Practical AI In Digital Forensics: Running Offline AI On Your Own Evidence With BelkaGPT

The following transcript was generated by AI and may contain inaccuracies.

Intro: Welcome to Belkasoft’s webinar on practical AI in digital forensics and incident response. Today, Belkasoft CEO Yuri Gubanov will walk you through how AI helps investigators manage overwhelming data volumes, and how Belkasoft tools let you bring AI into your workflow securely and efficiently.

Yuri Gubanov: …charts and documents and emails — that’s a huge pile of text-based information in your case. Reviewing large volumes of pictures, photos, videos and audio is also a big bottleneck. At the same time, most labs are working with limited staff and limited software licenses.

Wherever I go, I hear that we don’t have enough of anything: enough staff, enough software licenses, enough hardware. That’s a typical complaint. When a big case comes in it’s always a problem, and the backlogs are always growing.

I’ve witnessed it in multiple countries, in many different laboratories, whether it’s a country in Asia or a continent like America. Even here in Portugal, I visited one of the law enforcement laboratories and they showed me some hard drives that had been waiting two years before even being initially touched by a digital forensic investigator.


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Two years is quite a lot, right? And after that, they still have to spend significant time analysing the contents, because a one terabyte drive is no surprise these days. In my home I have three drives, and the biggest one is 10 terabytes, so in total I have a capacity of 17 terabytes, which is huge. Imagine analysing everything on that kind of computer — it would take weeks, I believe.

So how can AI help with all of that? Let’s start with picture analysis. AI can assist you with one of the heaviest analysis types in investigations, because devices can contain thousands of photos, or even hundreds of thousands of photos. In my case, I store every picture I’ve ever taken.

Even on a mobile device — even on a new mobile device — you can easily find lots of photos, because a device can inherit a photo library from a previous device by restoring a backup or using a device transfer when someone buys a new phone. It’s not a surprise to see thousands or tens of thousands of photos taken years ago on a brand new device.

Manually reviewing these pictures is slow and costly, because every second costs you something. AI-powered image classification can do a lot automatically. It can sort content by categories — it can flag weapons and drugs, it can find scanned documents or explicit material without you even having to open a file.

Facial recognition can also help. For example, if you need to find who was present at a certain location, who appeared across different devices, or whether a face matches a known individual, AI can help you a lot here. We actually had this AI picture analysis even before the large language model boom. But nowadays, when LLMs are multimodal — when they can process not just text but also pictures and videos — the accuracy has risen a lot. Using LLMs for picture and video analysis works with much greater precision.

There’s also audio analysis. You know that now people, especially younger people, tend to send more voice messages than before. The parents here can confirm that the younger generation uses voice messages far more. But there are also recorded calls and video files with spoken content, and analysing the entirety of the audio content on a typical device is very time-consuming if you do it one by one, manually.

Automatic speech recognition can help you by converting audio into searchable, reviewable text. An investigator no longer has to listen to hours of recordings. Instead, they can run the automated analysis and have the audio fully converted to text that you can search and filter, and that you can use with technologies like BelkaGPT, which I’ll cover today as well.

Speaking about BelkaGPT and LLMs in general — you know that LLMs have gone from being just a research topic, or just a toy, to something that hundreds of millions of people use every day. I use a few AI services every day. I think I run dozens of queries across hundreds of topics every month.

I run deep research every few days, so I use them as a personal assistant and as a helper in my work. I generate pictures for some of Belkasoft’s posts on social networks, for example. By the way, it would be interesting to know how you use AI. If you put into the chat which particular AI services you use and what for, that would be interesting to see.

And if you use AI for digital forensics or cyber incident response, please put your ideas about how to effectively use online services — and offline services as well — into the chat window of this webinar.

What’s great about those models is that you can ask them a question the same way you’d ask a colleague. For example: show me messages where financial transactions are discussed, or, did the device owner search for chemical compounds? The LLMs and the newer models understand what you’re looking for. They don’t require you to know the exact wording, or the exact application where the content lives.

They’ll forgive you typos. They know synonyms, and they’ll find the relevant information even if you made a mistake, or if the answer is hidden behind slang or synonyms of what you’re looking for. If you work with complex cases like financial fraud, organised crime or corporate misconduct, that’s not just a convenience. It’s like having another pair of hands in your lab, at basically no cost.

However, it’s not all ponies and rainbows. There are a number of challenges. The biggest one that I constantly hear from investigators and corporate security teams is: we want efficient AI, but we cannot use any public AI solutions. And of course that’s a completely legitimate expectation.

Most AI tools on the market are cloud dependent. They send your data to a remote service, and you have no control over where it goes — whether your data is sent to California, or to some island in the Pacific Ocean where the data centre sits.

In standard commercial and personal use, that can be acceptable. However, in digital forensics, and in many cyber incident response cases, you simply cannot do that. You work with evidence that stores confidential data. You work under strict legal and procedural obligations. In many countries you are legally obliged to work on a disconnected machine.

Sending case materials to a third party is not just a policy risk. In many jurisdictions it can compromise the integrity of the investigation entirely — your evidence will be invalidated in court if you worked from a connected computer.

So the question now is not whether to adopt AI, because the efficiency gains are too significant to ignore. The question is how to adopt AI without creating new risks and new vulnerabilities in the process. Public cloud AI is not an option.

Another idea I frequently hear when I present on this topic is people asking me: “Okay, Yuri, what would you recommend as an offline LLM for us to build a system from scratch? How many parameters? What goes here? What goes there? How do we tune this and that?” The idea is to build and run AI themselves.

Yes, local deployment options exist. You can run open source models on your own infrastructure. You can use frameworks like Model Context Protocol, MCP, to let your AI models know about your local data sources, and this will be a thought line, right? It can work. However, it has its own complications.

First, configuring a local AI deployment requires expertise that forensic labs don’t have, and don’t actually need to have: model selection, various kinds of precision testing, accuracy testing, hardware setup, context configuration, and keeping current, because models evolve and different parts of the pipeline evolve.

You can replace one part and it’s not going to be compatible with the previous version of another part, and so on and so forth. You’ll need to maintain this whole zoo of different technologies. It often means custom code that you write to connect those pieces together.

And finally, your tools are not necessarily aware of what you’re doing with AI. Forensic tools were not designed with AI in mind. They may have limited APIs, rigid data models, or no programmatic interface at all. You’ll need to somehow connect your forensic tool and your external AI, which means doing exports and imports. Again, whenever the forensic tool updates, or the AI part is updated, incompatibility arises and you have to tune it all again and again.

That’s overhead which distracts you from your real work, which is investigation. Instead of saving time, you start losing time. So what’s the point?

My last point here is that do-it-yourself AI will be general purpose. You take llama.cpp, or Gemma, or whatever popular model you select, but it doesn’t necessarily know anything about your workflow. It has all the drawbacks that online models have. It tends to hallucinate. It can’t say that it didn’t find anything when you ask about a specific topic — it wants to please you instead of giving you the truth, and so on.

I think that for digital forensics we need a domain-specific AI developed specifically for digital forensics, and this is where we have BelkaGPT.

BelkaGPT is our offline AI assistant, built right inside our main product, Belkasoft X. Belkasoft has spent over 15 years serving the digital forensic community, so we know the requirements and the constraints of our customers. When we started designing BelkaGPT, we shaped it around the workflows and requirements that investigators face every day.

So what can BelkaGPT do for you? Let’s start with picture analysis. BelkaGPT can describe and classify pictures automatically. You can use built-in classifiers like weapons, tattoos or money, or you can create your own case-specific, workflow-specific or organisation-specific categories.

It’s as easy as giving the technology a few words about what you’re looking for, and it works surprisingly well — classifying pictures based on just four or five words that you give in your own language. It doesn’t necessarily have to be English.

For audio and video, it can run automatic speech recognition and convert speech to text. Again, you can do traditional keyword search, and you can use the BelkaGPT window for chatting about the content of those audio and video files.

An interesting new feature built into the most recent version of Belkasoft X is chat topic detection. The product can detect topics of interest across all the chat data, and also across emails and documents. As with pictures, you can define your own custom classifier for topics to be found in chats.

Across all of it, BelkaGPT provides a natural language interface where you can ask questions about your case data directly, and you get answers based on your case data. All the answers have references to your case artifacts — they’re not just taken out of thin air. That’s one of the tricks we use to help the technology avoid hallucinating.

This talk isn’t really about the features of BelkaGPT, because I have another webinar for that — you can request a recording of that webinar from [email protected]. But I will show you some exciting examples of what the technology can help with, and explain a few interesting points.

For example, on this screen you can see that I’m asking for pictures of a male sitting in a car. The product found one picture — this one. If you click this button it will navigate you to another window called Artifacts, where you can see the pictures, and this man will be selected. Notice the green box around his face, because the face was detected in this picture. The answer says: yes, there is a picture of a male sitting in a car.

