Oxygen Forensics – 2020 In Review: Highlights Of Our Year

This has been a challenging year for all of us, and as it comes to a close, we wanted to take this opportunity to thank our customers and the forensic community for their continued support and trust in us during this time.

We are proud and grateful to acknowledge that Oxygen Forensics has not only adjusted to the changing environment but led the industry with innovative online training, continued output of groundbreaking tools, and consistent, world-class customer service.

MOBILE DEVICE EXTRACTION

The screen lock bypass methods we introduced for Android devices this year put us at the forefront of the mobile forensics industry. Our complete catalog of supported physical extraction methods does not only allow investigators to extract evidence from a locked Android device but also decrypt dumps using the built-in brute force module. Let’s recap our most notable achievements.

  • Added Huawei Kirin Support. Our exclusive Huawei Android Dump enables extraction and decryption of devices based on 710, 710F, 810, 659, 960, 970, 980, 990, 990 5G Kirin chipsets with File-Based Encryption and running Android OS 9 and 10.
  • Introduced extraction for Exynos chipsets. Samsung Exynos Dump provides extraction and decryption of devices based on Exynos chipsets with Full Disk Encryption and running Android OS 7, 8 and 9.
  • Introduced support for 2 new MTK chipsets. MTK Android Dump method now supports two new chipsets for extraction and decryption – MT 6739 and МТ 6580.
  • Improved support for Qualcomm chipsets. Investigators can perform a screen lock bypass, physical extraction, and decrypt physical dumps of Android devices based on Qualcomm MSM8917, MSM8937, MSM8940 and MSM8953 chipsets.
  • Improved support for Spreadtrum chipsets. Our Spreadtrum Dump method now supports extraction and decryption for devices based on Spreadtrum SC9850, Spreadtrum SC9863, Spreadtrum SC7731E, and Spreadtrum SC9832E chipsets.
  • Introduced data acquisition via checkm8. We added Apple iOS full file system and keychain extractions using the checkm8 vulnerability for iPhone 5s through iPhone X, as well as the corresponding iPad devices running iOS up to and including 14.3. Selective data extractions are available for this method.
  • Enhanced OxyAgent utility. Investigators can now use USB or Wi-Fi to extract evidence from Android devices. OxyAgent also allows investigators to screenshot data and extract WhatsApp and Signal Messenger data, Android file structure, and the list of apk files as long as the device is unlocked.
  • Added a new extraction method for Android devices. We introduced file system extraction for Android devices with File-Based Encryption and running Android 10. This method is based on rooting and allows access to device applications.

DATA IMPORT


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

We added several new file formats to Oxygen Forensic Detective. Now investigators can import and parse data from Facebook, Twitter, Snapchat, and Instagram Warrant Returns. Similarly, we added parsing of Samsung Smart Switch backups, a great alternative source of evidence. Not stopping there, we introduced support for Android and PC E01 images and Meiya Pico extractions to our list.

CLOUD DATA EXTRACTION

Our number of supported cloud services has increased once again to double and triple those of our nearest competitors. This year we added 14 new cloud services to our catalog: Slack, Skype, SecMail, Zoom, Amazon Photos, Airbnb, IMO, Firefox Lockwise, Firefox Browser, Huawei Cloud backups, VIPole, Evernote, and JioChat.

Moreover, we introduced the ability to extract iCloud backups made from the latest Apple iOS 14.3 devices.

Our industry-first innovative method of cloud data extraction via QR code was significantly extended. Investigators can now use QR codes to extract cloud evidence from Telegram, Huawei Cloud Data, Huawei Cloud backups, as well as previously supported apps like WhatsApp, Viber, Line Messengers, and Line Keep.

We also updated authorization and extraction algorithms for already supported cloud services like Wickr Me, FitBit, Huawei Cloud, Instagram, Google Mail, Line Google Backup, Linkedin, Mi Cloud, Outlook Calendar, Outlook People, and OneDrive. We also improved extraction via our WhatsApp QR method, WhatsApp cloud, and WhatsApp backup decryption via phone number.

Overall, our built-in Cloud Extractor supports 90 cloud services.

COMPUTER ARTIFACTS

Throughout the year, each release has made our Oxygen Forensic® KeyScout a more powerful tool for computer live artifact collection.

To start, we gave investigators the ability to recover valuable insights into computer usage by collecting a wide variety of system files, such as Jump Lists, Shellbags, USBSTOR, Amcache, ActivitiesCache, Prefetch, and many others on Windows PCs. For macOS users, we added Quarantine Events and FSEvents files.

Our powerful Oxygen Forensic® KeyScout can locate and decrypt a vast number of computer artifacts and credentials for various pre-installed Apple apps on macOS. Signal Messenger, Zoom, Facebook Messenger, Amazon Photos, Dropbox, Google Sync, Skype, Telegram, Slack, OneDrive, and Evernote data on macOS and Windows computers can also be located and decrypted.

DATA PARSING AND ANALYSIS

First, we focused on improving decryption capabilities for secure apps such as Signal Messenger, Wickr Me, Wire, ChatSecure, and Facebook secret chats. Decrypting app data from Apple iOS devices is now possible after the introduction of full keychain extraction via checkm8. The total amount of supported app versions now exceeds 19,500.

When it comes to analytics, we are known for providing our users with the industry’s most comprehensive and innovative tools. This year we introduced several new features built into Oxygen Forensic Detective at no additional cost:

  • Optical Character Recognition – allows investigators to easily search for words located within screenshots and images by automatically converting them to machine-encoded text.
  • New Statistics Section – helps investigators quickly gather actionable intelligence of a user’s activity. This tool also tracks the investigator’s interactions with the evidence.
  • New Reports section – places all generated reports in one location for simpler, more efficient access.
  • Enhanced Image Categorization – we added several new categories, such as Vehicles, Chats, QR codes, Maps. In total, this section offers 16 categories.
  • Enhanced Facial Categorization – allows investigators to identify people wearing glasses, hats, and, most importantly, masks.

Wish to try Oxygen Forensic Detective? Ask for a demo license here.

Leave a Comment

Latest Videos

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification 

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_VKk-mhlae1c

Becoming An Amped FIVE Certified Examiner (AFCE)

Forensic Focus 1st December 2023 4:25 pm

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data. 

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data.

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_4z-EgH54KZk

The Power Of Digital Forensics: How ADF Solutions Is Revolutionizing The Digital Forensics Industry

Forensic Focus 30th November 2023 2:57 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles