Oxygen Forensic® Detective v.18 Updates

Find out how Oxygen Forensic® Detective version 18 updates have improved analysis & analytic tools, cloud support & more.

Oxygen Forensic® Detective v.18.3.1

Download PDF

Key features include:

  • Enhanced Full file system method
  • Social Graph improvements
  • Support for ArduPilot TLOG telemetry logs
  • Automatic CDR field mapping
  • Extraction of new computer artifacts

For a full list of updates, refer to the “What’s New” file in the Oxygen Forensic® Detective “Options” menu.

Mobile Forensic Updates

Enhanced Full file system method

A new vulnerability, CVE-2025-0072, has been added to the Full file system method for Android devices.

It supports full file system extraction from the following devices with a Security Patch Level through May 2025:

  • Pixel 7 series
  • Pixel 8 series
  • Pixel 9 series
  • Pixel Tablet
  • Pixel Fold
Decryption of Safe folder data

We have added support for extracting encryption keys and data from the Safe folder on Huawei devices based on Kirin chipsets.

App extraction via USB and Wi-Fi using Android Agent

We have incorporated the ability to extract the following app data via USB and Wi-Fi using Android Agent:

  • Line
  • WhatsApp backups
  • WhatsApp Business backups

Cloud Forensic Updates

Updated cloud extraction support

We have updated the ability to extract cloud data from the following services:

  • iCloud backups from devices running iOS 17.3.1–18.7.9
  • Discord
  • Dropbox

Data Analysis

Viewing relationships between contacts on Social Graph

You can now view relationships between two selected contacts.

To do so, select two contacts on the Social Graph by holding Ctrl and clicking each contact in sequence. Alternatively, position the contacts next to each other on the graph and select them using a selection box.

Next, click the “Show path between contacts” button in the right panel.

The shortest path between the selected contacts will be displayed in the grid. If the selected contacts communicate directly with each other, no intermediary contacts are shown.

If the selected contacts do not communicate directly but share one or more common contacts, the Social Graph displays an intermediary layer, with all shared contacts shown on the same level between the two selected contacts.

The Social Graph displays a maximum of five intermediary layers. You can filter the number of intermediary layers, or handshakes, using the filter in the grid.

New bottom panel in Social Graph

We have added a bottom panel that provides detailed information about all contacts in the Social Graph.

The data is presented in the same format as the Contacts section, with two additional columns:

Links — the number of connections between the contact and other contacts
Communications — the total number of communications between the contact and other contacts

This functionality helps you identify the most active contacts within an extraction.

It also displays shared contacts, including merged contacts and contacts that appear in two or more extractions within a case.

Computer Artifacts Updates

Extraction of login Keychain files from a running macOS system

We have implemented the ability to collect credentials for the current user.

The process enables the successful extraction of login Keychain files and the required cryptographic keys, allowing subsequent access to protected data without relying on the operating system’s standard authorization mechanisms.

New artifacts

The following new computer artifacts are supported for extraction:

  • Comet browser data from Windows and macOS
  • Roblox data from Windows and macOS
  • System Logs, or syslog, data in IETF format from GNU/Linux
  • System Logs, or messages, data from GNU/Linux RHEL
  • Kernel Logs data in IETF format from GNU/Linux
  • Network Logs, or maillog, data from GNU/Linux

General Updates

Automatic CDR field mapping

An Auto-detection of fields option has been added to the toolbar, allowing users to enable or disable automatic field detection.

Clicking this button creates a template named Autotemplate for later manual editing while simultaneously initiating automatic field processing.

Please note that fully automatic processing is not possible for complex fields such as Direction, Event Type, and Beamwidth.

These fields require either manual rule configuration or the option to populate missing values with zeros, as different Call Data Records may use different values for these fields.

Support for ArduPilot TLOG telemetry logs

We have added support for importing ArduPilot telemetry logs in TLOG format.

Parsed evidence includes:

  • Battery status
  • Orientation
  • Sensor data
  • Home points
  • GPS and global points
  • Events
  • Other telemetry data
Speech-to-text recognition updates

We have significantly increased the speed of speech-to-text recognition.

We have also reduced the number of hallucinations that previously occurred when processing noise, silence, and other irrelevant audio segments.

Oxygen Forensic® Detective v.18.3

Download PDF

Key features include:

  • Upgraded Image Categorization engine
  • App extraction via USB and Wi-Fi using Android Agent
  • Enhanced support for MTK-based devices
  • Link recognized faces to existing contacts
  • Saving disk and partition images in E01 format on running GNU/Linux systems

For a full list of updates, refer to the “What’s New” file in the Oxygen Forensic® Detective “Options” menu.

Data Analysis

Upgraded Image Categorization engine

Images can now be categorized using our enhanced engine, delivering improved accuracy and better results across most categories. To get started, download and install the Image Categorization add-on from your customer area.

This new engine also introduces support for additional categories that were not available previously:

  • Animals
  • Faces
  • Food
  • Home Interiors
  • License Plates
  • Nature Landscapes
  • Text
  • Urban Scenes

We have also added configurable prompts for the following categories: Child Abuse, Nudity, Pornography, and Extremism. The enhanced image categorization engine supports both CPU and GPU execution, with GPU providing significantly higher performance.

Mobile Forensic Updates

App extraction via USB and Wi-Fi using Android Agent

We have incorporated the ability to extract app data via USB and Wi-Fi using Android Agent. The list of supported apps is as follows:

  • Chrome
  • Discord
  • Samsung Internet Browser
  • Signal
  • Slack
  • Telegram
  • Telegram Web
  • WhatsApp
  • WhatsApp Business

Previously, this extraction was supported by the Android Agent Manual method.

Enhanced support for MTK-based devices

We have added support for Android devices based on the following MTK chipsets: Mediatek MT6789, MT8781, MT6886, MT6983, MT6985, and MT6895.

Supported device models include Nothing Phone (2a), OnePlus Nord 3, POCO M5, Realme 10, Motorola Moto G72, vivo V27, vivo T2 Pro 5G, OnePlus 10R, and others.

Brute Force Module Updates

We have incorporated the ability to find passcodes to the following apps:

  • Telegram for macOS
  • Threema

Computer Artifacts Updates

Saving disk and partition images in E01 format on running GNU/Linux systems

Now you can save disks and partitions in E01 format on running GNU/Linux systems. To create an image of a disk or partition, you can choose one of the following options:

  • Physical disk. When selected, all partitions on the disk are automatically included, except for the Logical Volume Group.
  • Any partition of a physical disk that does not include a Logical Volume Group.
  • Logical Volume Group. Only one logical volume can be selected.
Other enhancements

Several functionality enhancements have been added:

  • Search for GIF files, 7-ZIP, and RAR container files by file signature
  • Extraction of GIF files, 7-ZIP, and RAR container files from unallocated space of NTFS partitions using file carving
  • Search for email files by PST and OST extensions
  • The ability to automatically detect the Windows account type and select the appropriate decryption method for protected data
New artifacts

The following new computer artifacts are supported for extraction:

  • Login Records data from GNU/Linux
  • Privilege escalation data from GNU/Linux
  • Authentication logs from GNU/Linux
  • Firewall rules data from GNU/Linux
  • Cloud-init configuration data from GNU/Linux
  • Samsung Internet Beta data from Windows
  • Singularity App data from Windows, macOS, and GNU/Linux

General Updates

Link recognized faces to existing contacts

We have added the ability to link recognized faces with existing contacts. In the Faces section, within the People block, a new Contact column has been added with a “Link Contact” option. Clicking this option allows you to select a contact to associate with the recognized face.

Resetting program data

A new “Reset Program Data” option has been added to the General settings. This feature opens a management window that allows investigators to selectively remove internally generated application data, including hash sets, face recognition sets, user tags, hex lists, keyword sets, and other custom program configurations.

This operation only affects investigator-generated metadata and application-level settings created during forensic examinations. Original forensic evidence and acquired source data remain unchanged and are not modified by this process.

The feature provides a controlled method for clearing previously created analytical datasets and custom configurations when they are no longer required, allowing investigators to return the application to a clean operational state.

Oxygen Forensic® Detective v.18.2

Download PDF

Key features include:

  • WhatsApp chat extraction via iOS Agent public data method
  • Geolocations section
  • Malware scan in KeyScout
  • File-to-app linking
  • Key Evidence enhancements

For a full list of updates, refer to the “What’s New” file in the Oxygen Forensic® Detective “Options” menu.

Mobile Forensic Updates

Enhancements of the iOS Agent public data method

We have incorporated several enhancements to the iOS Agent functionality for extracting publicly available data:

  • Added the ability to manually select and extract exported chats from WhatsApp and WhatsApp Business. Chats can be exported either with media files or without them. All iOS devices running iOS 15.1 and later are supported.
  • Added the ability to manually select and extract files and folders. In a single request, you can download files from one folder or an entire folder at once. All iOS devices running iOS 12.0 and later are supported.
  • Added functionality for extracting reminders and wireless connections data. All iOS devices running iOS 12.0 and later are supported.

Cloud Forensic Updates

Data extraction from Google Authenticator

You can now extract data from Google Authenticator using a login and password or token. The extracted data will include the account owner’s details and secret keys.

Brute Force Module Updates

We have incorporated the following improvements to the module:

  • We have added the ability to brute-force passwords for encrypted Samsung Smart Switch backups.
  • Attacks are now automatically paused when the user-defined critical GPU temperature is reached, and a corresponding notification is displayed in the attack window.
  • We have improved the brute-force algorithm for Android FDE images.
  • We have improved the ability to utilize multiple GPUs simultaneously to brute-force passwords on Android FDE and FBE images.

Computer Artifacts Updates

Malware scan

We have implemented the ability to scan disk images and physical drives for malware in KeyScout. There are two usage scenarios:

  • Select a corresponding checkbox on the General tab of KeyScout Profile settings. Files containing threats will be flagged among the other extracted files.
  • Select the corresponding search condition on the Files tab of KeyScout Profile settings. In this case only files containing threats will be found and displayed.
Other enhancements

Several other functionality enhancements have been added:

  • Search for PNG files by file signature
  • Extraction of PNG files from unallocated space on NTFS partitions
  • Calculation of SHA3-256 hashes for disk images
  • Ability to specify investigator and extraction details in the new Case Details tab
  • Decryption of Microsoft Account data for Windows Hello accounts

New artifacts

View all

The following new computer artifacts are supported for extraction:

  • Event logs of the atop utility from GNU/Linux
  • Voice Memos data from macOS
  • Zoom Workplace data from GNU/Linux
  • Obsidian data from Windows, macOS, and GNU/Linux
  • Program Compatibility Assistant data from Windows

Import Updates

View all

We have included several import enhancements:

  • Added the ability to import and decrypt E01 images of all previously supported encrypted SD cards, including those formatted as Android Adoptable Storage, with a FAT32 file system
  • Added the ability to perform selective file analysis when importing memory card dumps
  • Updated the import mechanism to support extended timestamps from GrayKey extractions
  • Updated the ability to import and parse the binary keychain format for GrayKey extractions
  • Updated the import and parsing of data from Facebook Warrant returns

General Updates

Geolocations section

We’ve introduced a new Geolocations data section that allows you to analyze all location-related information in one place. The data can be filtered using different criteria, including accounts, groups, contacts, and sources. You can also retrieve addresses from geographic coordinates. Additionally, each geolocation now includes a map preview on the Details side panel. Lastly, coordinates extracted from media file metadata are automatically labeled as the device owner’s geodata when the files are stored in standard media directories within the extraction.

Key Evidence enhancements

We have added the ability to mark all messages of a selected contact as Key Evidence.

Two new options have been added to the contact’s context menu in the Contacts section: mark communication as Key Evidence and unmark communication as Key Evidence.

File-to-app linking

Files are now automatically linked to their source application records for easier tracing and context. In the Files section, an Application column has been added. It displays the application icon if the given file is present in that application. A link to the application is displayed in the sidebar. When you click the link, you are redirected to the application section.

Support for OpenCellID database

We have added support for OpenCellID. This feature allows you to analyze network coverage around the location of an event. You can download cellular tower databases directly from the OpenCellID website by registering there and obtaining a token.

Other Updates

We have introduced other general features across the software:

  • Added the ability to filter files and exclude system files for saving in OFBR format
  • Implemented tag separation by origin into User tags and Image categorization tags
  • Added a new Coordinates column with a pop-up filter in the Messages section
  • Added new filters to the advanced search settings in the Search section
  • Added cryptocurrency search at data import
  • Added the ability to translate data from Burmese, Kannada, Khmer, Malayalam, Marathi, Mongolian, Odia, Somali, and Tagalog languages.

Oxygen Forensic® Detective v.18.1

Download PDF

Key features include:

  • Screenshot capture via iOS Agent
  • Chain extractions
  • Slack account data import
  • Automation updates
  • Check for app parsing package updates

Mobile Forensic Updates

Screenshot capture via iOS Agent

We have added the ability to capture screenshots from an iOS device via iOS Agent. You can sign iOS Agent and install it through an Apple developer account or a free iCloud account. Once it is installed, you must grant the iOS Agent permission for screen recording. In Oxygen  Device Extractor, you can access real-time screen views and save screenshots to the extraction. The extraction with the saved screenshots should be imported into Oxygen Forensic® Detective. All iOS devices with iOS 12 and newer are supported by this functionality.

Chain extractions

We added the Chain extraction method to allow using multiple extraction methods in a single process from Android OS devices. When a device is connected using this method, the system checks for available vulnerabilities. Depending on the results, you can choose Android Physical Image and Full File System. For example, the scenario allows selecting methods for a chain extraction the following way:
Android Physical Image → Full File System → Android Agent → ADB Backup.

If the full set of physical data has been successfully extracted, no further extraction is performed. If not, other methods in the chain are applied.

Android Agent updates

We updated the ability to extract the following data via Android Agent:

  • Discord
  • Opera
  • Samsung Browser
Brute Force Module Updates

We have added the following improvements to the module:

  • All found passwords are now automatically saved to the dictionary of previously brute-forced passwords.
  • You can remove previously uploaded password dictionaries and add new ones via the Dictionary manager.
  • You can export all attacks as a ZIP archive and also delete all attacks in a single action.
  • JSON files are now validated for correctness and checked for the presence of all mandatory fields required to launch an attack.

Computer Artifacts Updates

Carving enhancements

We’ve introduced support for extracting ZIP-based container files and DOC and XLS files from the unallocated space of NTFS partitions. To use this feature, enable File Carving in the KeyScout Search Rules settings and select the relevant option. Recovered files will appear in the Files tab.

Enhanced search by file signature

We’ve added the ability to search the following files by file signature:

  • ZIP-based container files
  • DOC and XLS files
  • PDF and JPEG files

You have two scenarios for data analysis in our software: determining the file type based on its contents and searching for files according to specified parameters.

New artifacts and other updates

View all

The following new computer artifacts are supported for extraction:

  • Ledger Live data from Windows, macOS and GNU/Linux
  • App Store data from macOS
  • auditd log data from GNU/Linux
  • a web version of Microsoft Teams used in Brave, Chromium, Google Chrome, Microsoft Edge, Opera, Vivaldi, Firefox, and Safari browsers from Windows, macOS, and GNU/Linux
  • TeamViewer data from Windows and GNU/Linux
  • Revolt Chat data from Windows, macOS, and GNU/Linux
  • Stoat Chat data from Windows, macOS, and GNU/Linux
  • Recent Interactions data from macOS

Import Updates

Import of Slack account data

We’ve added the ability to import downloaded Slack account data. The data is exported from the web version of the account as a ZIP archive. Evidence set will include users, messages, comments, lists, and event log.

Updated Huawei HiSuite backups

We have also added support for importing backups from Huawei HiSuite and Honor HiSuite v.14.0.

Automation Updates

Enhanced CLI support

Several enhancements have been added in this area:

  • We have included the ability to use the command-line interface to import all extractions from the Extractions folder and to save them in .ofbx and .ofbr formats.
  • We have added the ability to analyze disk images and external drives via the command line interface.
  • You can now export data to reports through the command line interface.

Applications

Check for app parsing package updates

We’ve added a check for the application parsing package updates in both manual and automatic modes. If a new version of the application parsing package is available, this information is displayed in the same place as the updated information for Oxygen Forensic® Detective. Because the application parsing package can now be updated independently, users can get parsing improvements without waiting for a new release of Oxygen Forensic® Detective.

Cryptocurrency section

A new Cryptocurrency section is added. It includes:

  • data parsed by the software algorithms
  • results of searches for cryptocurrency wallets and mnemonic phrases

The main workspace displays the following data:

  • the name of the cryptocurrency
  • the value
  • the type of value (address, transaction, mnemonic phrase)
  • the source (application or search history)

General Updates

View all

We have introduced multiple general features across the software:

  • Support for importing SQL files downloaded from NIST has been added to the Hash Set Manager.
  • In the Cases context menu we have added the option to generate a wordlist from all words and numbers found in a device extraction. They can be used for passcode brute force.
  • The Key Evidence section has been split into two sections – Key Evidence and Notes, and Tagged Evidence.
  • You can now view Protobuf files directly in the Viewer.
  • The Tags Manager now supports importing and exporting tag lists.
  • Data that is saved to an .ofbr backup can be filtered by user tags.
  • You can now set a user password when saving data to an .ofbx backup.

