Oxygen Remote Explorer v.1.9 Adds iOS And Telegram Remote Collection

The latest version of Oxygen Remote Explorer has been released! 

Oxygen Remote Explorer revolutionizes the way businesses collect critical digital evidence. Whether investigating incidents remotely or onsite, our tool provides powerful, targeted data collection and analytic capabilities designed for efficiency and accuracy. With features like automated task scheduling and comprehensive data access, you can ensure no detail is overlooked – no matter where the evidence resides. 

The Release of Oxygen Remote Explorer v.1.9 Includes:

Remote iOS data collection via iOS Agent 

Oxygen users now have the ability to remotely collect data from iOS devices using the new Remote iOS Agent available in the Agent Management Center. 

This new capability provides fast access to critical iOS device data while eliminating travel costs and minimizing disruption to the device user. 

Remote Telegram data collection 

Remote collection of Telegram and Telegram Web data from Android devices is now possible for Oxygen users via the Remote Android Agent. 

Remote Telegram data collection is crucial in corporate investigations as it helps to rapidly detect confidential data leaks and uncover unauthorized communications or insider threats occurring outside official channels.

Search by hash sets and support for NOT IN operator 

Oxygen Forensics has added the ability to use hash sets when creating file search rules. We have also added the NOT IN operator for rules with the “Hash” and “Hash set” search conditions. This option allows searching for files whose hashes are not included in the selected hash set or do not match the selected hash. 

Search by hash sets and the support for NOT IN operator provides greater search flexibility while enabling precise and efficient targeting of specific files. 

On-demand licensing method for desktop endpoints 

Users can now choose “Issue on demand” to manually issue a license to new endpoints of any type or “Issue automatically” to allow the license to be issued automatically when the new endpoint connects to the server for the first time. 

The ability to issue licenses both automatically and on-demand provides greater deployment flexibility. 

Parsing of Google Semantic Location 

Android devices may contain the Google Semantic Location artifact that stores detailed information about user’s movements, including precise locations and timestamps. Now this artifact is parsed in Oxygen Remote Explorer. 

The additional detailed geolocation data parsed in Oxygen Remote Explorer might reveal key clues that aid investigation. 

See Oxygen Remote Explorer v.1.9 for Yourself

If you use Oxygen Remote Explorer, refer to the “What’s New” file in the “Options” menu or check out our Release Notes for a full list of updates. 

If you are not yet a customer and are interested in seeing these enhancements in Oxygen Remote Explorer v.1.9, contact us to make arrangements. 

About Oxygen Forensics 

Oxygen Forensics is a global leader in digital forensics software, enabling law enforcement, government agencies, enterprises, law firms, and service providers to gain critical insights into their data faster than ever before. Specializing in remote and onsite access to digital data from cloud services, mobile and IoT devices, drones, device backups, UICC, and media cards, Oxygen Forensics provides the most advanced digital forensics data extraction capabilities, innovative analytics tools, and seamless collaborative analysis for criminal and corporate investigations to bring insight and truth to data. 

Want to share an investigation with us? We’d love to hear how our software supported you in solving your investigation. Please contact us at marketing@oxygenforensics.com

Passware Kit 2025v3 Released: Decrypt BitLocker Devices With TPM And PXE

BitLocker encryption has long presented a significant challenge in forensic investigations. With the release of Passware Kit 2025 v3, a streamlined solution is now available. This update allows forensic experts to decrypt BitLocker-protected devices with TPM chip in minutes. The process is supported on Windows x64 devices that use the Preboot Execution Environment (PXE).

Passware introduces a new “Apply Rules” attack, compatible with rule files from third-party tools, such as hashcat and John the Ripper. This advanced option allows the user to modify, extend, and filter passwords generated by basic password-recovery attacks, including Dictionary and Brute-force.

Passware Kit now supports digest extraction from password-protected files, allowing users to transfer the password recovery process to another machine without moving large files or disk images.

Additional enhancements in this release include support for the latest bcrypt hash algorithm; GPU acceleration for Steganos Safe; and updated password recovery and decryption for Apple Notes, FileMaker, and Windows domain users.

What’s New in Passware Kit 2025 v3:

  • Decryption of BitLocker-encrypted devices with TPM and Preboot Execution Environment

  • New rule-based attack compatible with hashcat

  • Password recovery using digests instead of disk images and large files

  • Password recovery for bcrypt SHA-256 hashes

  • GPU-accelerated password recovery for Steganos containers

  • Password recovery for Apple Notes from macOS Sequoia

  • Instant decryption of FileMaker 2024 databases

  • Instant Windows user and domain password removal on Windows Server 2025

For your convenience, we have included a video of all the latest features of Passware Kit 2025 v3. Take a look!

Decryption of BitLocker-encrypted devices with TPM and Preboot Execution Environment

Passware enables forensic investigators to decrypt BitLocker-protected devices with TPM security chip in minutes. The process works on target Windows x64 devices that use the Preboot Execution Environment (PXE). The requirements are: enabled PXE boot, two USB flash drives, an Ethernet cable (with a compatible adapter if needed), and a Windows computer running the latest version of Passware Kit Ultimate or Passware Kit Forensic with Device Decryption Add-on.

As a result, Passware Kit extracts the BitLocker VMK and Recovery key, enabling the user to decrypt the disk image.

New rule-based attack compatible with hashcat

Passware Kit introduces a new rule-based password-recovery attack that modifies password candidates using rule files compatible with third-party tools like hashcat and John the Ripper. This enables flexible and precise customization of password variations, significantly enhancing recovery efficiency.

The new “Apply Rules” attack is available as an Advanced option and can be combined with standard attacks, such as Dictionary, Brute-force, and others.

Password recovery using digests instead of disk images and large files

Passware Kit now supports digest extraction from password-protected files, allowing users to transfer the password recovery process to another computer without moving large files or disk images. Digests are small files containing only the information necessary for decryption: they include no user data and can be safely moved to a more powerful system for efficient password recovery.

Password recovery for bcrypt SHA-256 hashes

Passware Kit 2025v3 supports the new bcrypt hash algorithm: Blowfish-based SHA-256 crypt. The average recovery speed is 60 passwords per second on AMD Ryzen 9 5900X CPU.

GPU-accelerated password recovery for Steganos containers

Passware adds GPU acceleration to password recovery for Steganos Safe containers. The recovery speed now reaches 646,000 passwords per second on NVIDIA RTX 4070 Ti.

Password recovery for Apple Notes from macOS Sequoia

Passware Kit 2025 v3 is now fully compatible with macOS Sequoia, featuring support for Apple Notes created on this operating system. The update enables password recovery for individual notes protected with custom passwords, achieving speeds of up to 184,000 passwords per second on an NVIDIA RTX 4070 Ti.

Instant decryption of FileMaker 2024 databases

Passware Kit instantly decrypts FileMaker databases protected with the latest 2024 version on both Windows and Mac.

Instant Windows user and domain password removal on Windows Server 2025

Passware Kit is now fully compatible with the Windows Server 2025. It can be installed and launched on this system, and it instantly resets Windows user and domain passwords.

Read more about this update on the Passware blog.

2025 MD-Series Q2 Release Note Highlights

Advancing Digital Forensics Through Continuous Innovation 

As the volume of mobile device evidence continues to escalate in modern investigations, GMDSOFT remains committed to delivering comprehensive solutions that address the evolving challenges faced by digital forensics professionals worldwide. Our Q2 2025 release demonstrates our ongoing dedication to expanding device compatibility, enhancing extraction methods, and providing global language support to meet the diverse needs of law enforcement and forensic investigators. 

📱 MD NEXT 

  • Supports new phones – 37 manufacturers, 330 new models 
  • Supports new extraction method using MD-PLUG (Android Live Pro)
    : For 449 models including Samsung Galaxy S22~S24 Series, Z Flip 4~6 Series, Z Fold 4~6 Series  
  • Supports new extraction method within Android Live (App Backup)
    : WhatsApp and WhatsApp Business 
  • 5 new languages added: Indonesian, Spanish, French, Thai, Portuguese 

📤 MD-RED 

  • Supports new apps – 5 Android apps, 3 iOS apps 
  • Updated apps – 27 Android apps, 25 iOS apps 
  • Support for analyzing Keystore files extracted by UFED tools 

👮🏻‍♀️ MD-LIVE 

  • Added new languages: Russian(русский), Arabic(العربية)  
  • Supports Zangi Private Messenger application in app downgrade 

☁️ MD-CLOUD 

  • Added new languages: Indonesian (Bahasa Indonesia)  
  • Improved extraction stability for Facebook, Google, and iCloud 

🚁 MD-DRONE  

  • Added new models manufactured by Mateksys and SpeedyBee 

🎥 MD-VIDEO AI 

  • ‘Number Plate Restoration’ covering 3 countries + 14 states of USA   
  • ‘Multi-Input Number Plate Restoration’ covering 2 countries 

For comprehensive technical specifications, detailed release notes, and implementation guidance, please contact our sales team. Our experts are available to provide consultation on MD-Series integration and optimization for your specific forensic requirements. 

Introducing Oxygen Forensic® Detective v.17.3.1

The latest update to our flagship solution is here, Oxygen Forensic® Detective v.17.3.1.

General Updates 

Search for specific cryptocurrencies  

Search for specific cryptocurrencies has been implemented. A drop-down menu has been added allowing users to select the cryptocurrencies for which they want to search. This will help reduce the number of false positives in cryptocurrency search and will enable faster access to required evidence, improving investigative efficiency.  

Mobile Forensic Updates 

Support for SC9863, SC9832E, and SC7731E chipsets 

We have added the ability to extract the physical image and hardware encryption keys from devices based on UNISOC/Spreadtrum chipsets SC9863, SC9832E, and SC7731E released from 2020 onwards.  

Android Agent updates 

We have updated the ability to extract the following app data via Android Agent:  

  • Chrome browser  
  • Line  
  • Opera browser  
  • Signal 
  • Viber

Adding extraction and decryption support is always beneficial, as it enables evidence extraction and accelerates investigations.  

Data Parsing  

Parsing of Google Semantic Location 

Android devices may contain the Google Semantic Location artifact that stores detailed information about user’s movements, including precise locations and timestamps. Now this artifact is parsed in Oxygen Forensic® Detective. Additional detailed geolocation data might reveal key clues that aid investigation. 

Parsing of Google Password Manager 

Google Password Manager is a built-in password manager that saves, autofills, and synchronizes user credentials across devices via a Google account. This application data is now parsed in Oxygen Forensic® Detective. Extracted passwords can grant access to additional data sources, including cloud storage, which can significantly aid investigations.  

If you use Oxygen Forensic® Detective, refer to the “What’s New” file in the “Options” menu for a full list of updates.  

If you are not a customer and are interested in trying out Oxygen Forensic® Detective v.17.3.1, request a free trial

About Oxygen Forensics 

Oxygen Forensics is a global leader in digital forensics software, enabling law enforcement, government agencies, enterprises, law firms, and service providers to gain critical insights into their data faster than ever before. Specializing in remote and onsite access to digital data from cloud services, mobile and IoT devices, drones, device backups, UICC, and media cards, Oxygen Forensics provides the most advanced digital forensics data extraction capabilities, innovative analytics tools, and seamless collaborative analysis for criminal and corporate investigations to bring insight and truth to data. 

# # # 

Want to Share an Investigation With Us?

We’d love to hear from you and how our software supported you in solving your investigation. Please contact us at marketing@oxygenforensics.com.

Passware Kit Mobile 2025v3 Instantly Decrypts Data From Select Huawei Kirin Devices

Passware Kit Mobile 2025 v3 introduces instant data decryption for select Huawei Kirin devices, enabling forensic professionals to extract critical information even without requiring the device password. This decryption option supports Kirin 710 and 970 chipsets with UFS storage and covers popular models such as the Huawei P20 Pro, Y9s, and Honor 10.

Additionally, PKM now supports the latest hybrid encryption scheme used in Huawei devices powered by Kirin 659 and Kirin 960 chipsets, ensuring full compatibility with models such as the Huawei Mate 9 and P20 Lite.

The latest version of PKM further expands device support by adding 22 new models powered by the Qualcomm Snapdragon 425 and MediaTek Dimensity 800 (MT6873) chipsets.

What’s New in Passware Kit Mobile 2025 v3

  • Instant decryption of Kirin 710/970 data, regardless of the password
  • Support for the latest hybrid encryption scheme on Kirin 659/960 devices
  • Password recovery for Qualcomm Snapdragon 425 devices
  • Password recovery for MediaTek Dimensity 800 devices

Instant decryption of Kirin 710/970 data, regardless of the password

Passware Kit Mobile 2025 v3 introduces instant partial data decryption for select Huawei Kirin devices, allowing forensic professionals to access critical user data without the device password. The tool automatically detects various file types, such as images, archives, audio and video files, databases, and more. It decrypts their contents, though original file names are not recovered.

Once the user data is extracted, decryption can continue on a computer with the device disconnected, leveraging CPU, GPU, and distributed computing for optimal performance.

This feature supports Kirin 710 and Kirin 970 chipsets with UFS storage and is compatible with popular models including the Huawei P20 Pro, Y9s, and Honor 10. The decryption works even for devices protected with hybrid encryption scheme, also known as blob 341 encryption, which currently does not allow password recovery.

Support for the latest hybrid encryption scheme on Kirin 659/960 devices

Passware Kit Mobile now supports the latest hybrid encryption scheme used in Huawei devices powered by Kirin 659 and Kirin 960 chipsets. This ensures full compatibility with models such as the Huawei Mate 9 and P20 Lite.

Password recovery for Qualcomm Snapdragon 425 devices

The latest PKM version supports 13 new devices powered by the Qualcomm Snapdragon 425 chipset (MSM8917). For example, the recovery speed for the Xiaomi Redmi Go (with Secure Startup enabled) reaches up to 130 passwords per second using an NVIDIA GeForce RTX 4070 Ti.

Password recovery for MediaTek Dimensity 800 devices

PKM now supports password recovery for devices powered by the MediaTek Dimensity 800 (MT6873) chipset, including nine models, such as the Honor 30 Youth and ZTE Axon 11 SE. The recovery speed for the Ulefone Armor 11 reaches up to 18,000 passwords per second using an AMD Radeon RX 6900 XT.

See the full list of supported models.

Read more about this update on the Passware blog.

Amped Software Releases Powerful New Amped FIVE Update, Featuring Writing Queue, Camera Calibration, RIFF Viewer, And More

What if you could schedule your video exports for later, calibrate distortion on action cam footage, and verify every byte in an AVI file — all within your forensic video platform?

Amped Software has released the latest Amped FIVE Update. This delivers a targeted set of enhancements designed to improve analytical control, increase export efficiency, and provide advanced forensic insights. From refined lens correction and precision timing tools to advanced container structure analysis, this update addresses real-world challenges faced by forensic video analysts.

Manage Heavy Video Exports with the New Writing Queue

Writing out long or high-resolution video sequences can tie up your system. With the introduction of the Writing Queue, Amped FIVE now allows you to prepare multiple video exports and process them later, at your convenience.

If you’re handling high-resolution, high-frame-rate, or lengthy evidence chains, now you can queue your jobs for overnight processing or batch them at the end of your shift. No need to sit and wait, just set it and return when it’s done.

This new utility integrates seamlessly into both the Video Writer and Sequence Writer filters. Once queued, writing jobs can be suspended, reordered, resumed, or removed. Everything is managed within an intuitive interface that retains its state across project saves.

Go Beyond Fisheye Correction with Camera Calibration

Distorted bodycam footage? Warped dashcam video?

How do you correct lens distortion when there are no straight lines in your frame?

Traditional filters like Undistort and Correct Fisheye may not be effective, especially when straight reference lines aren’t available.

The new Camera Calibration tools allow you to precisely correct lens distortion based on real calibration footage. Using a printed grid and a short calibration video, you can now generate a dedicated camera profile that can be applied to any evidential footage recorded with the same setup. This is a game-changer for footage from body-worn cameras, dashcams, action cams, and other wide-angle lenses.

The process is straightforward, scientifically sound, and results in clear, distortion-free views that are ready for court. Amped FIVE now supports calibration board configuration, checkerboard detection, and profile saving/loading for streamlined repeat use. This ensures the corrected output is not only visually accurate but also forensically defensible.

RIFF Viewer: See What Your Container Is Made Of

Understanding a video file’s container structure is critical for verifying integrity and troubleshooting playback or decoding issues. With this update, Amped FIVE introduces the RIFF Viewer, a forensic-grade tool for dissecting AVI and other RIFF-based multimedia files.

Now, you can view the file’s raw hexadecimal data alongside a parsed breakdown of the RIFF structure, including headers, streams, chunks, and padding. Spot inconsistencies like missing audio data, mismatched compression flags, or placeholder frames used in variable frame rate recordings, all of which can impact your analysis and reporting.

The RIFF Viewer equips you with the insight needed to trace file origins, identify manipulations, or explain playback issues.

Convert DVR Enhancements: Improved Stream Concatenation

Merging multiple short clips into a coherent video is now easier than ever. Stream concatenation in Convert DVR now checks for uniform timebases (rather than identical frame rates), enabling robust merging of VFR recordings from Wi-Fi or body-worn cameras. The output format is preserved where possible, avoiding downstream compatibility issues.

This update also improves fallback extraction with support for raw H264/H265 streams. This is ideal for rescuing data from damaged or improperly formatted containers.

Also New in This Update

  • Video Writer: A new Timing Source parameter gives you granular control over frame duration metadata.
  • Decimate: Retain only a constant pattern of frames from your footage
  • CTU Enhancements: Visualize Prediction Units in H.265 coding structures
  • Multiview Grid: Expanded to 8×8 (up to 64 chains)
  • Exportable Logs: Save data from FFMS, MediaInfo, ExifTool, and more
  • Load Timestamp Enhancements: Customize input date formats for subtitle data
  • Generate Report: Now separates input/output metadata for cleaner documentation
  • Improved muxing, MJPEG metadata handling, HEIC support, and macroblock filtering

Ready to Explore the Full Update?

These highlights only scratch the surface of what this powerful new update offers. This release is packed with tools to support your most demanding forensic tasks.

Read the full blog post and explore all the new features!

Oxygen Forensic® Detective v.17.3 Is Available Now

The latest update to our flagship solution is here, Oxygen Forensic® Detective v.17.3.

General

Privileged data protection with password

Users can now restrict access to privileged data by protecting it with a password. This feature is especially useful when certain evidence must remain hidden from investigators due to legal or procedural constraints. Allowing users to set a password helps ensure compliance while still enabling investigators to work effectively. 

Cloud Forensic Updates

Extraction of Line iCloud backup

It is now possible to extract Line iCloud backup that stores contacts, private and group chats, private and group calls, and notifications. Moreover, we have improved support for Line Google backups. Adding this additional source of Line data can significantly enhance investigative capabilities.

Import Updates

Support for AT&T Call Data Records

Support for additional columns in AT&T Call Data Records (CDR) has been implemented, including fields such as Beamwidth, Sector, ECGI, ENB-ID, LAC, and CID. Moreover, the display of cell towers, as well as beam and sector widths, has been implemented in the Maps module. Predefined templates have been added to simplify the processing of CDR data. CDR analysis plays a crucial role in many investigations. This support expands investigators’ ability to analyze data. 

Supplementary data import from external sources

Users can now enrich existing files in the software with supplementary data. A new Import Supplementary Data button has been added to the Files section, allowing users to upload CSV or TXT files. Each hash from the uploaded file is matched against the hashes in the extracted files. When a match is found, the related data is added to the corresponding file in the extraction. The result is more efficient and seamless investigations. 

Export Updates

Selective data export to OFBR backups

Selectively export data to OFBR backups choosing specific sections, applications, and time ranges in the Custom export settings. This update allows users to include only the necessary information, enhancing both flexibility and efficiency in your workflow. 

If you use Oxygen Forensic® Detective, refer to the “What’s New” file in the “Options” menu for a full list of updates.  

If you are not a customer and are interested in trying out Oxygen Forensic® Detective v.17.3, request a free trial.  

About Oxygen Forensics

Oxygen Forensics is a global leader in digital forensics software, enabling law enforcement, government agencies, enterprises, law firms, and service providers to gain critical insights into their data faster than ever before. Specializing in remote and onsite access to digital data from cloud services, mobile and IoT devices, drones, device backups, UICC, and media cards, Oxygen Forensics provides the most advanced digital forensics data extraction capabilities, innovative analytics tools, and seamless collaborative analysis for criminal and corporate investigations to bring insight and truth to data. 

# # #

Want to share an investigation with us? 

We’d love to hear from you and how our software supported you in solving your investigation. Please contact us at marketing@oxygenforensics.com.

Introducing XRY 11.0.1 From MSAB

MSAB is proud to unveil XRY 11.0.1, the latest evolution in mobile forensics technology. This release brings powerful new capabilities and critical updates that strengthen your ability to extract, decode, and analyze data from the most in-demand mobile devices and apps.

With expanded support for leading Android and iOS devices, new app decoding capabilities, and enhanced brute force functionality, XRY 11.0.1 ensures that investigators stay one step ahead in today’s fast-moving digital landscape.

What’s New in XRY?

Improved Support for Oppo MediaTek Devices

Enhanced extraction capabilities now cover a broader range of Oppo MediaTek devices, including those running the latest security updates.

