Each module acquires a type of digital content and produces the same result: an exhibit with hash, RFC 3161 timestamp and forensic report, verifiable by anyone.
WACZ archive, video recording, screenshots, HTTP traffic (HAR) and forensic report.
Learn moreRemote file acquisition with double download, DNS/WHOIS/SSL analysis and traceroute.
Learn moreIMAP connection, DKIM/SPF/DMARC verification, PEC analysis, EML preservation and hop analysis.
Learn moreForensic evidence collection of a user-supplied image: EXIF/IPTC/XMP, GPS, perceptual hashes, ELA and in-depth analysis.
Learn moreForensic screen capture (full screen or region), tamper-proof, with anti-manipulation shielding and timestamp.
Learn moreRemote files and directories via FTP/FTPS/SFTP with integrity check and server snapshot.
Learn moreContent from Google Drive, Dropbox, OneDrive and iCloud with token auto-refresh.
Learn moreWhatsApp conversations, media and metadata with session recording and cryptographic sealing.
Learn moreTelegram channels, groups and chats with media, metadata and certified bundle.
Learn moreC.E.R.T.O. Desktop for Windows and macOS includes every acquisition module.