Oxygen Forensic Detective (includes 12 months of updates) has full Unicode support - you can easily view and extract information in any language. Device Information: Device information section displays complete technical information about the device. Here experts can find a brief statistics of the device, the number of entries in each section split by data type and quickly move to the needed data. Section also summarizes and displays user accounts gathered through all data extracted from the device. To make device recognizable in the database, forensic experts add device/user photos and brief description of the item.
Depending on the device experts gain access to the private information of the contacts, like birthdays, relatives' names and anniversaries. Section provides convenient way to find information using Quick filter. Found contacts will appear immediately once expert starts typing query.
Favorites and Birthday Center are the tools that indirectly points to the important contacts. Experts can customize report layout and then easily print or export all marked or filtered contacts.
Important contacts can be marked as Key Evidence and then analyzed separately with additional marked data. Plist Viewer Plist files, known as Property List XML Files, contain a lot of valuable forensic information in Apple devices. While plain-text Plist files have XML-like structure and can be viewed in a text viewer, binary Plist file requires decoding before analysis. Oxygen Forensic® Plist Viewer offers convenient analyzing of device data. Parse plain XML and binary XML files.Plist Viewer runs automatically when opens compatible file. Shows entries according to its type: string, data, numbers etc. Ability to open external files for analysis.
Plist file data in XML format for further analysis by external tools. Messages Messages section contains users' correspondence including SMS, MMS, Emails, iMessages and other depending on the device type. Recovering deleted messages is available for certain types of devices: iOS, Android OS and Symbian OS smartphones.There are a lot of messages in seized devices usually. Messages section provides convenient way to analyze them: quick filter on toolbar, context filters in grid headers, folders tree view. These tools help exerts find needed data and prepare it for report. Experts can preview generated report, customize its layout if needed, and then print or export messages with or without attachments. Using built-in viewer experts can analyze attachments and technical headers of the message.
Each attachment can be saved in a separate file for future analysis. Navigation Oxygen Forensic® Suite grants the access to popular Navigation applications and reveals POIs, routes and searches that device user made. Navigation section in Oxygen Forensic® Suite allows to analyze the places that the device user was looking for, headed to and visited. Modern smartphones offer a lot of additional features based on geo-services, but searching for a certain place, finding the best route, acquiring current location are still the most usable ones. User can easily find himself on the map, find the place and even build a route with his smartphone.Oxygen Forensic® Suite allows investigators to analyze all activity that corresponds to these actions. In Navigation section investigators find the sheets of. And in Oxygen Forensic® Suite investigators can view all the points and locations that suspect checked. Oxygen Forensic Maps Oxygen Forensic® Detective acquires geo coordinates from all possible sources including: mobile devices, cloud storage, media cards, and imported images. Once analyzed, the data can be viewed within both online or offline maps. The brand-new Oxygen Forensic® Maps offers advanced analytical capabilities for geo data including. Identify device owners frequently visited places.
Visualize users movements within specified period of time. Pinpoint common locations of several device users. Smoothly work with large data sets of geo points Passware Kit Module: Passware Kit Mobile Module enables straightforward data acquisition and decryption regardless of the data source: smartphone, tablet, cloud service or backup file. Current version offer the following capabilities. Acquire full iPhone, iPad and iPod Touch backups from iCloud provided that the Apple ID credentials are known.
Recover passwords for: - iTunes backups - Android backups - Android physical images The module helps to find passwords with latest algorithms and technologies including distributed processing and GPU acceleration with ATI and NVIDIA boards. Event Log Event Log section contains users' voice communication: dialed, received and missed calls. Experts find here call time, duration and remote party.Recovering deleted calls is available for certain types of devices: iOS and Android OS smartphones. These are quick filter on toolbar, context filters in grid headers, date filter on sidebar. These tools help exerts find user calls at a certain period of time, call direction or communication with a contact.
When the call event doesn't have the name of the caller, Oxygen Forensic® Suite looks for this data in Phonebook. Calendar & Tasks Organizer section displays notes, tasks, and calendar entries created or synchronized by device user. Calendar is the most data-rich part of organizer. Events have text label, location, start date, end date, alarm and recurrence.
Notes are the entries with large text fields and time stamp. Tasks are the kind of calendar events that have special Done flag to mark the state of the item. In Oxygen Forensic® Suite experts get access to all these types of data in a convenient sheet-like view.
Quick filter and sorting capabilities helps to find and analyse data. Special Time Zones tool converts dates to a local or any other time zone.