New App Decoding Support

XRY continues to evolve with support for additional private messaging and social media platforms. New decoding support includes:

  • Zangi
  • Threads
  • Element

This ensures your access to vital communication data across emerging platforms that are increasingly used to conceal digital evidence.

iOS 18.4 Now Supported

XRY now offers full decoding support for iOS version 18.4, keeping your investigations aligned with Apple’s most recent software updates.

What’s New in XRY Pro?

Full File System Access for Pixel Devices

XRY 11.0.1 Pro introduces a new Full File System (FFS) extraction solution for Google Pixel 6 and Pixel 8. Investigators can now use the respective Generic profiles in XRY Pro to access deeper, more comprehensive data from these widely used Android models.

Latest Samsung Devices

Investigators can now brute force and extract data from the Samsung Galaxy S25, one of the most advanced flagship devices on the market.

Broader Qualcomm Support

Improved support has been added for devices with Qualcomm chipsets manufactured between 2018 and 2020, including select mid-range and legacy models.

Stronger Exynos Extraction

XRY Pro brings enhanced robustness for Samsung Exynos chipset extraction, improving reliability across a wide range of supported devices.

Brute Storm & RAMalyzer Improvements

Distributed Brute Forcing

Brute Storm has been upgraded to support more devices with Full Disk Encryption (FDE), expanding your brute-force capabilities where it matters most.

XRY RAMalyzer Enhancements

RAM analysis gets smarter with improved error messages, better command logic, and overall enhancements that make memory analysis faster, clearer, and more efficient.

Whether you’re investigating encrypted messaging apps, the latest Android flagships, or cutting-edge iOS devices, XRY 11.0.1 gives you the tools to go further and recover more. For the full list of updates, visit msab.com or contact us to book a demo.

Amped Authenticate Update Empowers Investigators With Expanded Tools For Deepfake Detection And Video Integrity Analysis

Amped Software is proud to announce the release of the latest Amped Authenticate Update. This substantial upgrade is designed to give you enhanced tools to validate image and video authenticity with even greater accuracy and efficiency.

If you work with digital evidence, this release directly supports your mission. Here’s what’s new and why it matters.

Enhanced Compression Analysis: Coding Tree Units Filter

How can visualizing video encoding patterns help uncover manipulation?

With this update, Authenticate introduces the Coding Tree Units (CTU) filter, previously available in Amped FIVE, now refined specifically for image authentication case work. This filter allows you to visualize both Coding Unit and Prediction Unit partitioning. It provides a deeper understanding of how a video has been encoded.

In addition, the filter includes powerful plotting features, enabling temporal analysis of encoding structures. This is critical when verifying the authenticity of videos that may have been re-encoded or manipulated. Detecting encoding inconsistencies can reveal hidden alterations, and this filter provides the precision needed to spot them.

Deep File Analysis: RIFF Viewer Tab in Advanced File Info

Working with AVI files? You’re going to love this. The new RIFF Viewer tab, under the Advanced File Info tool, lets you examine the internal structure of RIFF (Resource Interchange File Format) containers directly. This is particularly valuable when examining AVI files, a common format for surveillance and security video.

The RIFF Viewer gives you a dual-pane view:

  • Hex data on the left
  • Structured file components on the right.

Selecting any chunk instantly directs you to its file offset. This makes it easier to analyze, compare, and verify container structures, identifying tampering or inconsistencies quickly, even across multiple open instances. You can even open multiple files side-by-side for comparative analysis—an essential step when validating suspect media.

Strengthened Deepfake Detection: Flux Added to Diffusion Model Filter

The evolving landscape of AI-generated content demands advanced detection tools. This update strengthens the Diffusion Model Deepfake filter by introducing support for the Flux deepfake generation model, one of the latest and most realistic tools available today.

Flux can be run offline with modest hardware, making it an attractive choice for criminals seeking to bypass online safeguards. With the integration of Flux detection, you’ll be able to identify synthetic content using pixel-level CLIP feature analysis and machine learning classification. A robust approach, especially when metadata or container-level evidence is missing or unreliable.

Improved Redaction Tools: Inverted and Edge Feathering Modes in Annotate’s Hide

Accurate redaction is essential when working with sensitive content. This release introduces two new options within the Hide tool of the Annotate feature:

  1. Inverted mode allows you to redact the entire image except for a selected area—ideal when isolating key subjects while protecting identities or sensitive context.
  2. Edge Feathering smooths the borders of redacted areas, providing a cleaner, more professional visual output—perfect for courtroom presentations or internal reporting.

Ready to Update?

