oxygen forensic®

analyst

features

o_f_analyst
f5a5f28e8aa4832609fec2250f3bace3

aggregated contacts

Reveal same people in different sources and merge them in one meta contact for efficient analysis

cbd71a67f964d0a83dd802afbbd7e0cb

applications

Extract, decrypt and examine user data from popular Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness and Multimedia apps

8b82c4a9c5a8b32e044647c08c2a05b7

backups and images import

Import and parse various backups and images made from iOS, Android, Windows Phone and Blackberry devices

4543cd786f7614b45de494bccc54671d

Aggregated Contacts section displays contacts obtained from various sources: standard phonebook, calls log, messages and application databases. Contacts with the same fields are merged into one meta-contact. Aggregated Data can be used at both the case level and device level of the examination.

544f8368240e6cce9edc89bb9f12ae50

Applications section displays user data extracted and parsed from popular Social Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness and Multimedia apps. You can view app account details, contacts, messages, calls, logs, cache and other data. The software decrypts evidence even from Private Messengers and other secure apps.

85efb4e02ed588b30ca0b472cd4c8b8d

Oxygen Forensic® software imports and parses dozens of various device backups and images created in official device software, third-party programs or other forensic tools. You can import iTunes, ADB and Nokia backups, JTAG, CHIP-Off and Nandroid images, XRY and UFED images and many more.

f3faf40e29a13350e32e5ad118a89d5b

data reports

Customize and generate data reports to PDF, XLS, RTF, XML and other popular file formats

bb28a9cbdcafccc90b920171aaf55126

data search

Perform search in a single device or in a case. Apply various search criteria including keywords, regular expressions and credit card numbers search

f608758859d220df2738510db7a20ba6

deleted data

Automatically recover deleted records and files: contacts, calls, messages, notes, photos, videos, SQLite databases and other vital evidence

00b0047c17e036711598479fbf3e85d1

Oxygen Forensic® software enables export of data from any section to popular file formats: PDF, RTF, XLS, XML, HYML, etc. This can be a report of the whole device, several devices, several sections or even several entries. Reports are highly customizable to fit every possible need. XML reports can be integrated into other analysis software.

54b3256d99b5f6fc8ae424d3eb712e99

Oxygen Forensic® software has a powerful built-in interface for data search. Searching can be conducted on all devices, case level and device level. You can search data according to the information entered in the input field, by keyword lists, using regular expressions or choosing any other available method. Search is launched as a separate process so you are free to work with the software during the search process

a5f6da386630cdb03a5fb5f32ac76293

Oxygen Forensic® software recovers a wide range of deleted evidence: contacts, messages, calls, notes, user data from applications from SQLite databases, It is also capable to recover photos, videos, databases and files from physical images of Android and Windows Phone devices. All recovered evidence is marked with a special trash bin icon for you to easily identify it.

7f24e98eee827d85272f57f76d993696

device information

view the detailed information about the device and its owner

707b6ff29cc949ecc3c1dccee2de9443

event log

View dialed, answered and failed calls including deleted ones. Apply filters to show calls only for a specific period of time

d2f0a14bd89ef5179f1120b7492b9490

file browser

Access devices photos, audio and video files, databases and other acquired evidence. View any file in a raw, hex mode, or run appropriate player for the media content

d85f58a02d1bb5cabc9b1ffafcf14043

Device information section gives you the general information about the acquired device. It shows various attributes, like the device, SIM and network information, phone numbers and case details. You can also find the summary of all device owner’s accounts with the login and password information.

514890ac98f1603a5985868c1c397e4e

Event Log section provides access to phone and FaceTime calls as well as messages and packet data. You can apply time filters to view calls only for a particular period. The section allows to export all or selected data to PDF, RTF, XLS, XML and other types of reports.

d18681570a14d8836c602407fd7041f7

File Browser section grants access to user’s photos, videos, documents and device databases. Built-in Text, Hex, Multimedia, SQLite and Plist viewers allow to examine files and their properties. Rich filtering and powerful search help to focus only on the required evidence.

45ef2aedf84f2c0981a05d7b350e9aed

geo data

Extract and view geo coordinates from various sources: applications data, photo and video EXIF headers, history of Wi-Fi connections, etc

d3b7d56cbe63ef9e7d442410afe5a08a

key evidence

Mark important entries as key evidence in any program section and view them later in a single list

333fd9d8d4e71eb02cdb044881769e03

keywords search

Create and use keyword lists to quickly find the relevant data during or after data extraction

32330601b78f2b7329660a586ab194f3

Oxygen Forensic® software collects geo data from various sources: photo and video EXIF headers, web connections information and applications databases. Geo coordinates can be extracted both from mobile devices and cloud services. The full list of geo points can be found on Geo Timeline tab in Timeline section. Oxygen Forensic® Maps can be opened from this section to view the coordinates.

e8f0d14f658e2984fb86e1c2f80c0d47

Key Evidence section displays events marked in other program sections as important. The function of the section is to put the entries that can be used as evidence relevant to a certain case in the same place to make the data analysis easier. You can bookmark important evidence in one or several devices and export it later to one data report.

e76c89531a90a4219d771125c54ba4ab

Oxygen Forensic® software allows creating and using keyword lists to quickly reveal the required evidence. You can enter keywords or import them from a .txt file before data extraction to receive the results once the extraction process is completed.