Built-in text, hex, multimedia, SQLite, Plist viewers, Geo-location and EXIF extractors help experts to view files and their properties. Additionally experts can view files in selected only folders, grouped in tabs by type, or in search tabs created when Quick filter was applied. Oxygen Forensic® Suite automatically extracts Geo-location data from multimedia files and offers shortcut to view the place on the map where the action took place.Additionally, it looks into EXIF headers for specific tags like Make, Model, time stamps which helps forensic experts to determine file origin. Basic data about the file is displayed on the left sidebar, while file attributes and additional tags are available via popup menu. Section has a two-panel multipurpose viewer, where experts view the file in a raw, hex mode, or run appropriate player for the media file. Additionally, double clicking on a file opens appropriate viewer in a separate window. Databases and configuration files will be opened with built-in Oxygen Forensic® SQLite Viewer and Oxygen Forensic® Plist Viewer. Investigators can save files, whole folders on PC, mark the items as Key Evidence, print and prepare reports, export Geo data to Google Earth. Reports When it comes to solving a crime, reports are one of the most important things for the investigator. Popular file formats and ability to export or print the whole set of data or only important parts helps experts to show the result of their work in the best way. In Oxygen Forensic Detective forensic experts can export any data from any section. This can be a report of the whole device or several sections or even several entries. Everything depend on the need of the investigator.
We support all popular file formats: Adobe PDF, Microsoft Excel, HTML, Rich Text Format (RTF), and XML. Each format has own best place to apply. For example, PDF is good for printing, while XML can be used by 3rd party data parsers to import data extracted by Oxygen Forensic® Suite. Reports section is a place where expert can find reports generated for selected device with brief data about the report: date of creation, sections in the report, its path and name.Section also can check if the report was changed after generation and let expert know about it. Screen Lock Disabler With locked devices being a top forensic problem we are doing our best to invent new methods to recover digital evidence even in the most challenging cases. Screen Lock Disabler allows to disable user lock code on Samsung devices based on Android OS and get access to the critical data. The procedure takes several minutes and requires no special knowledge or training. It is enough to have MTP driver and regular USB cable for disabling the lock How it works. Download and install Screen Lock Disabler. Connect locked device via USB cable to PC.
Select the device from the list and press Unlock button. Turn off the device screen and then turn it on. Swipe the screen with your finger to disable the lock.The screen lock will be disabled and you will get access to all the user data. Where to find: At the moment Screen Lock Disabler is available to Oxygen Forensic® Detective users. Skype & Messengers Oxygen Forensic® Suite supports a lot of mobile messengers like Skype, Facebook, WhatsApp, Viber and others. Oxygen Forensic® Suite retrieves all available data from messengers.
Depending on the application the feature set may vary. Chat history with individuals (including unauthorized contacts) and groups. Contact list with photos, all fields and notes. Geo-location where the action took place Aggregated Contacts Analyze contacts from multiple sources such as the Phonebook, Messages, Event Log, Skype, chat and messaging applications in Aggregated Contacts. Section automatically reveals same people in different sources and groups them together in one meta-contact.When the contacts have no matches, but forensic expert detected that the contacts in various sources belong to one person, he can manually merge these contacts. Later this contact will be used as a single item for Links and Stats analysis. Section offers quick filter functionality, convenient data sources filter and sorting for faster analysis. Preparing and printing reports is easy as in every section of Oxygen Forensic® Suite. Android Rooting Rooting a device based on Android OS reveals the complete set of user data to the investigator. Generally this procedure needs certain knowledge and research, but Oxygen Forensic® Suite helps experts to automate this operation. Rooting procedure is a part Data Extraction Wizard that guides you through the whole process of gaining the root rights to the device. The important benefit of the proprietary method is that the root access will be revoked immediately after rebooting the device. This method makes rooting and further extraction completely forensic and safe. Android Rooting add-on grants an access to. Full file system, stored both on internal memory and memory card.
Application saved data including logins, passwords, history, cache and much more. Geo-location information for tracking suspect position in the past. Deleted data in database tables No 100% successful rooting is guaranteed.The procedure is available for the most of Android devices with versions 1.6 - 2.3.4 and 3.0 - 4.2.2. Applications Oxygen Forensic Detective retrieves numerous application data from a mobile device.
In the Applications section, forensic experts view the list of pre-installed and user applications with the files created by these programs. Each application can contain valuable user data, like passwords, logs, history, files and so on. Section offers the following main features. Get logins and passwords to the app.
Find geo-location of the last run. Inspect all used or created app files. Know exactly when the app was used. Access to system and user apps. Filter apps by a certain term.
Export and print selected items Many popular applications have a special User Data data tab where investigators find application data categorized and prepared for effective analysis. Forensic experts can always access source files to learn how Oxygen Forensic Detective gathers information for User Data tab or to analyze applications that were not automatically prepared.
Navigation Oxygen Forensic Detective grants the access to popular Navigation applications and reveals POIs, routes and searches that device user made. Spyware Oxygen Forensic® Suite can detect spyware apps installed on Android and Apple devices, discover and process their logs and configuration files. Backups import Oxygen Forensic® Suite Analyst allows to import and parse data from various device backups and images created by sync software or other forensic products. Oxygen Forensic® Passware® Analyst and Oxygen Forensic® Suite Passware Edition can additionally find passwords that encrypt Apple iOS and Android backups and images. Supported Apple iOS backups and images: iTunes backup, iCloud backup, non-encrypted Apple DMG image, UFED DMG image, UFED file system backup, UFED Advanced Logical backup, XRY DMG image, decrypted/encrypted Elcomsoft DMG image, decrypted/encrypted Lantern DMG image, Apple tarball backup.
Supported Android OS backups and images: Android backup, Android physical/JTAG image, Android file system tarball backup, UFED physical image, UFED Android file system backup, Nandroid backup (CWM, TWRP). Supported BlackBerry OS backups: BlackBerry IPD, BlackBerry BBB and BlackBerry 10 backup. Supported Nokia backups: Nokia NBU and Nokia MBK. Blackberry Backups BBB and IPD are the Blackberry device backup files made with Blackberry Desktop Manager. These files can be found on a suspect computer or external media like CD, DVD, memory disks and cards etc.
Oxygen Forensic® Suite is able to extract and present forensically important information from these backup files. ITunes Backup iTunes backup found on a suspect computer is a regular practice due to the popularity of Apple devices. Oxygen Forensic® Suite offers experts an easy way to extract suspects' private data from the iTunes backup files. BlackBerry Backups BBB and IPD are the Blackberry device backup files made with Blackberry Desktop Manager. Oxygen Forensic® Suite is able to extract and present forensically important information from backup files and chip-off images.Oxygen Forensic® Suite imports and parses all data from BlackBerry 10 Chip-off images. Chip-off technique is considered to be the last-option method to get a device memory image. It can be used to extract crucial evidence when the device is locked or damaged and all other forensic options have been already exhausted. At the same time Oxygen Forensic® Suite is able to extract and examine data stored in backup files made by a suspect. Opening backup file gives an expert an access to all information stored in it: contacts, calendar, tasks, event log, messages, photos, videos, documents, etc. Oxygen Forensic® Suite grants an access to the raw data of IPD/BBB file also. Expert can view all the data in a separate Blackberry Source Tables section. It opens data in a table view showing all fields and values of a database file. For the more convenience the tool has a content-dependent field-viewer that is able to present data basin on its type: text, media, etc. Oxygen Forensic® Suite became the industry first software with ability to extract data from BlackBerry 10 devices! Call Data Records Oxygen Forensic® Call Data Expert is a forensic program that allows importing and analyzing CDR files (Call Data Records) received from mobile service providers regardless of the difference in their column formats and file layouts.
The supported file formats are. There are no file size limits. Oxygen Forensic® Call Data Expert conveniently guides through the process of call data records file importing and fields mapping that is required to convert the file into unified format. Afterwards the processed results can be viewed and analyzed by the expert allowing to build direct and indirect links between callers on the graph.
Processed and analyzed results can be saved to external files on PC Oxygen Forensic® Call Data Expert is available in Oxygen Forensic® Detective at no additional charge. Watch Oxygen Forensic® Call Data Expert guide. Download Oxygen Forensic® Call Data Expert help manual.
Oxygen Forensic® Suite is able to acquire from Chinese devices important user data like event log, messages, contacts and files. In emerging markets, Chinese-branded phones dominate in the low-budget niche. Oxygen Forensic Detective handles a huge variety of devices based on MTK (Mediatek) chipset and grants forensic access to the following user data. This including IMEI/IMEI2, hardware revision, firmware revision and baseband.Supported event types: Meeting, Call, Anniversary, Birthday, Training, Reminder, Notes. Call Log Includes dialed, answered and missed calls. Messages: SMS and MMS in default folders. Cloud Data Extraction Oxygen Forensic® Detective acquires data from more than 15 cloud storages: iCloud contacts and calendar, Google Drive, Google Location History, Live contacts and calendar, OneDrive, Dropbox and Box as well as from a wide range of social media including Twitter and Instagram. Forensic experts may utilize either account credentials or token to enter the cloud account to acquire the cloud data. Extracted credentials and tokens from a mobile device are organized and displayed in the Passwords section of Oxygen Forensic® Detective. After the cloud data is acquired it can be viewed in Oxygen Forensic® Detective and merged with other extractions for deep data analysis in Timeline, Social Graph and other analytical tools.
