Advanced software to extract data from multiple sources
Oxygen Detective® is a complete match for busy forensic labs, accelerating data acquisition from multiple devices by distributing time-consuming operations between multiple workstations.
Wi-Fi Networks Activity Section
Displays the list of hotspots the examined Apple device was ever connected to with dates and times of first and last connection. Oxygen Forensic Suite automatically determines the geographical position of each hotspot and shows it using Google Maps.
Deleted Data Access
The built-in SQLite browser not only displays the actual data, but also unallocated blocks where you can find deleted contacts, calls and message information.
SQLite and Plist Viewers
These viewers make the process of analyzing Apple devices much more convenient, since SQLite databases is the standard storage format for data and Plist.
Oxygen Detective Extractor recovers the following data:
Common device information
Contacts with all the fields and contact photos
Missed/Outgoing/Incoming calls and Facetime calls
Organizer data (meetings, appointments, memos, anniversaries, tasks, notes, etc.)
SMS, MMS, iMessages, emails with attachments
Device dictionary words
Photos, videos, audio files and voice records
Passwords to the device owner accounts and Wi-Fi hotspots
250+ applications user data: Apple Maps, Booking.com, Facebook, Google+, Paypal, Safari, Skype, Viber, Whatsapp, etc.
Oxygen Forensic® Detective Enterprise is a cost efficient solution for big organizations with multiple local or remote workstations.
Distribute software across unlimited locations
Available in 5, 10, 20+ Concurrent Licenses
All functionality of Detective Version
12 months of free updates
Easily scalable to suite specific requirements
Most Cost Effective Way to Implement
Mobile Device Forensics Across Multiple Locations
Oxygen Forensic® Detective Enterprise has all Detective features. It includes Applications, Passwords, Deleted data recovery, Timeline, Aggregated Contacts, Social Graph, Links and Stats, Search and other features. One server with one USB dongle manages all connections. There is no need to have USB dongles on all computers. All workstations use one USB dongle plugged-in to the server.
No more expenses for occasionally used software. Oxygen Forensic® Detective Enterprise counts only workstations that use Oxygen Forensic® Detective at the moment and not every PC where it is installed. Oxygen Forensic® Detective Enterprise allows both local and Internet connections. You are not limited to use Oxygen Forensic® Detective in a lab. Connect remote experts via Internet if needed.
Manage your multi-user license easily. It is much easier to update license in one dongle on the server than on every workstation that uses Oxygen Forensic® Detective. You can choose how many concurrent connections you need. Oxygen Forensic® Detective Enterprise is distributed as follows: 5, 10, 20 and 50 concurrent connections.
Oxygen Forensic Detective Features
Call Data Records
Oxygen Forensic® Call Data Expert is a forensic program that allows importing and analyzing CDR files (Call Data Records) received from mobile service providers regardless of the difference in their column formats and file layouts.
Web Connections & Locations section reveals suspects’ visited places and routes.
Experts can analyze several sources of Geo data: Wifi connections, IP connections and Locations databases.
Locked devices acquisition
Oxygen Forensic® Detective offers a new physical method for Samsung Android devices using our forensic custom recovery function. This approach covers the latest Samsung devices based on Android OS, like Galaxy S5, Galaxy S6, etc.
Plist files, known as Property List XML Files, contain a lot of valuable forensic information in Apple devices. Browser history, Wi-Fi access points, speed dials, Bluetooth settings, global applications settings, Apple Store settings and even more data can be extracted from .plist files.
SQLite Viewer allows to explore the database files with the following extensions: .sqlite, .sqlite3, .sqlitedb, .db, .db3.
Experts have the access to the actual and deleted data stored in databases created by system and user applications.
Timeline allows to view all facts of mobile device usage in one sorted list.
This section organizes all calls, messages, calendar events, geo data and other activities in chronological way, so you can easily follow the conversation history without the need to switch between different sections.
Decrypt passwords and authentication tokens to user accounts in social networks, messengers and email apps. Reveal passwords that were used to connect to wi-fi networks.
ADVANCED PHYSICAL METHODS
Physical collection while bypassing device security.
Extract, decrypt and examine user data from today's most popular apps.
BACKUP AND IMAGE IMPORT
Import and parse various backups and images made from today's devices like ios, android, and more as well as import from other forensic tools like cellebrite and msab.
View dialed, answered and failed calls including deleted ones. Apply filters to show calls only for a specific period of time.
Process and analyze call data records obtained from wireless providers. Visualize geo coordinates on the map and identify links between callers.
Gain access to cloud services like: whatsapp, telegram, icloud, google, samsung, microsoft, facebook, instagram, twitter and many other social media cloud services.
Uncover and reveal names, usernames, emails, and more in different sources on the device.
Customize and generate data reports in many formats like pdf, xls, rtf, xml and html.
Powerful global search over a single device, multiple devices or entire case.
View the detailed information about the device and its owner.
Extract and analyze drone data from physical dumps, drone logs and mobile applications.
ENCRYPTED BACKUPS AND IMAGES IMPORT
Find passwords to encrypted backups and images by using various attacks and optimize the attacks to deliver unrivaled results in record speeds.
Use the most innovative and powerful ability to categorize human faces at no additional charge.
Access a devices photos, audio and video files, databases and other acquired evidence at the file-system level. View any file in a raw, hex mode, native view.
Extract and view geo coordinates from various sources: applications data, photo and video exif headers, history of wi-fi connections, etc.
Detect significant images including pornography, extremism, drugs, guns, etc with the built-in image categorization engine.
IOT DEVICE SUPPORT
Extract and analyze data from iot devices.
Mark important entries as key evidence in any program section and view them later in a single list.
Create and use keyword lists to quickly find the relevant data during or after data extraction.
LIVE DATA EXTRACTION
Extract data from mobile devices based on ios, android, windows phone, windows mobile, blackberry, bada os or feature phones. Additionally, acquire device media and sim cards.
Open geo coordinates on the built-in maps, visualize user’s movements, determine his frequently visited places and find out if several people were at the same time at the same place.
Gain access to sms, mms, email and imessage communications and read them either in table or chats view.
Extract and recover user’s calendars, notes and tasks. Decode ios encrypted notes.
Open and examine. Plist files found in ios device extractions. Use converter panel to convert values into a readable format.
Explore social connections between the device owner and his contacts or between several devices by analyzing calls, messages and app communication activities.
Examine sqlite databases, recover deleted data, convert values, build sql queries, perform search and export selected entries to reports.
View all events in a chronological order: chats, calls, voicemails, photos and videos history, wi-fi connections, geo files and web cache.
USER DATA COLLECTION ON COMPUTER
Collect credentials and passwords on computer using Oxygen Forensic® keyscout
Parse user’s emails from webmail interface and content of visited webpages. Gain access to email messages, web search history, locations and other data stored in webkit databases.
Oxygen Forensic® Detective currently offers the most verbose drone data parsing and analysis from physical dumps, drone logs and mobile applications.
There are over 770,000 registered drones in the United States alone and much more all over the world.With the ability of drones to video, photograph, and even transport material it is no wonder law enforcement is rushing to obtain valuable digital data from them.
This data contains not only images and videos but routes the device has been on from where it started to where it finished. Furthermore, data from these devices can show altitude, a direction of travel, speed, rotor speed, and even facial recognition data!
First time Oxygen Customer? Use the following part code:
Part No: AP-OXYDET
Upgrading from Oxygen Analyst? Use the following part code: