Version 4

Paraben’s P2C 4.0
Release Notes
Welcome to Paraben’s P2C 4.0!
Paraben's P2 Commander is a comprehensive digital forensic analysis tool designed to handle
more data, more efficiently while keeping to Paraben's P2 Paradigm of specialized focus of the entire
forensic exam process.
P2 Commander utilizes Paraben's advanced plug-in architecture to create specialized engines
that focus on such things as Email, Network Email, Chat Logs, File Sorting, Internet file analysis and
more all while increasing the amount of data that can be processed and utilizing resources through
multi-threading and task scheduling. Not only is P2 Commander affordable, it runs effectively with
lower hardware requirements than you thought possible.
What’s new in P2C v. 4.0

Pre-Release of Windows 10 support!

A completely new modern looking interface including ribbons, improved layout, new graphics, and a
case guidance screen are now available.

Encrypted and non-encrypted iPhone, iPad, and iPod Touch backups are now parsed.

Microsoft Exchange 2013 (EDB) mailstorages are now supported.

Gaming System Support: Xbox evidence extracted from Xbox 360 is now supported.

SQLite databases are now parsed.

A new Game Console Files category has been added to the file sorting.

Possible problems with keyword indexing on HFS+ file system have been fixed.

Possible problems with displaying attachments in Microsoft Exchange evidence have been fixed.

Overall stability has been improved.

DP2C and P2 eXplorer Pro are now included with the purchase of P2C 4.
This document provides you with a list of all P2C robust features and a full list of key changes in version 4.0.
P2C Key Features
Paraben’s P2C v 4.0 has the following key features:
Main features:
 Analysis of disks and disk images with the most popular file systems, indexing, deleted data recovery,
searching, and exporting.
 Analysis of the most popular mail storage formats: viewing, searching, sorting attachments, and
exporting.
 Enhanced parsing of chat databases, registry hive files, OLE streams, archives, Internet browser data,
memory dump files, and more.
 Processing and analysis of existing forensic containers, exporting data to them and creating the new
ones.
General features:
 Full Windows 8 and 8.1 compatibility, including UAC and digital signature by Microsoft
 Back-end Firebird database for support of massive amounts of data
 Multi-threading and task scheduling capabilities to process more data in less time
 Convenient plug-in architecture
 Easy-to-use registration scheme
GUI features:
 [NEW!] GUI is redesigned and is now more sophisticated than ever.
 File viewers for popular file formats
 EXIF data viewer for graphic files including search in EXIF data
 Special e-mail data viewer for viewing e-mail messages in different formats including viewing
attachments
 Special Chat RTF viewer for viewing chat history in a convenient format
 Data Triage of operating system
 Integrated Internet Explorer cache parser
 Adjustable font color and size
Plug-ins features:
 File system plug-ins allow you to examine logical and physical disks as well as individual files and
folders (local, network and stored on CD/DVD) with:
o FAT12, FAT16, FAT 32, [NEW!] FATX
o ExtX
o HFS+
o NTFS (including partition free space and file slack)
o [NEW!] STFS

Supports disk images from the most popular forensic imaging software
o Paraben's Forensic Replicator (PFR)
o Safeback 2-3
o EnCase 4-5-6-7
o RAW disk images (created in P2 Enterprise, Smart, etc.)
o Virtual PC Virtual HD image
o VMware disk image


Supports memory dump files
E-mail plug-in supports viewing multiple e-mail and network e-mail formats in a special e-mail data
viewer (including support for exporting data to E-mail Examiner, EML [rfc822 compliant], Attachments
only, MSG [OLE message], and PST [Outlook] e-mail formats)
o Microsoft Exchange 5.0, 5.5, 2000, 2003 SP1, 2007, 2010, [NEW!] 2013 (EDB)
o Lotus Notes 4.0, 5.0, 6.0, 7.0, 8.0, 8.5 (ODS 43 and 51), 9.0.
o Novell Group Wise up to 2012
o Microsoft Outlook (PST) up to 2013
o Microsoft Outlook Express (EML)
o E-mail Examiner (EMX)
o AOL
o The Bat! (3.x and higher)
o Thunderbird
o Windows Mail
o Google Takeout storage
o Eudora
o Maildir

Chat database plug-in supports many popular chat clients for viewing chat database contents in a
convenient, color coded format for easy analysis
o Yahoo!
o Skype
o ICQ
o Miranda
o Hello (Including Thumbnails)
o Trillian

OLE Storage plug-in supports the parsing and analysis of any OLE storage

Archive plug-in supports many popular archive types including: zip, jar, xpi, iso, chm, cab, msi, ppt, doc,
xls, arj, bzip2, cpio, deb, gzip, lzh, msis, rpm, split, tar, z, wim, and 7z.

Internet Data plug-in supports the parsing and analysis of:
o Mozilla Firefox cache and history
o Internet Explorer cache, cookies, and history
o Google Chrome history, cookies, auto fill items, keywords and logins

[NEW!]

[NEW!]
SQLite plugin supports parsing and analysis of SQLite databases including: *.db, *.Sqlite,
*.Sqlite3, *.sqlitedb, and *.db3, and others.
iPhone backup plugin supports iPhone, iPad, and iPod Touch backups created by iTunes,
including:
o
o

iOS 1x-7x non-encrypted backups
iOS 3x-7x encrypted backups
Forensic Container plug-in allows:
o Creating a new Forensic Container
o Adding an existing Forensic Container as evidence
o Parsing the content of a Forensic Container as embedded data in the added file system
evidence.

DS case plug-in allows parsing and analysis of cases created by Paraben’s DS and Paraben’s
Deployable DS.

[NEW!]

Forensic Sorter plug-in sorts data into relevant categories and creates a keywords database for
keywords search:
o Perform keywords indexing of any text data
o Quick keywords search in indexed data including multiple parameters for email evidence
o Sort e-mail attachments
o Sort recovered deleted data
o Analyze file type/file extension mismatch

Deleted data recovery
Game Console plug-in allows you to examine images of logical and physical disks with evidence
from Xbox 360 including:
o FATX filesystem used by Xbox.
o STFS filesystem data intended to store packages created and downloaded by the Xbox.
o XDBF databases containing gamer profile data.
Other features:







Hash database features can manage and Filter Out Common Hashes (FOCH)
Automatic detection of embedded data from supported file types (view e-mail archives, chat databases,
disk image files, OLE storage, archives, etc. from the exact place they are stored without having to add
them to your case separately)
Multiple reporting options for complete customization
Image Analyzer for pornographic image detection
An encrypted dynamic Forensic Container creation
Robust advanced searching and filtering options including multi-encoding support
o Search within e-mail attachments including search by attachments type
o Search in deleted data, unallocated disk space, file slack, etc.
o Multi-parameter search for each type of data.
o Regular Expressions search.
o Ability to search for data without searching for its contents (file name/directory names)
o Multi selection of search results for adding to a Search results report.
Exporting
o Export any file in its native format
o Export multiple files from different folders/disks/evidence types
o Export files/folders to forensic containers.
o Export mail storage contents to EML, EMX, PST, MHTML, and MSG formats.
o Export e-mail attachments in their native format.
o Export from search results and bookmarked data including multi-selection.
o Batch export for e-mail databases
P2C 4.0 New Features
A completely new modern looking interface including ribbons, improved layout, new graphics,
and the case guidance screen are now available.
Encrypted and non-encrypted iPhone, iPad, and iPod Touch backups are now parsed.
Xbox evidence extracted from Xbox 360 is now supported (including FATX, STFS, and XDBF).
SQLite databases are now parsed.
A new Game Console Files category has been added to the file sorting.
Microsoft Exchange 2013 (EDB) mailstorages are now supported.