Data Viewers Various data viewers help experts to analyze extracted data in a convenient way. Oxygen Forensic® Suite has built-in HEX-viewer, picture viewer, music and video players, text viewer with code page converter, HTML, SQLite and Plist Viewers. Modern mobile devices create numerous number of files during their life cycle. The very basic tool to open them is HEX viewer that will allow analyzing data in a raw manner.
Built-in HEX viewer in Oxygen Forensic® Suite allows experts to search data, make bytes conversions of the selected parts, save files on disk. In case of multimedia files it is convenient to use built-in media player that will allow to play recorded video and voice messages, and view camera shots. Additionally, forensic experts can view EXIF information and Geo-data if they are available. SQLite Viewer SQLite Viewer allows to explore the database files with the following extensions.
Experts have the access to the actual and deleted data stored in databases created by system and user applications. Dictionaries Dictionaries section shows all the words ever entered in device messages, notes and calendar. These are not words from the device system dictionary, they are from unique user dictionary that is created by device owners when using it. View all words entered by a suspect. Choose certain language on demand.
Find out each word usage frequency. Reveal the order words were used. Export and print selected items Dictionaries section provides a list of words entered by a suspect. Forensic expert can determine the order that the words appeared, how often the word was used, filter and reorder the words in the list. Phrase simulation feature is a highly valuable tool for an expert.
Using it he can suppose the phrases that the suspect typed. This can be a password, address, or even a deleted message.
Global Search Global Search allows discovering user data in every section of the device. Regular expressions library is available for more custom search. Forensic experts can search data in a single device, all devices of the case, or all acquired devices. They can choose the sections where to search the query, apply boolean terms, or chose any of predefined patterns.
Keyword list manager allows creating custom set of terms and perform search for all these terms at once. For example, these can be the lists of names or the set of offensive words and phrases. Global Search tool saves all results and offers printing and preparing reports for any number of searches. Oxygen Forensic® Suite is able to extract and examine data stored in backup files made by iTunes.
Opening backup file gives an expert an access to all information stored in it: contacts, calendar, messages, photos, videos, documents, etc. Both password-protected and non-protected backups are supported. If expert knows the password he can just type it, if not Oxygen Forensic® Suite suggests to use a 3rd party tool to collect the password. You can browse the data, perform context and global search, export and print reports. Key Evidence Key Evidence section offers a clean, uncluttered view of evidence marked as essential by investigators.Forensic specialists can mark certain items belonging to various sections as being essential evidence, then review them all at once regardless of their original location. Key Evidence is an aggregated view that can display selected items from Phonebook, Calendar, Messages, Camera shots, Web Connections and Location Services, Applications, as well as other sections available in Oxygen Forensic® Suite.
The section offers the ability to review relevant information at a single glance, concentrating ones efforts on what really matters and filtering out distracting, unimportant data. Forensic examiners are able to sort, filter and group data for the best viewing results. Tagging and notes makes Key Evidence section even more convenient to use. Links and Stats Quickly reveal social connections between users of mobile devices under investigation and their contacts. Diagram view with a graphical chart presents a quick overlook of communication circles, allowing forensic experts to determine and analyze suspects communications with all details at a glance.
Along with communication duration it produces a concise summary of the forensically important data. Oxygen Forensic® Suite offers investigators the ability to analyze interactions among users of multiple seized mobile devices. The feature builds and displays a Links and Stats diagram with a chart for multiple devices, clearly visualizing connections between the phones users.
Passwords Passwords section displays logins and passwords extracted from default secure storage like keychain database. Applications files can also contain this valuable data. Oxygen Forensic® Suite parses them for it and displays nearby Password recovery is available for iOS and Android devices. In Apple iOS devices including iPhone and iPad, sensitive information is stored in the keychain. The content is stored securely encrypted with device-specific hardware keys that are unique to each individual device.Oxygen Forensic® Suite adds the ability to access protected content stored in the keychain, extracting and displaying user passwords. More passwords are hidden in applications files. Passwords section also extracts this data and displays passwords from applications at one place. Social Graph Social Graph visualizes complex connections inside crime groups.
This is a highly adjustable workplace that allows forensic experts to review connections between mobile device owners and their contacts, pinpoint connections between multiple device owners, and detect their common contacts. Oxygen Forensic® Suite builds Social Graph basing on communication activity of device owners.The graph is not static, experts are free to manipulate the way it looks like by moving, hiding and merging contacts. Investigator can also change the date range to reveal most popular connections in a certain period of time or/and set the minimum number of connections for the contacts to be displayed. Social Graph contains information about each displayed owner and contact like preferable types of communication, the first and the last date of communications, total time spent in talk and number of messages sent each other.
Additionally, forensic expert can the change layout of the graph using mouse and keyboard shortcuts, view it in full-screen mode, save to a file for future reports. Information retrieved from log files created by spyware applications may include application configuration data, the list of running services, application user name, sometimes accompanied with a unique code allowing to detect the app, Cell ID used at the time of data transmission, and GPS logs accompanied with Geo-coordinates and a timestamp.
By analyzing spyware logs, forensic specialists may gain access to additional information that could be used at the time of investigation. SQLite Viewer for Oxygen Forensic® Suite offers convenient analyzing of device data. Shows data in a convenient table view. Blocks of deleted data examination. Opportunity to recover clusters of deleted records.
Export to RTF, PDF, XML, XLS, SV, TSV and HTML file formats. Ability to save big BLOB fields in a file. Full Unicode and UTF-8 support.
Automatic hash calculation in the status bar for analyzed files. Grid view cells and lines can be copied to Windows Clipboard. Nokia dates conversion to readable view. Unix and iOS date conversion to readable view. Support for OS X Epoch format conversion.Timeline Timeline allows to view all facts of mobile device usage in one sorted list. This section organizes all calls, messages, calendar events, geo data and other activities in chronological way, so you can easily follow the conversation history without the need to switch between different sections. Timeline is available for a single device and for all devices belonging to a case, revealing the complete event list occurred. A graphical chart is available to display user activities for selected periods of time. The chart allows grouping all possible mobile device events over different time intervals (from one second to one year) and filtering them by various parameters. The chart enables forensic experts to easily analyze detailed activities of a single contact or group of contacts at a glance. Printing and exporting data in popular formats is also available in Timeline section. Web Browsers Oxygen Forensic® Suite supports all popular Web browsers for Android OS, Apple iOS, BlackBerry OS and Symbian OS platforms. Surfing Internet on a mobile device is ordinary today. Mobile devices of all types offer such an ability to their owners. Oxygen Forensic® Suite allows investigators to extract and examine data in mobile web browsers (preinstalled as well as 3rd party ones) and analyze user activities over the Internet. The following data is usually available for analysis. Geolocation Web browsers offers a variety of features like sorting, filtering, searching entries. Advanced file viewer helps to review cache content in a proper way: play video, sounds, view files in different codepages HEX or Web mode. Once the connection is established Oxygen Forensic® Suite starts data acquisition. Current version extracts contacts and messages. First of all, not all data is available for browsing even after logging in to the account.
Secondly cloud stores information in a complex format, making manual forensic analysis of this data complicated and practically unfeasible. On the other hand, Oxygen Forensic® Suite will extract, parse and classify every bit of user data stored in the cloud. Like data extraction from a backup file, expert won't need to have the access to the device itself. Web Connections & Locations Web Connections & Locations section reveals suspects' visited places and routes.
Experts can analyze several sources of Geo data: Wifi connections, IP connections and Locations databases. With Wi-Fi Connections list forensic experts are able to determine where and when suspect used Wi-Fi internet access (public or even private) and ascertain his location. Entries in hot spot list have the following parameters: hotspot name (SSID), hotspot BSSID (MAC-address) and RSSI (Signal level), last time when suspect used hotspot.
Processing this data Oxygen Forensic Detective acquires geo-coordinates and mini-maps for each location. IP Connections tab shows all the history of Web connections (Wi-Fi, GPRS, LTE) and their details: MAC and VPN addresses, device and router IPs, DNS name, region, time stamp, etc. Db files contents in an extremely convenient way. Initially these files store all the network activity of the device basing on GPS/Cell/Wi-Fi data. Experts can track device movements and determine device owner location basing in Locations data.Experts can view geographical coordinates and maps directly in Oxygen Forensic Detective or export data to KML format to see the route in Google Earth application. Standard reporting and printing features available. More than 2500 mobile device models are supported. And the list is rapidly growing!
Using low-level protocols and straight access to phones allows Oxygen Forensic Suite not to be limited by GSM models, but also support CDMA and DAMPS phones! PLEASE NOTE THAT THIS IS A DIGITAL CODE , YOU WONT GET A CD! You will get the download link for. The item "Oxygen Forensic DetectiveFull Version Lifetime Windows Instant" is in sale since Monday, November 18, 2019.This item is in the category "Computers/Tablets & Networking\Software\Operating Systems". The seller is "freemium007" and is located in Addison, Texas.
This item can be shipped worldwide.