st December 2023 4:25 pm

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data. 

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data.

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_4z-EgH54KZk

The Power Of Digital Forensics: How ADF Solutions Is Revolutionizing The Digital Forensics Industry

Forensic Focus 30th November 2023 2:57 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles