Oxygen Forensic® Detective 2025: Powerful New Capabilities for Modern Digital Investigations

Discover Oxygen Forensic® Detective’s 2025 updates, including expanded mobile, cloud, computer, and passcode recovery capabilities for modern investigations.

As 2025 transitions into 2026, digital investigations continue to grow more complex. Investigators face encrypted devices, diverse operating systems, cloud-hosted evidence, and increasingly sophisticated user behavior. To keep pace, forensic tools must evolve quickly — and this year, Oxygen Forensic® Detective delivered major advancements across mobile, cloud, and computer forensics.

Here’s a look at the most impactful features added in 2025 and how they help investigators uncover critical evidence faster, more reliably, and with greater confidence.

Mobile Data Extraction: Broader Coverage, Deeper Access

Expanded Android Support Across Chipsets and Devices

Oxygen Forensic® Detective updates have added faster and more reliable access to critical mobile device data including significantly expanded Android extraction capabilities, such as:

Unisoc-based Android support

First, we have enhanced data extraction from Unisoc-based Android devices by adding support for the SC9863, SC9832E, and SC7731E chipsets released from 2020 onward, as well as the T606 chipset.

Qualcomm-based Android support

Second, we have added support for extracting encryption keys and decrypting user data for additional users on Qualcomm-based Android devices.

Support for Unisoc-based feature phones

In addition, a new method has been introduced for extracting data from feature phones based on the Unisoc T117 and T107 chipsets. Supported devices include Alcatel 3080G, Gigaset GLX8, MyPhone C1 LTE,  Nokia 225 4G (2020), Panasonic KX-TU550, and many others.

Unlocked Android device support

For unlocked Android devices, we have introduced the capability to perform selective app data acquisition when extracting the Full File System using the CVE-2024-31317 exploit.

We have also implemented the Chain method, a process that allows sequential application of the Android Physical, Android Full File System, Android Agent, and Android Backup methods to extract data from one device in a single session.

Furthermore, we have enhanced the Android Agent functionality, adding the ability to collect multiple third-party apps and different data categories from logical acquisition into a single multi-source extraction.

Moreover, you can now extract data from devices running Android OS 15. We have also added support for extracting Element Messenger data via Android Agent.

These updates give investigators access to evidence from devices that were previously difficult or impossible to extract.

Cloud Data Extraction

This year, we focused on continuously updating support for our industry-best 100+ cloud services and introduced the ability to extract evidence including contacts, calls, chats, and notifications from Line backups stored in iCloud Drive.

Oxygen Forensic Detective data analysis view displaying contacts and chat messages from extracted devices

Expanded Passcode Recovery Capabilities

Updates to KeyDiver were designed to help recover passcodes for encrypted partitions, files, and applications. Enhancements include:

  • Support for CPU-based passcode brute forcing.
  • The ability to find passcodes for encrypted Adobe Acrobat PDF files.
  • KeyDiver can now brute force 1Password account passwords using known hashes.

KeyDiver interface in Oxygen Forensic Detective for recovering passwords from encrypted PDF files

Computer Data Extraction

KeyScout, the portable acquisition utility inside Oxygen Forensic® Detective, received a significant update this year with the introduction of the following:

  • File carving, enabling the recovery of JPEG, PDF, TXT, ZIP, and many other file types from the unallocated space of NTFS partitions
  • The range of files searchable by file signature has been expanded to include ZIP-based container files, as well as DOC, XLS, PDF, and JPEG files.
  • Added support for decrypting E01 images containing volumes protected by multiple recovery keys.
  • KeyScout can now recognize virtual machines on target desktop devices.
  • We have greatly expanded the range of supported system and user artifacts that can be collected from macOS, Windows, and Linux computers.

KeyScout file carving settings in Oxygen Forensic Detective for recovering documents and images

Oxygen Forensic Detective KeyScout showing supported document and archive file types for carving

Data Import

Data import capabilities have been expanded to include supplementary data import from external sources. You can now enrich existing files in the software by uploading CSV or TXT files with additional data.

Supplementary data import feature in Oxygen Forensic Detective for enriching existing investigations

We have also added many new evidence sources to our toolkit:

  • Samsung Smart Switch backups of version 37 and later
  • UFED Advanced Logical extractions of iOS devices
  • Unencrypted DMG backups of iPhone devices
  • Memory card dumps in AD1 format
  • Exported WhatsApp chats
  • Exported Telegram Desktop chats
  • Slack account data
  • Google Timeline data from Google Takeout
  • Encrypted DJI Avata drone flight logs
  • AT&T call data records in XLSX/CSV formats
  • Verizon call data records

We also introduced the ability to import single or multiple extractions via the Command Line interface.

Data Analysis Enhancements

A number of great analytic enhancements have been incorporated this year:

  • We’ve added support for parsing data from applications that are not officially supported by using the parent application’s parsing rules. This option is available on the toolbar of the Applications section and helps eliminate the need for manual database analysis.
  • We have introduced the ability to restrict access to privileged data by protecting it with a password. Password-protected data is automatically hidden in final reports but can be fully revealed after entering the correct password in the Export Wizard’s Security tab. This feature is particularly useful when certain evidence must be kept confidential from investigators due to legal or procedural constraints.
  • The ability to search for cryptocurrency addresses has been added to the Search section. This includes the selective search for specific cryptocurrencies, as well as search for words from mnemonic (seed) phrases using the BIP39 and SLIP39 dictionaries.
  • We have also enhanced our industry-leading Translation module to include the capability to translate recognized texts from the Optical Character Recognition and Speech-to-Text engines into all supported languages. Moreover, search for a string across multiple languages has been implemented. The value entered in the Search field is first translated into the specified languages. The search is then performed for both the original and translated values.

Cryptocurrency address search interface in Oxygen Forensic Detective supporting Bitcoin, Ethereum, and other assets

Get started learning more about the industry-leading capabilities provided by Oxygen Forensic® Detective.

Transform your workflow

Unlock the power of our digital forensic solutions to streamline your workflow, gain insights from multiple sources, and speed up your investigations.