BlackLight Quick Start Guide

Version 2019 R3

Welcome to BlackLight

BlackLight is designed with both novice and advanced users in mind. It features a clean interface, easy navigation, and powerful advanced options. This guide is designed to quickly get users up and running and experiencing the power and simplicity of BlackLight.

Recommended System Requirements:

OS SpecificationsPlatformProcessorRAMScreen ResolutionFree Disk Space
macOS 10.14.6
Windows 10
Intel 64-bit system3.1 Ghz 6-Core Intel Xeon E5 or better32GB DDR3 or higher1680 x 1050 or better5 GB (installation only)
25 GB (temporary space)

Minimum System Requirements

OS SpecificationsPlatformProcessorRAMScreen ResolutionFree Disk Space (for minimal installation of BlackLight)
macOS 10.11.4
Windows 7
Intel based system2.7 Ghz Intel Dual Core i716GB DDR31024 x 768 or better5 GB (installation only)
25 GB (temporary space)

Getting the Most Out of BlackLight

Not Recommended

Create a BlackLight Case

Upon launching BlackLight, examiners are presented with the Case Manager window:

[Description of Case Manager window showing existing cases and options to create a new one]

Note: Even though it may work, BlackLight does not officially support saving BlackLight cases to network attached drives.

Remember

  • Use NTFS, HFS+, or APFS
  • Store case file on separate drive
  • Do NOT store on RAID 0 (striped disk)
  • Do NOT use exFAT

Add Evidence

Select the [Add] button beside Evidence and navigate to the location of the evidence file.

BlackLight Supports:

Select the evidence file, or the first segment of the evidence, then click 'Select'.

Within the Add Evidence window, BlackLight automatically displays the size of each volume/partition.

Processing Options

BlackLight has a comprehensive list of processing options. In 2019 R3 and later, all processing options are displayed in the Processing Options: section of the 'Add Evidence' Window. As a general rule, the more options chosen the longer the evidence takes to process. Most processes can be run later.

Radio Buttons

Three default Processing Options are included in the interface: Preview, Triage, Comprehensive.

Preview: No processing options are selected. BL parses the file system and shows the results in the Browser tab.

When Preview is chosen, BlackLight displays the following warning:

[Warning: Running Preview or skipping normalization will limit the views. By choosing the Preview option or skipping normalization you will only be able to view and search the filesystem. You will not be able to see the data views until the data normalizers have been run.]

Prior to 2019 R3, by default BlackLight automatically normalized all data. Normalization was a background process the user had no control over. It is the normalization process that populates many of the views in BlackLight (Actionable Intel, Communication, Media, Locations, etc.). If you do not run this, only the Browser and File Filter tabs will work.

Processing Options Details

OptionDescription
NormalizationBlackLight's internal processes for populating data in Actionable Intel, Communication, Locations, Internet, Productivity, and System tabs
File Signature AnalysisCompares file signature and file extension to populate Content Extension field
Picture AnalysisIdentify pictures using signature analysis
Video AnalysisParse videos and split them into sixteen frame sequences (4 x 4) to allow BlackLight gallery view and % skin tone analysis
Threat Category AnalysisImage Analyzer used to classify media into Threat Categories
Calculate HashesHash all files using MD5, SHA-1 and/or SHA-256 algorithms
Identify Known FilesIdentify known file types using hash sets from BlackBag's website, other imported hash sets, or user created hash sets
File CarvingRecover or attempt to recover deleted files based on defined File Signatures
Snapshots / Volume Shadow CopiesmacOS APFS Snapshots and Windows Volume Shadow copy parsing LONG PROCESSING TIME
File System Journal AnalysisProcess $USNJRL file in Windows and macOS .fsevents
SpotLight ParsingmacOS Spotlight extended attribute data parsing
OS Event / Security LogsWindows $log analysis, EVT/EVTX analysis, and macOS ASL logs
Process ArchivesAll archives files (zip, gz, 7z, tar, and rar) are expanded down to two levels of nested archives CONSUMES A LOT OF DISK SPACE
Smart IndexingBuilds a Smart Index of processed allocated data
Content Search (Bulk extraction)Runs built-in searches agains memory files
Mail ParsingProcesses Apple Mail, Outlook mail files
Hiberfil.sys / Pagefile.sysProcesses Windows memory hibernate file and pageful
Calculate File EntropyDetermines possible encryption level of files LONG PROCESSING TIME

Note: If the correct processing options are not chosen, many views in BlackLight will NOT contain data.

Evidence Status

While evidence is processing, BlackLight provides feedback indicating the status of the jobs being processed.

