oxygen forensic®




aggregated contacts

Reveal same people in different sources and merge them in one meta contact for efficient analysis



Extract, decrypt and examine user data from popular Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness and Multimedia apps


backups and images import

Import and parse various backups and images made from iOS, Android, Windows Phone and Blackberry devices


Aggregated Contacts section displays contacts obtained from various sources: standard phonebook, calls log, messages and application databases. Contacts with the same fields are merged into one meta-contact. Aggregated Data can be used at both the case level and device level of the examination.


Applications section displays user data extracted and parsed from popular Social Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness and Multimedia apps. You can view app account details, contacts, messages, calls, logs, cache and other data. The software decrypts evidence even from Private Messengers and other secure apps.


Oxygen Forensic® software imports and parses dozens of various device backups and images created in official device software, third-party programs or other forensic tools. You can import iTunes, ADB and Nokia backups, JTAG, CHIP-Off and Nandroid images, XRY and UFED images and many more.


data reports

Customize and generate data reports to PDF, XLS, RTF, XML and other popular file formats


data search

Perform search in a single device or in a case. Apply various search criteria including keywords, regular expressions and credit card numbers search


deleted data

Automatically recover deleted records and files: contacts, calls, messages, notes, photos, videos, SQLite databases and other vital evidence


Oxygen Forensic® software enables export of data from any section to popular file formats: PDF, RTF, XLS, XML, HYML, etc. This can be a report of the whole device, several devices, several sections or even several entries. Reports are highly customizable to fit every possible need. XML reports can be integrated into other analysis software.


Oxygen Forensic® software has a powerful built-in interface for data search. Searching can be conducted on all devices, case level and device level. You can search data according to the information entered in the input field, by keyword lists, using regular expressions or choosing any other available method. Search is launched as a separate process so you are free to work with the software during the search process


Oxygen Forensic® software recovers a wide range of deleted evidence: contacts, messages, calls, notes, user data from applications from SQLite databases, It is also capable to recover photos, videos, databases and files from physical images of Android and Windows Phone devices. All recovered evidence is marked with a special trash bin icon for you to easily identify it.


device information

view the detailed information about the device and its owner


event log

View dialed, answered and failed calls including deleted ones. Apply filters to show calls only for a specific period of time


file browser

Access devices photos, audio and video files, databases and other acquired evidence. View any file in a raw, hex mode, or run appropriate player for the media content


Device information section gives you the general information about the acquired device. It shows various attributes, like the device, SIM and network information, phone numbers and case details. You can also find the summary of all device owner’s accounts with the login and password information.


Event Log section provides access to phone and FaceTime calls as well as messages and packet data. You can apply time filters to view calls only for a particular period. The section allows to export all or selected data to PDF, RTF, XLS, XML and other types of reports.


File Browser section grants access to user’s photos, videos, documents and device databases. Built-in Text, Hex, Multimedia, SQLite and Plist viewers allow to examine files and their properties. Rich filtering and powerful search help to focus only on the required evidence.


geo data

Extract and view geo coordinates from various sources: applications data, photo and video EXIF headers, history of Wi-Fi connections, etc


key evidence

Mark important entries as key evidence in any program section and view them later in a single list


keywords search

Create and use keyword lists to quickly find the relevant data during or after data extraction


Oxygen Forensic® software collects geo data from various sources: photo and video EXIF headers, web connections information and applications databases. Geo coordinates can be extracted both from mobile devices and cloud services. The full list of geo points can be found on Geo Timeline tab in Timeline section. Oxygen Forensic® Maps can be opened from this section to view the coordinates.


Key Evidence section displays events marked in other program sections as important. The function of the section is to put the entries that can be used as evidence relevant to a certain case in the same place to make the data analysis easier. You can bookmark important evidence in one or several devices and export it later to one data report.


Oxygen Forensic® software allows creating and using keyword lists to quickly reveal the required evidence. You can enter keywords or import them from a .txt file before data extraction to receive the results once the extraction process is completed.


link analysis

Explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities


live data extraction

Extract data from mobile devices based on iOS, Android, Windows Phone, Windows Mobile, Blackberry, Bada OS or feature phones. Additionally, acquire device media and SIM cards



Gain access to SMS, MMS, Email and iMessage communications and read them either in Table or Chats view


Oxygen Forensic® software provides several tools to explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities. You can use either a Graph or Diagram view to determine social links, find the closest circle of communication and analyze communication statistics.


Oxygen Forensic® software offers both logical and physical methods of device acquisition via a regular USB cable. The program supports thousands of devices running iOS, Android, Windows Phone, Windows Mobile, Blackberry, Bada, Symbian OS or having no OS at all (feature phones). Support for Chinese MTK and Spreadtrum chipsets is also available. Additionally, you can extract and recover data from media and SIM cards via specialized readers.


Messages section gives you access to SMS, MMS, iMessage and E-mail messages (with the attachments) in the device. You can read conversations either in Table or Chats view. Export button allows to send all or selected messages with attachments to data reports.



Extract and recover user’s calendars, notes and tasks. Decode iOS encrypted notes



Decrypt passwords and authentication tokens to user accounts in Social Networks, Messengers and Email apps. Reveal passwords that were used to connect to Wi-Fi networks



View all phonebook information including names, phone numbers, email addresses, notes, birthdays, creation and modification dates


Organizer section displays the detailed information about calendar events, notes and tasks. The program can decrypt notes created and encrypted in Apple devices running iOS 9.x and 10.x. Data reports can be customized and generated in any of supported file formats.


Passwords section displays logins, passwords and tokens extracted iOS, Android and Windows Phone devices. The program decrypts credentials from the iOS keychain, finds them in application databases and web forms. You can find passwords to various application accounts as well as passwords used to connect to WiFi networks.


Phonebook section presents the complete information about the device contacts - phone and SIM card contacts, their standard and customer fields, speed dials and birthdays, creation and last modification dates. The section offers rich sorting and filtering capabilities and allows to generate data reports with all or selected contacts.


plist viewer

Open and examine. plist files found in iOS device extractions. Use Converter panel to convert values into a readable format


sqlite viewer

Examine SQLite databases, recover deleted data, convert values, build SQL queries, perform search and export selected entries to reports



Discover spyware that might be running on mobile devices and analyze its logs and configuration files


The built-in Oxygen Forensic® Plist Viewer offers convenient analyzing of Plist files: you can open plain XML and binary XML files, view entries according to their type (string, data, numbers etc.), convert values, open external files for analysis, export .plist file data in XML format for further analysis by external tools.


The built-in Oxygen Forensic SQLite Viewer is a powerful tool that allows examining of SQLite files and studying their contents. With this tool, you can open any SQLite database, recover deleted records, convert values to a readable format, build visual SQL queries and save them for further use, run search and finally export selected entries to data reports.


Oxygen Forensic® software can detect spyware apps installed on Android and Apple devices, discover and process their logs and configuration files. Spyware log files may include application configuration data, the list of running services, application username, sometimes accompanied with a unique code allowing to detect the app, Cell ID used at the time of data transmission, and GPS logs accompanied with Geo-coordinates and a timestamp.



View all events in a chronological order: chats, calls, voicemails, photos and videos history, wi-fi connections, geo files and web cache


web connections

Find out when and where the device owner used Internet access and gather information about frequent locations of iOS users


webkit data

Parse user’s emails from webmail interface and content of visited webpages. Gain access to email messages, web search history, locations and other data stored in WebKit databases


Timeline section summarizes all events in chronological order: calendar events, messages, calls, web cache, web connections, voicemails, photos and videos history, etc. The section offers you a number of powerful filters and convenient data presentation modes that permit you to concentrate on the analysis of the needed data only. It also graphically shows the peaks of user activity.


Web Connections section presents the history of Web connections (Wi-Fi, GPRS, LTE) in one list and shows the place where the Internet was used. The information about every Wi-Fi hotspot includes its name, Mac address, time of the first and last connections. The program also displays the list of frequent locations extracted from iOS devices.


WebKit Data section shows user’s emails from webmail interface and content of visited web pages. You can gain access to email messages, web search history, locations and other data stored in WebKit databases. This section is an additional source of app user data for forensic experts.

get quote

  • I have read and agree with Privacy Policy. I agree to my data being stored and used to receive quotations and other question that I might have.