9d72c61de1a47d3f45a8c3d9dbea7591

link analysis

Explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities

0598af69950c4c98957469e417403d62

live data extraction

Extract data from mobile devices based on iOS, Android, Windows Phone, Windows Mobile, Blackberry, Bada OS or feature phones. Additionally, acquire device media and SIM cards

e58ec3589cce74496881cde0c58c32da

messages

Gain access to SMS, MMS, Email and iMessage communications and read them either in Table or Chats view

c3f3611b735d806c7b35813c2cb38fe8

Oxygen Forensic® software provides several tools to explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities. You can use either a Graph or Diagram view to determine social links, find the closest circle of communication and analyze communication statistics.

b40d553755976d7ca6c3cd8f9c5b3e1e

Oxygen Forensic® software offers both logical and physical methods of device acquisition via a regular USB cable. The program supports thousands of devices running iOS, Android, Windows Phone, Windows Mobile, Blackberry, Bada, Symbian OS or having no OS at all (feature phones). Support for Chinese MTK and Spreadtrum chipsets is also available. Additionally, you can extract and recover data from media and SIM cards via specialized readers.

8c27a5a26616efb7c357419269f5e736

Messages section gives you access to SMS, MMS, iMessage and E-mail messages (with the attachments) in the device. You can read conversations either in Table or Chats view. Export button allows to send all or selected messages with attachments to data reports.

87e0d14eedaac64553ff31a3c4f9da99

organizer

Extract and recover user’s calendars, notes and tasks. Decode iOS encrypted notes

de5b38dace22747a0f47dbaa7c046c06

passwords

Decrypt passwords and authentication tokens to user accounts in Social Networks, Messengers and Email apps. Reveal passwords that were used to connect to Wi-Fi networks

b11ac979c148eeb919dcf6cbb4a65781

phonebook

View all phonebook information including names, phone numbers, email addresses, notes, birthdays, creation and modification dates

024e92ecdc632c3499791df71a6e3ff8

Organizer section displays the detailed information about calendar events, notes and tasks. The program can decrypt notes created and encrypted in Apple devices running iOS 9.x and 10.x. Data reports can be customized and generated in any of supported file formats.

63de3fff1bb84f0afb2a7771e8b7abb2

Passwords section displays logins, passwords and tokens extracted iOS, Android and Windows Phone devices. The program decrypts credentials from the iOS keychain, finds them in application databases and web forms. You can find passwords to various application accounts as well as passwords used to connect to WiFi networks.

12c60b4c610c21ed6642d7e72a5f823e

Phonebook section presents the complete information about the device contacts - phone and SIM card contacts, their standard and customer fields, speed dials and birthdays, creation and last modification dates. The section offers rich sorting and filtering capabilities and allows to generate data reports with all or selected contacts.

ee8a21d16eabe5a0de880ebe6483f1cc

plist viewer

Open and examine. plist files found in iOS device extractions. Use Converter panel to convert values into a readable format

be642d8dbc95ab3f3529bf06509ba282

sqlite viewer

Examine SQLite databases, recover deleted data, convert values, build SQL queries, perform search and export selected entries to reports

8b567c965e2db57605543eff70ce654e

spyware

Discover spyware that might be running on mobile devices and analyze its logs and configuration files

866ba81685597b02cb0a48047a692e9b

The built-in Oxygen Forensic® Plist Viewer offers convenient analyzing of Plist files: you can open plain XML and binary XML files, view entries according to their type (string, data, numbers etc.), convert values, open external files for analysis, export .plist file data in XML format for further analysis by external tools.

ba459291063f77706bbc2e500573958d

The built-in Oxygen Forensic SQLite Viewer is a powerful tool that allows examining of SQLite files and studying their contents. With this tool, you can open any SQLite database, recover deleted records, convert values to a readable format, build visual SQL queries and save them for further use, run search and finally export selected entries to data reports.

16d662859f195ac98d86b35f3003a914

Oxygen Forensic® software can detect spyware apps installed on Android and Apple devices, discover and process their logs and configuration files. Spyware log files may include application configuration data, the list of running services, application username, sometimes accompanied with a unique code allowing to detect the app, Cell ID used at the time of data transmission, and GPS logs accompanied with Geo-coordinates and a timestamp.

077c405a6435353d5514353ae71ac52d

timeline

View all events in a chronological order: chats, calls, voicemails, photos and videos history, wi-fi connections, geo files and web cache

d9f804d6078a9216ea89dbe0552cc6da

web connections

Find out when and where the device owner used Internet access and gather information about frequent locations of iOS users

6d5d822a19422404b0f0277b83ba3ce6

webkit data

Parse user’s emails from webmail interface and content of visited webpages. Gain access to email messages, web search history, locations and other data stored in WebKit databases

96bc36bb17c981e6761d37ff02879672

Timeline section summarizes all events in chronological order: calendar events, messages, calls, web cache, web connections, voicemails, photos and videos history, etc. The section offers you a number of powerful filters and convenient data presentation modes that permit you to concentrate on the analysis of the needed data only. It also graphically shows the peaks of user activity.

c105ddec6b9bf3d80339ed4807a111d0

Web Connections section presents the history of Web connections (Wi-Fi, GPRS, LTE) in one list and shows the place where the Internet was used. The information about every Wi-Fi hotspot includes its name, Mac address, time of the first and last connections. The program also displays the list of frequent locations extracted from iOS devices.

4f2d9d3d09feeab8b43833b693f1b018

WebKit Data section shows user’s emails from webmail interface and content of visited web pages. You can gain access to email messages, web search history, locations and other data stored in WebKit databases. This section is an additional source of app user data for forensic experts.

get quote


  • I have read and agree with Privacy Policy. I agree to my data being stored and used to received quotations and other question that i might have.