But it’s also interesting that it says no other pictures were found, while still giving you two more references. Why? Because the second image shows a Mercedes with a driver, but it’s not quite clear what the gender of the driver is. It also gives me a third reference showing a Porsche 718 Cayman GT4 RS Clubsport Edition.

I have no idea how to distinguish these kinds of Caymans, but it’s incredibly interesting that the technology gives you the exact model of the car in the picture. It also says that the gender of the driver is not specified.

I’d bet that a general purpose technology would say that these pictures really do have what you’re looking for. But since we try to avoid made-up answers, we taught the technology to give you negative replies as well. So it says that there is nothing else found. The technology is taught to give you at least three references to the case, so it gave you some additional ones, but it highlights that they aren’t actually an answer to your question.

You’re then going to review those images manually and see whether there is indeed a male sitting in a car, or a female, or a robot. That’s an important difference between BelkaGPT and a general purpose AI.

Another interesting search is here. I’m looking for pictures of minors near water bodies. The technology found me two pictures: a girl by the sea, and a boy by a river or a pond — it’s not quite clear which. Again, looking for this kind of evidence manually would be quite time-consuming, and I’m able to do it with just one question in the BelkaGPT window.

In my third example, I’m asking about discussions about storage locations. The third item in the answer is an audio file. It’s interesting that the technology can refer not just to text or pictures, but also to audio and video files. When I click on this file, I see that it’s transcribed, and it’s not in English — it’s in the Portuguese language.

And there’s a translation. It says: “A new place to store the goods.” A few AI features are involved here. It’s not just that the audio was transcribed, but that it was somehow translated to English. The meaning was extracted, and finally this audio file was considered and found as a suitable reference in the case to your question about storage locations. So a couple of different AI facets are highlighted here, and the result looks fantastic.

Now, how does this actually work from beginning to end? It all starts with artifact extraction. Belkasoft X can acquire data directly from devices and from the cloud — computers, mobiles, tablets, desktops, laptops, even drones and even cars.

Belkasoft is not just about AI. We have a fully fledged, all-in-one digital forensic suite that can analyse devices without any AI involved at all. It’s also important to highlight that you’re not bound to Belkasoft to do your acquisitions. Belkasoft X and BelkaGPT both support extractions from popular forensic tools, including UFED, UFD images, UFDRs, Magnet, GrayKey, Grayshift, EnCase, and many more.

Once artifacts are extracted from a Belkasoft image or a third-party image, Belkasoft parses a wide range of evidence formats. You can see different data such as browsers, calls, chats, documents, system files and so on.

The technology then takes audio, pictures, videos and text-based information and analyses it. It doesn’t just build the index for regular keyword search, it also processes the data into an AI-readable knowledge base that BelkaGPT will then use to build the replies. All the audio is converted to text. Descriptions and classifications are generated for images and videos. All the knowledge is transformed into a form that AI can query in order to build a reply in natural language.

Now you may ask how long this will take. AI calculations are quite time-consuming, so the question is whether we’re delaying the investigation or speeding it up, because the AI requires quite a few calculations for every single artifact. This is where BelkaGPT Hub makes a difference.

But before we go to BelkaGPT Hub, let me review the requirements for BelkaGPT running locally. First of all, it works on both CPU and GPU. Of course, GPU is way faster — we see performance gains as big as 60 times faster than a CPU, and even bigger for modern and more powerful GPU units. But it can still work on CPU if you have to use CPUs.

For example, when I travel to conferences and to customers, I have a laptop with me which weighs slightly over one kilogram. You can guess that it’s not very powerful — it has an i5 processor inside and just 16 gigs of RAM. But the technology still works inside that box. It’s painfully slow, but it works. Of course, your investigative machine is much better and much more powerful, so it will work better even on a CPU-only computer in your lab. It’s important for us to keep this compatibility with CPU-only machines.

Now, what is BelkaGPT Hub? BelkaGPT Hub is a software infrastructure layer that lets labs share GPU resources across forensic workstations. It offloads BelkaGPT processing tasks from individual desktops to more powerful servers or workstations that are equipped with GPUs and sitting on the same local network.

This way you keep the entire infrastructure manageable, you cut hardware costs, and security stays intact, because everything is still running in your hands, on your infrastructure, completely offline. Nothing goes outside. It’s local network only.

It’s pretty straightforward to enable BelkaGPT Hub in Belkasoft X. Once you run the tool, you go to Settings and navigate to the BelkaGPT tab. Here you have just two options: run BelkaGPT fully locally, or run it on a BelkaGPT Hub. If you decide to use a hub, you just specify the hub location.

It can be either an IP address on your local network, or the name of the computer. You also complement it with a port, which you select during the installation of the hub.

The hub infrastructure has three components. Belkasoft X clients, on the left of my picture, can be any computer on your local network, whether it’s a desktop, a laptop or a mini computer. In the middle of the picture you see the hub itself, and on the right you can see BelkaGPT workers.

Once the clients extract artifacts from the case, instead of processing them locally for AI they send the processing tasks to the hub. The hub receives this information, queues the processing tasks, and assigns workers to those tasks on a first in, first out basis. Workers handle the processing and return the results back to the hub, which delivers them back to the investigator’s workstation.

Once it completes, all those results — picture descriptions, classifications, detected faces, audio transcripts and so on — go back to your investigative computer, and you can ask Belkasoft X in natural language about what you have in the case. So the compute for AI happened somewhere else, not on your computer.

Meanwhile, the processing power of your computer wasn’t used, so you can use the computer for something else. You can continue working with Belkasoft X. Just avoid asking BelkaGPT anything, because the processing isn’t yet complete. But you can do searches, you can do exports, you can investigate the data in some of the other viewers we have in the product, and so on. You’re not blocked from working on the case while the data is being processed on the hub.

Let’s look at what each component actually requires. The hub itself is lightweight. It’s just middleware — it routes tasks between clients and workers, between the Belkasoft X instances and the GPU workers. It can run on almost any machine on your network. It doesn’t need dedicated hardware, so you don’t need to spend money on the hub.

Workers are where the processing actually happens. You can install a worker on a single machine, or spread workers across several computers: on dedicated servers, on GPU-enabled workstations, or even on a CPU-only computer that can also participate and give its resources towards the AI calculations.

To repeat: CPUs are supported, but of course GPU makes a real difference — tens or hundreds of times faster, depending on the hardware you have. The minimum GPU hardware requirements are the same as for a standalone BelkaGPT installation, so it must be a CUDA-compatible GPU with at least 12 gigs of VRAM.

The more the better, of course, and we support up to eight GPUs per machine. All eight can be used. That’s an option — you can use just one, you can use two, you can use eight. It’s all configurable. If your budget allows, we always recommend going for more VRAM, and if you’re comparing GPUs that cost the same amount of money, look for newer ones and for products with a larger number of tensor cores.

Here is my home installation, which is very affordable and which you could start with. That’s what I installed in my home office. Since I already have a very good development desktop in my office, but it doesn’t have a GPU and I don’t want to extend it to have a GPU inside, I bought an Intel NUC mini computer, which is a pretty small box that sits below my monitor.

The central piece in my configuration is a Gigabyte GeForce RTX 5060 with 16 gigs of VRAM. I think that’s the most expensive item in the overall configuration. Since I have a mini computer and of course I can’t install this card inside it — it’s twice as big as the NUC box — I needed an enclosure to give it power and some extra ventilation. So I bought the Sonnet eGPU Breakaway Box, which is a pretty nice device.

It’s trouble-free. I think I spent just 10 minutes installing the card. You open the box, install the card, connect it with a wire, and then connect the box to the mini computer with a Thunderbolt cable. That’s it. No drivers, nothing. Windows immediately sees the GPU, and the BelkaGPT worker also saw the GPU pretty quickly once I’d set everything up.

By the way, this box died yesterday, of course, while I was preparing today’s presentation. I’m not sure whether that’s the fault of the box, or whether there was a power cut in my electricity supply here. So I can’t say that it’s very robust. Make sure you have it behind a good UPS, because I witnessed myself that it possibly can’t tolerate jumps in your electricity. But apart from that, it’s very convenient and easy to install.

At the bottom there is a KVM switch, which I use to switch between computers. It’s convenient because it’s dual monitor, so I use both my monitors regardless of which computer I’m looking at.

This configuration cost me less than 1,500 euro — I think it was something like 1,200. So it’s very affordable, and I believe it’s affordable to an organisational buyer as well. And this configuration gives me 200 times better performance than the same computer without the Gigabyte GPU card, so it’s pretty productive. That’s the box behind my monitor — it occupies some space, but not too much.

Now, how do I install the whole infrastructure, software-wise? First, there’s a single installer for both the hub and the BelkaGPT worker. In most cases you’ll start — at least with your trial, or your first installation of BelkaGPT Hub — with the hub and the worker on the same computer. That’s why we have a first option to install both hub and worker together.

You also have two other options: installing just the hub, or installing just the BelkaGPT worker on the computer. If the hub is already found and installed, the installer will ask whether you want to update, so that’s going to be an update of the hub.

I already have the hub installed, so I’m only installing the worker, but I’m doing this on the same computer. I click Next, I specify the path, and here on this screen I let the worker know where the hub is installed. In my case it’s going to be the same computer, but if I were installing the worker on another computer I’d need to specify where the hub lives. That’s either an internal IP address or the computer name, and again, the port is required.

I select this computer, and it says that something is blocked. That’s because I have a worker already running on this computer — the previous version. I need to close the worker. In this version, the worker is a console application. This helps you to debug if you have any issues with the installation.

In the next version we’ll wrap it into a service, so it’s going to be easier to reinstall — we won’t ask you to close it, everything will be automatic. But the console version has its own benefits, because it’s easy to see what went wrong if any issue arises.

Once I close the worker, everything completes successfully, and on the last screen I run the worker. That’s a console application. What I see here is: “CUDA compatible GPU isn’t found, running on CPU.” That’s not what we wanted, right? We wanted to use my very good GPU card.

What happened here is that on my second computer I did the CUDA installation into some environments for Visual Studio Code and inside Anaconda, so it’s not visible to my worker.

Also, a frequent problem met by our customers is that they want to install the very latest version of CUDA, which is not necessarily the best. Belkasoft works with version 12 of CUDA. If you install version 13 it will not be visible, unfortunately. So what we do is go to developer.nvidia.com. We go to the 12 series of the CUDA toolkit. We haven’t yet tested 12.9.2, so I’m installing 12.9.1. Select every requested option here: what is the operating system, what is the version, what is the installer type, and so on.

Okay, downloading the executable file. And running it once the download completes.

Once it’s unpacked and run, it will show you this kind of interface. It does some system checks. You agree to the agreement. Express installation is fine. You just disregard the Visual Studio warning — you don’t need it for BelkaGPT Hub. And you wait until the NVIDIA installer completes. On the finish page you don’t need to launch anything; whatever you’ve installed already is enough.

Now I rerun the worker. And now it says that it’s started, and it doesn’t say that a GPU wasn’t found. So it’s actually running on GPU now, which is what we wanted.

Now, how do you make a hub visible from another computer? I’d say that in 99.9% of network configurations it will not work out of the box, because you need to allow other computers to see this one. So how do you do that?

You go to Services on the computer with the hub, and you find RabbitMQ. This is the middleware we use for routing messages across computers. You go to Properties and you find the path to the executable — some Erlang OTP path — which you have to copy.

Then you go to your firewall — Windows Defender Firewall, if you use that one — with advanced security options, and not just the firewall, because you’re going to create a rule. We need to create an inbound rule. You click on Inbound Rules first, then New Rule, and then you specify what your network is, whether it’s a private or a domain network. I skip that point in my slides.

Then you say that it’s going to be a program rule type. You allow this program to listen to the specified port and to TCP traffic. Notice that you need to change the name here — not erlsrv, but just erl. That’s important. And that’s it. Once you’ve specified that, everything will be visible. If you did this correctly, a remote Belkasoft X will show you a green circle next to the BelkaGPT Hub status.

You may ask: “Yuri, that’s easily doable from PowerShell. You can use PowerShell, you can use any kind of script to make this rule programmatically. Why do we have to do that?” There are two reasons why we don’t do it for you out of the box.

First, not everyone is using Defender. Many of you have different protection software, antiviruses, whatever, so that’s going to be managed by different software. And second, we’re not comfortable amending or changing something that is connected to the security of your infrastructure.

We think the proper way to do it is that you do it on your computer. Again, your domain user may not be allowed to do this kind of tweak on your systems — maybe it’s going to be a system administrator who has the permissions to make this kind of change to network traffic.

Okay. So what kind of configurations do we see when you use BelkaGPT Hub with workers? Number one, on the left: separate desktops, with both the hub and the worker sitting on one machine together. So you have just one worker, and the hub also on the same computer. I’d say that all the trial versions you’re going to run will be like that.

Number two, you can also merge the hub and run it on your investigative computer. For example, if you’re a one-man shop, or your laboratory has just one digital forensic investigator, it’s still feasible — it can still be useful to have BelkaGPT Hub if you want to route your AI calculations to another computer rather than your investigative workstation.

Number three, when your organisation or your lab needs to grow, you can install multiple workers. If you have many GPU-enabled computers, that’s your choice, and the hub can sit on one of the investigator computers, so you don’t need a dedicated computer for it. It’s easy to scale — you just add more workers if you need them.

And it’s easy to scale down. You just disconnect the computer from the infrastructure by shutting down the Belkasoft worker. You don’t need to do anything else. It’s important to mention that you don’t register anything on the hub, so adding a new worker is easy. You just install the worker and give it the address of the hub. That’s it. To add a worker or to remove a worker, you just add it or remove it. You don’t need to tweak either the hub or the investigative computers.

Finally, number four: for most major organisations you’ll possibly have multiple workers and a hub sitting on a separate computer, especially if you’re not comfortable with traffic going through your computer to somewhere else. You want to avoid the situation where one investigative computer talks to another investigative computer which talks to workers.

In this case you can use any computer for the hub, and this way your investigative computer isn’t tweaked — it doesn’t have open ports for incoming traffic from other computers on your network. So this is possibly the most mature configuration for you.

Now I have a question for you. If you use this kind of infrastructure, what would your planned setup be? Whether you just have one worker and a hub on the same computer; or you have the hub along with Belkasoft X if you’re a one-man shop with a single worker; or maybe you have several workers with the hub on one of the computers; or you have full decentralisation.

By the way, those of you who already have GPU farms — that’s a great way to save money. Many Belkasoft customers already have good computers for breaking passwords, and these can be monster machines with a number of powerful GPUs. In this case you can just put a worker, or several workers, onto that computer to reuse that power when the machines aren’t busy breaking passwords.

Let me wait a couple of seconds more while you’re still voting, and then we’ll go to the final slides. So we have 33 for the hub and worker on the same machine. No one selected full decentralisation. Interesting.

Now, what about the price of those components? BelkaGPT costs just one dollar or one euro short of 1,000 — so it’s under $1,000 a year, depending on the region. Again, it’s a module of Belkasoft X, which can be built into Belkasoft X. The second tier is much more affordable — I believe it’s some 450 to renew it.

BelkaGPT Hub is more expensive. It starts from 15,000 minus one dollar or euro per hub. But what’s important about BelkaGPT Hub is that we don’t charge you per worker, so the price only depends on the number of concurrent users you have. You can have one worker, you can have 100 workers, and the price will not change. It all depends on the number of users.

To get accurate quotes, please contact [email protected] and specify your planned setup. Also, BelkaGPT Hub is not available on our website to download. But if you’d like to test it, again, ask my colleagues at [email protected] and they’ll send you information on how to download the installation for you to test the entire configuration.

So far we’ll give you the Windows installer, so you’ll be able to install the trial version on a Windows machine. But we also have a Linux Docker version, which for some organisations is easier to deploy — install it once and then copy it across different computers if you need to. For that, though, we don’t have an installer. If you decide to buy the tool, we’ll help you install the Linux Docker version into your infrastructure. So the trial is only on Windows, but the commercial license will work on both Windows and Linux.

Some final thoughts. AI has found its place in many industries in our world, and these are interesting times for digital forensics. There’s still a lot of disagreement about it, but at the end of the day I think it will be widely adopted, simply because we cannot ignore the benefits it can bring to the table.

Of course, we will have some legislation, some recommendations, and bigger institutes and standardisation bodies will develop the rules for how we use it. But at the end of the day, I think we’ll somehow adopt AI for digital forensics as well.

The cloud approach and the do-it-yourself approach are, I think, not viable for digital forensics, at least at this point. We really need digital forensics-specific AI. BelkaGPT and BelkaGPT Hub are the tools that enable you to run everything entirely offline.

Both technologies are developed with digital forensics and cyber incident response in mind, so they live inside your forensic workflow. They have the same data that you see inside your digital forensic tool, which is Belkasoft X. So you are fully in control of what you see, where it’s stored, and where and when it’s processed.

It’s easy to scale up with the help of BelkaGPT Hub by just adding new workers, or new computers with GPUs. I think both technologies can bring you a lot of value if configured correctly, and it’s not going to cost you a fortune, because you can reuse your existing infrastructure for those technologies.

I hope my presentation was useful for you. You can learn more about BelkaGPT and BelkaGPT Hub using the links on this screen. I’d also like to remind you that we’re currently running a SQLite queries course which is completely free until 15 July 2026. After that it will cost $999. So please take the chance to participate in this course. A certificate and six CPE points will be granted to everyone who completes it.

Leave a Comment