Oxygen Forensic® Detective v.18

Download PDF

Key features include:

  • Multi-source extraction via Android Agent
  • Search for a string in multiple languages at once
  • Support for macOS 26
  • Parsing of unsupported apps by parent app parsing rules
  • Parsing of the ChatGPT app

Mobile Forensic Updates

Multi-source extraction via Android Agent

We have added the ability to collect multiple third-party apps and other data types into one extraction using Android Agent. Now, before manually extracting data with Android Agent, you can select different data categories from logical extraction (calls, contacts, calendars, and more) and multiple third-party apps. As a result, a single file and a folder with the extracted files are generated in one extraction, simplifying the workflow.

Automatic device detection improvements

We have added extended information about the connected device and have improved auto-detection of exploited vulnerabilities for the full file system method. In the full file system method, the first vulnerability shown for the connected device is now the most relevant that provides the best extraction results.

Updates to data extraction via checkm8
We now support the following devices via the checkm8 method:
  • iPad Pro 12.9-inch (1st gen)
  • iPad Pro 9.7-inch running iOS 12.0 – 16.7.11
  • iPad 7th gen running iOS 18.0-18.6.2
  • all supported iOS devices running iOS 12.0 and above

Brute Force Module Updates

Encrypted Adobe Acrobat PDF files
We have added the ability to find passcodes to encrypted Adobe Acrobat PDF files. To brute force the password, you need to upload a file into the KeyDiver module, and the hash will be detected automatically. Supported versions are:
  • PDF 1.7 ExtensionLevel 8, Acrobat 10 – 11
  • PDF 1.7 ExtensionLevel 3, Acrobat 9
  • PDF 1.4 – 1.6, Acrobat 5 – 8
  • PDF 1.4 – 1.6, Acrobat 5 – 8
  • PDF 1.1 – 1.3, Acrobat 2 – 4
  • PDF 1.1 – 1.3, Acrobat 2 – 4
  • PDF 1.1 – 1.3, Acrobat 2 – 4
1Password account brute force
We have also added the ability to brute force 1Password account passwords using known hashes.

Computer Artifacts Updates

Document and image carving

We’ve introduced support for extracting JPEG and PDF files from the unallocated space of NTFS partitions. To use this feature, enable File Carving in the KeyScout Search Rules settings and select either Image or Document. Recovered files will appear in the Files tab.
We have also simplified the navigation and prompt the system to facilitate the configuration of profiles containing file carving search rules.

New and other updates

The following new computer artifacts are supported for extraction:

  • The Bat! data from Windows
  • Battle.net data from Windows
  • Imo Messenger data from macOS

We have also added support for macOS 26 Tahoe (beta 8).

Search Updates

Search for mnemonic phrases
We have added the ability to search for mnemonic (seed) phrases. A new Mnemonic Phrase tab has been added to the Search section, which allows searching for words from mnemonic phrases using dictionaries.
The following dictionaries are supported:
  • BIP39 — supported languages: Chinese, Czech, English, French, Italian, Japanese, Portuguese, and Spanish
  • SLIP39 — mnemonic phrases supported only in English.

The phrase search results display a list of words of the specified length from the selected BIP39 or SLIP39 dictionaries.

Search for a string in multiple languages at once
In Oxygen Forensic® Detective v.18.0 search across multiple languages has been implemented using the Translation module. The value entered in the Search field is translated into the specified languages, after which the search is performed both for the original and the translated values. The search for translated values is available only if the TextTranslate language add-on is installed. It is available at no additional charge in the Customer Area.
Support for Verizon Call Data Records
We have added the ability to import Verizon call data records and cell tower library files as well as display cell towers, sectors, and beamwidth on the Maps tool.

Applications

Parsing of unsupported apps by parent app parsing rules

We’ve added support for parsing data from applications that are not officially supported by using templates. When you select an unsupported application in the Applications section, the Select Parent Application button becomes enabled on the toolbar. After you choose a parent application and start the analysis, the data is extracted and processed using the parent application’s parsing rules. Parsing works correctly only if the unsupported app is a clone of the parent app. If a parent application is selected, the unsupported app’s data will be analyzed automatically in all subsequent imports in Oxygen Forensic® Detective.

Parsing of ChatGPT app

We have added support for ChatGPT app parsing from Android and iOS devices. Parsed data set will include accounts, projects, chats, cookies, drafts, cache, and other data.

Android data parsing updates

We have improved collection and processing of system information and telemetry from Android devices: app launches and usage, granted permissions, power-on/reboot/shutdown events, and default apps.

Transform your workflow

Unlock the power of our digital forensic solutions to streamline your workflow, gain insights from multiple sources, and speed up your investigations.