Each module acquires a type of digital content and produces the same result: an exhibit with a hash, an RFC 3161 timestamp and a forensic report, verifiable by anyone.
WACZ archive, video recording, screenshots, HTTP traffic (HAR) and forensic report.
Learn moreRemote file acquisition with double download, DNS/WHOIS/SSL analysis and traceroute.
Learn moreIMAP connection, DKIM/SPF/DMARC verification, PEC analysis, EML preservation and hop analysis.
Learn moreForensic evidence collection of a user-supplied image: EXIF/IPTC/XMP, GPS, perceptual hashes, ELA and in-depth analysis.
Learn moreForensic screen capture (full screen or region), tamper-proof, with anti-manipulation shielding and timestamp.
Learn moreRemote files and directories via FTP/FTPS/SFTP with integrity check and server snapshot.
Learn moreContent from Google Drive, Dropbox and OneDrive with token auto-refresh.
Learn moreWhatsApp conversations, media and metadata with session recording and cryptographic sealing.
Learn moreTelegram channels, groups and chats with media, metadata and certified bundle.
Learn moreForensic acquisition of .onion services with a dedicated browser, documented circuit and single network exit.
Learn moreBeyond acquisition. Two features that do not capture content, and therefore do not count among the modules:
Inside the Web pages module, C.E.R.T.O. recognises seven platforms from the address and automatically activates the dedicated collection process:
C.E.R.T.O. Desktop for Windows and macOS includes every acquisition module.