010-68421378
sales@cogitosoft.com
Categories
AddFlow  AmCharts JavaScript Stock Chart AmCharts 4: Charts Aspose.Total for Java Altova SchemaAgent Altova DatabaseSpy Altova MobileTogether Altova UModel  Altova MapForce Altova MapForce Server Altova Authentic Aspose.Total for .NET Altova RaptorXML Server ComponentOne Ultimate Chart FX for SharePoint Chart FX CodeCharge Studio ComponentOne Enterprise combit Report Server Combit List & Label 22 Controls for Visual C++ MFC Chart Pro for Visual C ++ MFC DbVisualizer version 12.1 DemoCharge DXperience Subscription .NET DevExpress Universal Subscription Essential Studio for ASP.NET MVC FusionCharts Suite XT FusionCharts for Flex  FusionExport V2.0 GrapeCity TX Text Control .NET for WPF GrapeCity Spread Studio Highcharts Gantt Highcharts 10.0 版 HelpNDoc Infragistics Ultimate  ImageKit9 ActiveX ImageKit.NET JetBrains--Fleet JetBrains-DataSpell JetBrains--DataGrip jQuery EasyUI jChart FX Plus OPC DA .NET Server Toolkit  OSS ASN.1/C Oxygen XML Author  OSS 4G NAS/C, C++ Encoder Decoder Library OSS ASN.1 Tools for C with 4G S1/X2 OSS ASN.1/C# OSS ASN.1/JAVA OSS ASN.1/C++ OPC HDA .NET Server Toolkit OPC DA .Net Client Development Component PowerBuilder redgate NET Developer Bundle Report Control for Visual C++ MFC  Sencha Test SPC Control Chart Tools for .Net Stimulsoft Reports.PHP Stimulsoft Reports.JS Stimulsoft Reports.Java Stimulsoft Reports. Ultimate Stimulsoft Reports.Wpf Stimulsoft Reports.Silverlight SlickEdit Source Insight Software Verify .Net Coverage Validator Toolkit Pro for VisualC++MFC TeeChart .NET Telerik DevCraft Complete Altova XMLSpy Zend Server

Elcomsoft Cloud eXplorer

Elcomsoft Cloud eXplorer

Forensic Acquisition of Google Accounts

Acquire information from users’ Google Account with a simple all-in-one tool! Elcomsoft Cloud Explorer makes it easier to download, view and analyze information collected by the search giant, providing convenient access to users’ search and browsing history, page transitions, contacts, Google Keep notes, Hangouts messages, as well as images stored in the user’s Google Photos account.

Google collects massive amounts of information from registered customers. Elcomsoft Cloud Explorer extracts information from the many available sources, parses and assembles the data, presenting information in human-readable form.

Google Data in Digital Forensics

Cloud forensics is an emerging area to forensic experts and IT security officers. The amount of data generated by consumers using the many online services is hard to underestimate. This data can become extremely valuable for an investigation of criminal cases and security breaches of IT infrastructure.

Online services are increasingly used by consumers, including those of a criminal kind. Cloud service providers such as Google retain astonishing amounts of data that literally follow their users’ every step. Acquiring this evidence from cloud storage services can be a challenge. Viewing, discovering and analyzing the data may present yet another challenge if the investigator lacks tools and knowledge.

Elcomsoft Cloud Explorer was designed specifically to address those limitations. Requiring no special expertise and no prior training, Elcomsoft Cloud Explorer falls into the category of all-in-one tools offering one-click downloading and easy viewing of information. The tool comes with everything you need to investigate information that Google has about a suspect.

What Is Extracted

Elcomsoft Cloud Explorer offers over-the-air acquisition for a wide range of Google services including all of the following:

User Profile and other info

Messages (Google Hangouts)

Call logs (Android 7.0 Nougat)

Saved Wi-Fi credentials (SSID and passwords)

Email messages (Gmail) via Gmail API

Contacts (including synced contacts from mobile devices)

Notes (Google Keep)

Search History (including Web sites visited after firing up the search)

Google Chrome data[1] (synced bookmarks, Web forms, logins and passwords, page transitions)

Media (images from Google Photos including EXIF data)

Calendars

Dashboard

Location history

In other words, what you get is a comprehensive snapshot of user activities in Google services including searches made in non-Google browsers while the user was logged in to their Google Account.

Two-Factor Authentication Support

 

In order to access someone’s data, investigators must supply the correct Google ID and password. Since many users protect access to their accounts with two-step authentication, access to the secondary authentication factor is required if two-step authentication is enabled.

Elcomsoft Cloud Explorer fully supports two-factor authentication, allowing entering the 6-digit code generated by the secondary authentication factor.

Viewing, Searching and Analyzing the Data

Elcomsoft Cloud Explorer is not just about downloading information. It’s an all-in-one forensic tool allowing to view and analyze information obtained from the user’s Google Account.

The built-in viewer supports the most popular data formats used in the Google Account, parsing and displaying them automatically. The viewer includes instant filtering and quick search functionality. Finding a certain contact, message or Web site authentication credentials is easy: you just need to type part of the word you are looking for into the search box.

Forensic Gmail Acquisition

Elcomsoft Cloud Explorer offers fast offline access to Gmail communication history. The tool can download all or some email messages from the user’s Gmail account, allowing investigators specifying the exact period to acquire. Access to messages is implemented via Google’s proprietary Gmail API, which makes it possible to achieve acquisition speed of about 3000 email messages per minute (subject to message size and connection speed). Selective access to messages during the acquisition stage and unbeatable acquisition speed make Elcomsoft Cloud Explorer one of the fastest Gmail analytic toolkits on the market.

Gmail Analysis

The built-in Gmail analyzer offers detailed searching and filtering through all downloaded messages, and provides valuable insight about downloaded messages. Thanks to the use of Google’s Gmail API instead of the commonly available POP3 or IMAP protocols allows the tool to distinguish between Read, Unread and Archived messages, recognize Gmail categories, labels, folders and conversation threads. Users can automatically filter messages that contain media attachments such as pictures, videos or documents. Complete message threads are instantly available as investigators search or browse through downloaded mail.

Information Collected by Google

Google offers consumers a diverse range of services ranging from world’s most popular search engine to free email, free cloud storage and free Web browser with automatic sync across devices among other things. Google services run on a large number of desktop and mobile devices with literally billions of users.

All Google services can be personalized by registering for a Google Account. Once the user registers an account, Google starts aggregating information about the user’s online and offline activities. The system processes and analyzes communications, recommends places to visit and things to read. Comprehensive location history, Google searches ever fired on all stationary and mobile devices, Chrome bookmarks, passwords and browsing history, page transitions, travel data including air tickets, hotel stays and car rentals (even if not booked through Google itself), notes, pictures, contacts and a lot more data can be collected and stored by Google.

The various bits and pieces of data are kept in various places across Google servers. They are accessible via vastly different protocols, sharing one thing: they all require authentication via Google Account. While it is possible to download certain bits of information from Google, the data is offered in various formats (some of them binary) that can be difficult to view and hard to analyze in one place. Elcomsoft Cloud Explorer removes the hassle, not only downloading more data than provided by Google but offering the ability to view and analyze information without leaving the tool.

User Notification

 

Elcomsoft Cloud Explorer is a more forensically sound method of extracting Google data compared to Google’s own service, Google Takeout. In most cases, extracting information using Elcomsoft Cloud Explorer does not trigger a user alert message and does not leave traces in the user’s Google account. However, when accessing certain types of data, the user might still receive a notification from Google alerting about a new system, new browser or new IP address login. At this time, predicting whether a notification alert will be triggered is not possible.

Reporting

A wide range of HTML reports are available, including User Infо, History, Chrome, Dashboard, Media, Locations, Calendars, Notes, Chats, Google Keep, and Contacts. HTML reports can be easily printed or viewed in any Web browser.

Future Development

We are constantly working to improve Elcomsoft Cloud Explorer. Early next year, we’ll be adding features to allow visualizing location data on the map, extract additional types of data from Google accounts, and access information backed up by Android devices. We’ll be adding support for Google Drive, downloading all types of files from Google’s cloud storage service.

The Media section will be extended with more/additional information on persons who are marked on photographs as well as support for video download. Token authentication is also in the plans. All this and much more is expected to arrive in later this year.

Quick Navigation;

© Copyright 2000-2023  COGITO SOFTWARE CO.,LTD. All rights reserved