Top Software Updates from Oxygen Forensics in 2022

As this year comes to a close, we want to review the top advancements we’ve made to our software in 2022.

Mobile Data Extraction

This year we’ve introduced numerous methods and features to allow investigators increased access to evidence from mobile devices and cloud services, even if encrypted. Let’s review our extraction updates of 2022.

  • Android MTK Devices. MTK-based devices have been our priority this year. We’ve added passcode brute force for MTK-based Android devices with File-Based Encryption (FBE). These devices include the popular Xiaomi, Oppo, and Realme models. We’ve also added support for 3 new MTK chipsets: MT6765, MT6768, and MT6785. Our support for MTK-based Android devices with Full-Disk Encryption has also been significantly enhanced. Learn more in this article.
  • Access to the Xiaomi Second Space. Within the MTK Android Dump method, we’ve added the ability to brute force and decrypt Xiaomi Second Space where sensitive data might be located.
  • Brute force for Samsung Exynos (FBE) devices. Now you can brute force passcodes to decrypt data from Samsung Exynos devices with FBE and running Android OS 10-11.
  • Huawei Kirin Devices. We’ve added support for Kirin 985 and 820 chipsets. Now you can decrypt evidence from many more Huawei devices running Android OS 9 and 10. More information on this method is available here.
  • Huawei MainSpace. If several MainSpaces are activated, passcodes to all of them can now be brute forced and applied. Use the Huawei Android Dump method for this.
  • Android Agent Utility. For manual extraction, we’ve added support for the following new apps: Zoom, Wickr Pro, Silent Phone, Kik Messenger, Firefox. Use this method for fast data collection from unlocked Android devices.
  • Android KeyStore Extraction. We’ve enhanced the ability to extract encryption keys from the Android KeyStore to decrypt secure apps, like Signal, Silent Phone, and ProtonMail. Use the Full File System, Huawei Kirin, and Qualcomm methods for this purpose.
  • iOS checkm8 method. We have updated this method with the release of every new iOS version. Currently, it is compatible with all the versions up to, and including, 15.7.
  • iOS Agent. We’ve introduced a new method of iOS data extraction. Currently, this method covers a vast variety of devices including iPhone 11 and iPhone 12. The supported versions are 14.0 – 14.3, 14.4 – 14.5.1, and 15.0 – 15.1.1. Learn more in this article.
  • Mobile App Parsing. We’ve focused on app parsing updates and decryption of secure and vault apps like ProtonMail, Calculator+, Calculator#, FileSafe, and Briar. Currently, the total number of supported app versions exceeds 34,600.

Cloud Data Extraction

This year we focused on enhancing support for our 102 supported cloud services. However, we have also introduced support for multiple new services:

We’ve also added the ability to import and decrypt WhatsApp backups of .crypt 15 type.

Computer Artifacts

With every release, we add a great number of functionality and interface enhancements to Oxygen Forensic® KeyScout, making it a more powerful computer forensics tool.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

This year we’ve significantly improved the KeyScout interface, making it more user friendly. In addition, we’ve extended a number of supported system and user artifacts that can be collected on macOS, Windows, and Linux computers.

We’ve also added support for new types of computer images:

  • Lx01 images
  • Ex01 images
  • images of virtual machines of VMX and VBOX formats
  • macOS Time Machine backups
  • Windows Volume Shadow Copy snapshots
  • macOS images that contain the APFS file system
  • images and drives that contain the exFAT file system

Data Import

This year we’ve added many new evidence sources to our toolkit:

Data Analytics

Many great analytic enhancements have been incorporated this year:

  • User Searches section. You can now analyze all the extracted user searches in a single view.
  • New analysis tool in Timeline. We’ve added the ability to compare device call and message logs with CDR data.
  • Facial Categorization
    • multi-thread facial categorization using GPU and CPU
    • adding faces from video frames from the File section to face sets that are used in facial search across extracted evidence
    • ability to categorize faces from video frames in the Files section and add them to the Faces section
    • Selective categorization of faces in the Files section
  • Hex Search. We’ve added Hex Lists Manager in the Search section.
  • Locations analysis. Now you can get addresses from geo coordinates using OpenStreetMap and Mapbox services.

Leave a Comment

Latest Videos

Data Extraction From UNISOC-Based Devices In Oxygen Forensic® Detective

Forensic Focus 16th November 2023 3:08 pm

Si and Desi talk to Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation, and Emma Pickering, Head of Tech and Economic Abuse at Refuge. They discuss the impact of digital forensics and incident response (DFIR) in cases of domestic abuse. They highlight the prevalence of tech-enabled abuse, such as the use of stalkerware, and the need for comprehensive support and safety plans for survivors. 

They also talk about the challenges faced by law enforcement in investigating and prosecuting these cases, as well as the importance of training and awareness in addressing tech-enabled abuse. The conversation emphasizes the need for collaboration between organizations, tech developers, and law enforcement to effectively combat domestic abuse.

Show Notes:

Apple Support: How Safety Check on iPhone works to keep you safe - https://support.apple.com/guide/personal-safety/how-safety-check-works-ips2aad835e1/web
IBM: Five Technology Design Principles to Combat Domestic Abuse - https://www.ibm.com/policy/five-technology-design-principles-to-combat-domestic-abuse/
EFF: Today The UK Parliament Undermined The Privacy, Security, And Freedom Of All Internet Users  - https://www.eff.org/deeplinks/2023/09/today-uk-parliament-undermined-privacy-security-and-freedom-all-internet-users
Wesley Mission: More support to help escape family violence - https://www.wesleymission.org.au/about-us/what-we-do/helping-people-most-in-need/housing-and-accommodation/wesley-emergency-relief/more-support-to-help-escape-family-violence/
Refuge: How we can help you - https://refuge.org.uk/i-need-help-now/how-we-can-help-you/
Electronic Frontier Foundation - https://www.eff.org/

Si and Desi talk to Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation, and Emma Pickering, Head of Tech and Economic Abuse at Refuge. They discuss the impact of digital forensics and incident response (DFIR) in cases of domestic abuse. They highlight the prevalence of tech-enabled abuse, such as the use of stalkerware, and the need for comprehensive support and safety plans for survivors.

They also talk about the challenges faced by law enforcement in investigating and prosecuting these cases, as well as the importance of training and awareness in addressing tech-enabled abuse. The conversation emphasizes the need for collaboration between organizations, tech developers, and law enforcement to effectively combat domestic abuse.

Show Notes:

Apple Support: How Safety Check on iPhone works to keep you safe - https://support.apple.com/guide/personal-safety/how-safety-check-works-ips2aad835e1/web
IBM: Five Technology Design Principles to Combat Domestic Abuse - https://www.ibm.com/policy/five-technology-design-principles-to-combat-domestic-abuse/
EFF: Today The UK Parliament Undermined The Privacy, Security, And Freedom Of All Internet Users - https://www.eff.org/deeplinks/2023/09/today-uk-parliament-undermined-privacy-security-and-freedom-all-internet-users
Wesley Mission: More support to help escape family violence - https://www.wesleymission.org.au/about-us/what-we-do/helping-people-most-in-need/housing-and-accommodation/wesley-emergency-relief/more-support-to-help-escape-family-violence/
Refuge: How we can help you - https://refuge.org.uk/i-need-help-now/how-we-can-help-you/
Electronic Frontier Foundation - https://www.eff.org/

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_nSWQZe9gpVk

Protecting Victims From Stalkerware And Tech-Enabled Abuse

Forensic Focus 15th November 2023 11:11 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles