Belkasoft X is a digital forensics, incident response (DFIR), and eDiscovery platform designed for the acquisition, processing, and analysis of digital evidence. It supports data extraction from sources including computers (Windows, macOS, Linux/Unix-based), mobile devices (iOS, Android), cloud services, RAM, drones, and vehicle systems. The system performs local and remote acquisition via logical and physical methods, including agent-based collection, hardware-specific exploits like checkm8 and EDL, and the ingestion of third-party forensic images. Built upon a database engine to correlate heterogeneous data, the platform is architected for large-scale investigations and can be deployed on standalone workstations or in distributed environments.
The software's analytical functions combine automated artifact parsing with low-level analysis tools, including built-in viewers for Hex, SQLite databases, registries, and file systems. Its technical capabilities include full volume decryption for formats such as BitLocker and APFS, live memory analysis, data carving from unallocated space, malware detection using YARA and Sigma rules, and a mobile passcode brute-force module. An integrated offline AI module provides picture classification, speech-to-text transcription, optical character recognition (OCR), and natural language query support, complemented by connection graphing and a chronological timeline. Findings can be exported into standard industry formats and a portable viewer, with automation available through a command-line interface and API.