Oxygen Forensic® Detective v.16.0.1 Is Out

The latest update to our flagship solution is here, Oxygen Forensic® Detective v.16.0.1.

Key features include:

  • Public data extraction via iOS Agent
  • Extraction of iOS 17 devices
  • Decryption of VeraCrypt containers with key files
  • Updated support for WhatsApp QR Multi-Device cloud service
  • Export of contacts to VCF format

For a full list of updates, refer to the “What’s New” file in the Oxygen Forensic® Detective “Options” menu.

Mobile Forensic Updates

Extraction of public data via iOS Agent

You can now  extract public data via iOS Agent from Apple iOS devices with versions 12 and higher. Public data includes device information, contacts, calendar events, photos, media files, and shared files. This method is recommended when full file and keychain extraction is not supported or cannot be done.

Other extractor updates

We added several enhancements to our extraction methods:


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.

Unsubscribe any time. We respect your privacy - read our privacy policy.


  • Added extraction of iOS 17 devices via iTunes backup procedure.
  • Extractions are now much easier with animated instructions incorporated in the checkm8 method.
  • Android KeyStore extraction is now supported for devices with pre-installed Android OS 13.
  • Updated ability to extract WhatsApp, WhatsApp Business, Discord, Viber, and Google Chrome data via Android Agent.
  • Using Android Agent, you can now re-extract data protected with a passcode if the first attempt fails.

New app support

We added support for the following new apps:

  • Bumble (Android, iOS)
  • Todoist (Android, iOS)
  • Samsung My Files (Android)
  • Gmail Go (Android)

The total number of supported app versions now exceeds 41,200.

Import Updates

In Oxygen Forensic® Detective v.16.0.1, we added the following functionality:

  • Import and decryption of physical images of Honor 7S and Huawei Y5 devices.
  • Extraction of metadata from UFED extractions of CLBX format.

We also updated support for MTK-based devices having TEE T6.

Cloud Forensic Updates

In this release, we updated support for WhatsApp QR Mult-Device service and Huawei Cloud Data. Moreover, we added support for CAPTCHA for WhatsApp cloud.

Computer Artifacts

Decryption of VeraCrypt containers with key files

The updated Oxygen Forensic® KeyScout allows decryption of VeraCrypt containers using one or several key files. A user can create a list of key files for every VeraCrypt container and apply them to decrypt it.

We also added support for VeraCrypt app on Windows, macOS, and GNU/Linux. Key files might be found in the parsed data of this app.

New artifacts

The updated Oxygen Forensic® KeyScout enables users to collect the following new artifacts:

  • IrfanView app from Windows
  • KMPlayer from Windows
  • Dropbox from GNU/Linux
  • The creation and modification dates of APFS partitions
  • The serial number of a macOS computer
  • The history of the user logins on macOS
  • Information about trusted documents and locations stored in MS Office apps
  • Information about documents printed with CUPS (Common UNIX Printing System) from macOS and GNU/Linux
  • Information about bookmarks and sessions of web browsers based on the Blink engine

Additionally, you can now  decrypt user passwords extracted from FileZilla Client as well as logins and passwords saved in the system VPN client.

Export Updates

We added several enhancements to the Export engine. Now contacts can be exported to VCF format. Moreover, .SMIL files are now excluded from reports.

Interested in trying out Oxygen Forensic® Detective v.16.0.1? Request a free trial.

Leave a Comment