Reveal same people in different sources and merge them in one meta contact for efficient analysis
Extract, decrypt and examine user data from popular Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness and Multimedia apps
backups and images import
Import and parse various backups and images made from iOS, Android, Windows Phone and Blackberry devices
Applications section displays user data extracted and parsed from popular Social Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness and Multimedia apps. You can view app account details, contacts, messages, calls, logs, cache and other data. The software decrypts evidence even from Private Messengers and other secure apps.
Customize and generate data reports to PDF, XLS, RTF, XML and other popular file formats
Perform search in a single device or in a case. Apply various search criteria including keywords, regular expressions and credit card numbers search
Automatically recover deleted records and files: contacts, calls, messages, notes, photos, videos, SQLite databases and other vital evidence
Oxygen Forensic® software enables export of data from any section to popular file formats: PDF, RTF, XLS, XML, HYML, etc. This can be a report of the whole device, several devices, several sections or even several entries. Reports are highly customizable to fit every possible need. XML reports can be integrated into other analysis software.
Oxygen Forensic® software has a powerful built-in interface for data search. Searching can be conducted on all devices, case level and device level. You can search data according to the information entered in the input field, by keyword lists, using regular expressions or choosing any other available method. Search is launched as a separate process so you are free to work with the software during the search process
Oxygen Forensic® software recovers a wide range of deleted evidence: contacts, messages, calls, notes, user data from applications from SQLite databases, It is also capable to recover photos, videos, databases and files from physical images of Android and Windows Phone devices. All recovered evidence is marked with a special trash bin icon for you to easily identify it.
view the detailed information about the device and its owner
View dialed, answered and failed calls including deleted ones. Apply filters to show calls only for a specific period of time
Access devices photos, audio and video files, databases and other acquired evidence. View any file in a raw, hex mode, or run appropriate player for the media content
Extract and view geo coordinates from various sources: applications data, photo and video EXIF headers, history of Wi-Fi connections, etc
Mark important entries as key evidence in any program section and view them later in a single list
Create and use keyword lists to quickly find the relevant data during or after data extraction
Oxygen Forensic® software collects geo data from various sources: photo and video EXIF headers, web connections information and applications databases. Geo coordinates can be extracted both from mobile devices and cloud services. The full list of geo points can be found on Geo Timeline tab in Timeline section. Oxygen Forensic® Maps can be opened from this section to view the coordinates.
Key Evidence section displays events marked in other program sections as important. The function of the section is to put the entries that can be used as evidence relevant to a certain case in the same place to make the data analysis easier. You can bookmark important evidence in one or several devices and export it later to one data report.
Explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities
live data extraction
Extract data from mobile devices based on iOS, Android, Windows Phone, Windows Mobile, Blackberry, Bada OS or feature phones. Additionally, acquire device media and SIM cards
Gain access to SMS, MMS, Email and iMessage communications and read them either in Table or Chats view
Oxygen Forensic® software provides several tools to explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities. You can use either a Graph or Diagram view to determine social links, find the closest circle of communication and analyze communication statistics.
Oxygen Forensic® software offers both logical and physical methods of device acquisition via a regular USB cable. The program supports thousands of devices running iOS, Android, Windows Phone, Windows Mobile, Blackberry, Bada, Symbian OS or having no OS at all (feature phones). Support for Chinese MTK and Spreadtrum chipsets is also available. Additionally, you can extract and recover data from media and SIM cards via specialized readers.
Extract and recover user’s calendars, notes and tasks. Decode iOS encrypted notes
Decrypt passwords and authentication tokens to user accounts in Social Networks, Messengers and Email apps. Reveal passwords that were used to connect to Wi-Fi networks
View all phonebook information including names, phone numbers, email addresses, notes, birthdays, creation and modification dates
Passwords section displays logins, passwords and tokens extracted iOS, Android and Windows Phone devices. The program decrypts credentials from the iOS keychain, finds them in application databases and web forms. You can find passwords to various application accounts as well as passwords used to connect to WiFi networks.
Phonebook section presents the complete information about the device contacts - phone and SIM card contacts, their standard and customer fields, speed dials and birthdays, creation and last modification dates. The section offers rich sorting and filtering capabilities and allows to generate data reports with all or selected contacts.
Open and examine. plist files found in iOS device extractions. Use Converter panel to convert values into a readable format
Examine SQLite databases, recover deleted data, convert values, build SQL queries, perform search and export selected entries to reports
Discover spyware that might be running on mobile devices and analyze its logs and configuration files
The built-in Oxygen Forensic® Plist Viewer offers convenient analyzing of Plist files: you can open plain XML and binary XML files, view entries according to their type (string, data, numbers etc.), convert values, open external files for analysis, export .plist file data in XML format for further analysis by external tools.
The built-in Oxygen Forensic SQLite Viewer is a powerful tool that allows examining of SQLite files and studying their contents. With this tool, you can open any SQLite database, recover deleted records, convert values to a readable format, build visual SQL queries and save them for further use, run search and finally export selected entries to data reports.
Oxygen Forensic® software can detect spyware apps installed on Android and Apple devices, discover and process their logs and configuration files. Spyware log files may include application configuration data, the list of running services, application username, sometimes accompanied with a unique code allowing to detect the app, Cell ID used at the time of data transmission, and GPS logs accompanied with Geo-coordinates and a timestamp.
View all events in a chronological order: chats, calls, voicemails, photos and videos history, wi-fi connections, geo files and web cache
Find out when and where the device owner used Internet access and gather information about frequent locations of iOS users
Parse user’s emails from webmail interface and content of visited webpages. Gain access to email messages, web search history, locations and other data stored in WebKit databases
Timeline section summarizes all events in chronological order: calendar events, messages, calls, web cache, web connections, voicemails, photos and videos history, etc. The section offers you a number of powerful filters and convenient data presentation modes that permit you to concentrate on the analysis of the needed data only. It also graphically shows the peaks of user activity.
Web Connections section presents the history of Web connections (Wi-Fi, GPRS, LTE) in one list and shows the place where the Internet was used. The information about every Wi-Fi hotspot includes its name, Mac address, time of the first and last connections. The program also displays the list of frequent locations extracted from iOS devices.