Status Symbols and Meanings

SymbolMeaning
[Status Indicator]Overall progress of partition processing for the selected processing options. Green Light shows when processing started. Yellow Light indicates processing is still in progress. Green Light shows when processing completed. Timer shows the time it took to process the partition.
[Play Icon]Seen when Parsing or DB Recovery processes are running.
[Checkmark Icon]Process has completed.
[Yellow Circle Icon]Process has completed, but there are more options to run that were not selected.
[Hourglass Icon]Process is running, but not complete. The process cannot be paused.
[Waiting Icon]Process is waiting to run.
[Running Icon]Process is running, but not complete. The process can be paused.
[Not Chosen Icon]Process has not been chosen to run.
[Cannot Run Icon]Process cannot run on the partition.

For each volume being processed, BlackLight provides information about the status of all processing options.

Navigating BlackLight

Select evidence item(s) on the left and a consolidated data view icon above to display the data processed for that particular view.

The main navigation tabs include: Browser, File Filter, Actionable Intel, Communication, Media, Locations, Internet, Productivity, System, Plugins.

Within these views, data can be sorted by various criteria, such as file size.

Processed Data

BlackLight categorizes processed data into several key areas:

Automatically Processed Data within BlackLight

ArtifactLocationDescription
Device BackupsActionable Intel → Device BackupsStored iOS backups on macOS and Windows computers. iOS backups can be directly imported for processing.
Device ConnectionsActionable Intel → Device ConnectionsParsed Windows/macOS parsed USB device connections.
File DownloadsActionable Intel → File DownloadsShows files downloaded by macOS and Windows, along with QuarantineEvents from macOS.
Jump ListsActionable Intel → Program Execution → Jump ListsWindows 7 and above artifact that shows user interaction with files.
Link FilesActionable Intel → File Knowledge → Link FilesWindows user .lnk files.
PrefetchActionable Intel → Program Execution → PrefetchWindows artifact shows launched applications.
Program ExecutionActionable Intel → Program Execution → Last ExecutedWindows OpenSaveMRU registry key.
Recent ItemsActionable Intel → File Knowledge → Recent ItemsRecent items from NTUSER.dat and macOS recent items.
Shell BagsSystem → Registry → ShellBagsWindows shellbag registry values.
SuperfetchActionable Intel → Program Execution → SuperfetchWindows Vista and later show launched applications.
Trash ItemsActionable Intel → File Knowledge → Trash ItemsWindows Recycle Bin and macOS Trash items.
User AccountsActionable Intel → Account Usage → User AccountsData parsed from Windows SAM file and macOS user plist files.
User AssistActionable Intel → Program Execution → User AssistWindows applications launched by user. Data parsed from NTUSER.dat.
Windows RegistrySystem → Registry → AllParsed Windows registry hives.

More Information

The BlackLight User's Guide has detailed instructions on using BlackLight and is text searchable.

Classroom Instruction

BlackBag offers several training courses:

Basic Forensic Investigations

Whether you are first learning the fundamentals forensic investigation techniques or interested in seeing BlackBag's tools in action, this course is an excellent fit for any forensic professional who could benefit from a full scenario-based investigative tutorial, regardless of prior use of BlackBag tools.

https://www.blackbagtech.com/training/courses/basic-forensic-investigations.html

Apple® Forensic Investigations

This course is composed of the essential techniques every forensic professional needs to triage and analyze macOS and iOS devices. Specially crafted by our expert instructors, this course has something for every level of forensic experience.

https://www.blackbagtech.com/training/courses/apple-forensic-investigations.html

Advanced Apple® Forensic Investigations

As the second part of our Essential Forensic Techniques series, Advanced Apple® Forensic Investigations delves into more complex analysis concepts and includes many specific data points encountered in examinations.

https://www.blackbagtech.com/training/courses/advanced-apple-forensic-investigations.html

Windows® Forensic Investigations

Take your Windows forensic skills to the investigative level. This comprehensive course teaches the in-depth analysis of Windows-based evidence. Developed by our expert instructors with field experience, this course will provide you the skills to thoroughly inspect your digital evidence.

https://www.blackbagtech.com/training/courses/windows-forensic-investigations.html

PDF preview unavailable. Download the PDF instead.

BlackLight-QuickStart-Guide-v2019R3 macOS Version 10.14.6 (Build 18G95) Quartz PDFContext Word

Related Documents

Preview BlackBag MacQuisition 2020 R1 Quick Start Guide for Mac Forensics
A comprehensive quick start guide for BlackBag's MacQuisition 2020 R1 software, detailing its use in triaging and imaging Mac computers for digital forensic investigations, including live data collection and handling of FileVault2 and T2 security chips.