If your software maintenance plan is active, simply go to Help > Check for Updates Online within Amped Authenticate. For license renewals or support, please visit our Support Portal or contact your authorized distributor.

Read the blog post with all the improvements. Update now and take full advantage of these powerful new capabilities.

Cellebrite Unveils Spring 2025 Release To Accelerate Global Investigations

AI and Cloud as Strategic Foundations for the Next Era of its Digital Investigation Platform

Cellebrite today announced its Spring 2025 Release, featuring a new cloud foundation and AI-powered innovations across its portfolio. These enhancements are already playing an important role in helping customers modernize their digital workflows, speed up their investigations and elevate operational productivity and efficiency.

The Spring 2025 Release introduces the Cellebrite Cloud, which delivers a purpose-built user experience that scales investigative capabilities and accelerates decision-making across public safety, intelligence and enterprise sectors. As digital evidence continues to grow in volume and complexity, investigators now spend an average of 69 hours per case reviewing data. Cellebrite’s technology reduces that burden by delivering AI-powered productivity and efficiency across a secure, unified cloud infrastructure powered by AWS—while always keeping human expertise and engagement at the center. With more customers adopting a broader range of the Company’s integrated portfolio, Cellebrite is evolving its Case-to-Closure (C2C) Platform into the next-generation Digital Investigation Platform.

“Helping our customers navigate the growing complexity of digital evidence is at the core of what we do,” said Ronnen Armon, Cellebrite’s chief product and technologies officer. “More teams are rethinking how they approach digital evidence, and we’re introducing innovations to support that shift. Cellebrite Cloud enables a more efficient and secure approach to digital investigations, meeting teams where they are today and partnering for the future – whether it’s on premises, the cloud or a hybrid workflow.”

The Spring 2025 Release includes the following innovations, all of which are supported by expert consultative services to enable faster time to value:

  • Cellebrite Cloud, a new foundational layer across Cellebrite’s SaaS portfolio, brings consistent and purpose-built experiences, AI-powered productivity, advanced security and compliance and a framework for integrations.
  • Inseyets, Cellebrite’s flagship digital forensics software, introduces advanced media analysis capabilities—leveraging AI-powered forensic insights and pattern recognition to accelerate evidence review and understanding.
  • Guardian, Cellebrite’s evidence management solution, now includes timeline review and AI-powered search built on Cellebrite Cloud to surface hidden connections, streamline case organization and accelerate investigative workflows. Guardian continues to gain strong traction across agencies.
  • Smart Search, the Company’s single-click, SaaS-based intelligence offering for investigators, built on the Cellebrite Cloud, adds a new dashboard that highlights data connections and notable insights from publicly available sources, helping investigators gather online intelligence on people and organizations of interest more efficiently at the early stages of a case.
  • Pathfinder, the AI-driven investigative analytics solution trusted by leading law enforcement agencies, introduces automated transcription and translation workflows, simplifying the review of audio and video artifacts.
  • Endpoint Inspector, Cellebrite’s remote collection solution for enterprises, now offers Cellebrite Cloud-based mobile decoding that transforms mobile data into a review-ready format—eliminating the need for additional processing and integrating seamlessly with review platforms.

Cellebrite’s technology is used in more than 1.5M investigations globally each year, equipping more than 7,000 customers worldwide to resolve legally sanctioned investigations of child exploitation, homicide, anti-terror, border control, sex crimes, drugs and other organized crime, human trafficking, fraud, intellectual property theft, financial crimes, internal investigations, eDiscovery cases and more, while ensuring compliance with agency protocols and various regulatory requirements.

About Cellebrite

Cellebrite’s mission is to enable its global customers to protect and save lives by enhancing digital investigations and intelligence gathering to accelerate justice in communities around the world. Cellebrite’s AI-powered Digital Investigation Platform enables customers to lawfully access, collect, analyze and share digital evidence in legally sanctioned investigations while preserving data privacy. Thousands of public safety organizations, intelligence agencies, and businesses rely on Cellebrite’s digital forensic and investigative solutions—available via cloud, on-premises, and hybrid deployments—to close cases faster and safeguard communities.  To learn more, visit us at www.cellebrite.comhttps://investors.cellebrite.com and find us on social media @Cellebrite.

