BlackLight Quick Start Guide

  1. Open BlackLight and click on New

  2. Name and Save case file to desired location (local host drive is recommended)

  3. Click on the green Add button to ingest Evidence

  4. Select either an Attached Device OR click on the green Add button to ingest a Disk Image, File, or Folder

  5. Select desired processes to run under Ingestion Options and click Start

    Note - Clicking on the ellipsis button [...] opens another window for further options

  6. Processing options can also be clicked on to Run from the Evidence Status view

    Once the Parsing column shows complete with green checkmark, artifacts can be examined

  7. Click on the Evidence item and the desired category to view data