Oxygen Forensic® Detective
Oxygen Forensic® Detective is an all-in-one forensic software platform built to extract, decode, and analyze data from multiple digital sources: mobile and IoT devices, device backups, UICC and media cards, drones, and cloud services. Oxygen Forensic® Detective can also find and extract a vast range of artifacts, system files as well as credentials from Windows, macOS, and Linux machines.
The cutting edge and innovative technologies deployed in Oxygen Forensic® Detective include, but are not limited to, bypassing screen locks, locating passwords to encrypted backups, extracting and parsing data from secure applications and uncovering deleted data.
Furthermore, multiple extractions can be investigated in a single interface to gain a complete picture of the data. By using the integrated industry-leading analytical tools to find social connections, build timelines, and categorize images, law enforcement, corporate investigators and other authorized personnel can help make this world a safer place.
Oxygen Forensic® Detective is distributed in a USB dongle and is valid for a single user.
Oxygen Forensic® Detective offers data extraction from iOS, Android devices, feature phones, media, and SIM cards. Because time is always of importance, simultaneous acquisition of several devices is available and exclusive to Oxygen Forensic® Detective. Oxygen Forensic® Detective imports numerous backups and images, including iTunes, Android backups, GrayKey, JTAG, Chip-off, UFED, XRY images, and more.
Oxygen Forensic® Detective uses proprietary methods to bypass or disable screen locks on mobile devices, including Samsung, LG, Motorola, as well as devices based on MTK, Spreadtrum or Qualcomm chipsets. The built-in Jet Imager enables physical data extraction at speeds unsurpassed in the industry. Oxygen Forensic® Detective can find passwords to encrypted iTunes backups and Android images as well.
Oxygen Forensic® Detective enables the verbose data parsing and analysis from drone collections, flight logs, mobile apps and cloud services. Oxygen Forensic® Detective can create or import drone physical dumps and parse GPS locations showing valuable route data as well as device telemetry to include: speed, direction, altitude, temperature, and more. Currently, various models of DJI and Parrot drones are supported.
Data parsing from drone applications is also available from iOS and Android devices. Investigators can decode drone images and videos, locations with time stamps and other data. Additionally, drone data extraction from cloud services can be accomplished via login/password or token from DJI, SkyPixel or My Parrot clouds.
Oxygen Forensic® Detective currently offers data extraction from two popular IoT devices – Amazon Alexa and Google Home. Since it is difficult to extract data directly from devices, we provide investigators with the ability to access alternative sources – cloud and mobile apps. Investigators can gain access to cloud information via login/password or token that can often be extracted from the user’s PC or mobile devices. Oxygen Forensic® Cloud Extractor acquires a complete evidence set including voice recordings that can be played directly our software interface. Oxygen Forensic® Detective also extracts IoT app data from Apple iOS and Android devices.
The built-in Oxygen Forensic® Cloud Extractor allows investigators to gain access to a tremendous amount of cloud services that include iCloud, Google, Microsoft, Samsung, Huawei, Mi Cloud accounts, E-mail server and other services, like Facebook, Twitter, Instagram, Dropbox, WhatsApp, Telegram, etc. Our Cloud Extractor also offers the exclusive ability to extract and decrypt WhatsApp backups.
Investigators may utilize either account credentials or tokens to access any supported cloud storage service. Using Oxygen Forensic® Detective, investigators can extract credentials and tokens directly from a mobile device while Oxygen Forensic KeyScout collects passwords and tokens on Windows based computers. This valuable data can then be used to collect and extract information from the associated cloud service accounts under investigation.
Oxygen Forensic® KeyScout utility focuses on extracting passwords, tokens, and user data both from web browsers and desktop apps, as well as locating iTunes backups and finding Wi-Fi hotspot passwords on Windows OS computers.
Currently there are numerous desktop apps supported, including WhatsApp, Viber, WickrMe, Telegram, Skype, Microsoft Mail, Microsoft Outlook, Thunderbird, all the popular Web browsers, iCloud for Windows, etc. Collected tokens and passwords can be immediately used for cloud data extraction while extracted web browser, messenger and email data can be imported into Oxygen Forensic® Detective software for further analysis and analytics with mobile data artifacts in one case.
Oxygen Forensic® Detective performs logical acquisition of smartwatches based on MTK chipset allowing forensic experts to extract device model, contacts, calls, messages, multimedia files, and other data. Moreover, the software acquires complete data from various fitness apps, like Apple Health (including data synched with Apple Watch), Samsung Health, Google Fit, FitBit, Endomondo, and more. This valuable data can be extracted both from mobile devices and cloud services and often contains a tremendous amount of geo locations with time stamps, health data, steps and stair count with additional user statistics.
Oxygen Forensic® Detective’s powerful 64-bit forensic architecture allows investigators to quickly parse volumes of data and leverage advanced analytical tools, like Social Graph, Timeline, Facial Recognition, and more to quickly identify critical evidence. Oxygen Forensic® Detective delivers parsing and decoding of data three times faster than the leading competitor to support massive data sets from mobile devices, backups, drones and cloud services. This powerful tool also offers a multi-tab user interface so working with several sections simultaneously will allow effortless data comparing.
Oxygen Forensic® Detective offers the ability for investigators to categorize human faces. The facial recognition is available in the Faces section at no additional charge. The unique features include: industry leading accuracy (as measured by NIST), detailed face analytics (gender, race, emotion, and more), immediate categorization and matching (5 faces/second) and support for massive volumes of data. Using the built-in facial recognition investigators will spend less time looking through thousands of photos or videos in mobile, cloud or drone extractions.