Media

Jackie Labrecque

Sr. Director of Corporate Communications + Content Operations

jackie.labrecque@cellebrite.com

+1 771.241.7010

Investor Relations

Andrew Kramer

Vice President, Investor Relations

investors@cellebrite.com

+1 973.206.7760

Passware Kit Mobile 2025v2 Accelerates MediaTek Decryption And Displays MD5 As Integrity Proof

Passware Kit Mobile 2025 v2 delivers faster and more reliable processing of MediaTek-based devices and expands the list of supported devices by 30+ new models.

This release introduces a powerful multi-threaded decryption method for Android devices with the F2FS file system, accelerating decryption speeds by up to 85% on popular models such as the Xiaomi Mi 9T, Note 7 Pro, and Samsung Galaxy A03.

MD5 hash values of extracted userdata and decrypted files can now be displayed and exported, providing verifiable proof of evidence integrity.

What’s New:

  • Improved processing of MediaTek devices
  • MD5 hash display for extracted userdata and decrypted files
  • Support for new TEE encryption for Xiaomi and other devices
  • Faster decryption of F2FS Android devices
  • Support for new Android devices
  • Support for Apple devices with iOS 15.8.4

Improved processing of MediaTek devices

There are multiple enhancements to the processing of MediaTek-based devices. These include more accurate bootloader data processing, improved USB connection stability, and support for EMMC-based devices on the MT6833 chipset—covering models like the Samsung Galaxy A14 and Huawei Honor Play6T. These updates deliver faster, more reliable processing and expand the list of supported devices by 30+ new models.

MD5 hash display for extracted userdata and decrypted files

Passware Kit Mobile now offers an option on the Tools menu to calculate MD5 hash values for extracted userdata and decrypted files. The process takes no longer than a few minutes and can be enabled or disabled as needed. Acquired MD5 values are automatically displayed on the PKM results page, providing verifiable proof of evidence integrity.

Support for new TEE encryption for Xiaomi and other devices

Passware has expanded its support for Trusted Execution Environment (TEE) encryption with two new types: MiTEE and Trusty/ISEE. This enables compatibility with a wider range of devices, including models from Xiaomi, SKY, and Maxwest.

Faster decryption of F2FS Android devices

PKM 2025 v2 introduces a multi-threaded decryption method for Android devices with the F2FS file system, including popular smartphones like the Xiaomi Mi 9T, Note 7 Pro, Samsung Galaxy A03, and Huawei P20 Lite. Previously implemented for Apple devices with the APFS file system, this enhancement boosts the userdata decryption speed by up to 85%.

Support for new Android devices

The list of supported devices has been expanded with two new models reported by our customers: Oppo Realme X and Samsung Galaxy A14 5G. We always appreciate your feedback!

See the full list of supported models.

Support for Apple devices with iOS 15.8.4

Passware Kit Mobile extends iOS compatibility by adding support for version 15.8.4. The update covers iPhone 6S and other Apple devices with A8/A8X/A9/A9X processors.

Usability improvements

PKM 2025 v2 features an updated License Manager that supports activation of multiple Product Keys, a convenient “Request to Support” form for submitting new devices to our Customer Support, and various minor UI improvements.

Read more about this update on the Passware blog.

Passware Kit 2025v2 Released: Decrypt Seagate and LaCie Drives

In this release, Passware focuses on HDD decryption and optimized allocation of hardware resources. It introduces password recovery for two new vendors—Seagate and LaCie—and enhances VeraCrypt decryption.

The new intelligent resource allocation algorithm accelerates concurrent processing of files in batch mode, improving overall efficiency.

The Apple Notes decryption feature now supports custom passwords for individual notes. Newly added file types include Bitcoin Core v.20+ and WinRAR v.7.

The refreshed user interface provides detailed information about recovery progress and hardware resource usage for each file. It also includes a new “Save Passwords” option, which exports the list of passwords found during the recovery process.

What’s New in Passware Kit 2025 v2:

  • Password recovery for Seagate and LaCie HDD
  • Password recovery for VeraCrypt volumes with BLAKE2s-256 encryption
  • VeraCrypt memory analysis: support for hidden OS for latest versions and faster processing
  • Smart resource allocation algorithm for distributed and batch processes
  • Password recovery for individual Apple Notes
  • Password recovery for Bitcoin Core wallets v.20 and higher
  • Password recovery for WinRAR v.7 and RAR hashes
  • Usability improvements
  • Website improvements: search option and updated Hardware Benchmark

For your convenience, we have included a video of all the latest features of Passware Kit 2025 v2. Take a look!

Password recovery for Seagate and LaCie HDD

Passware introduces hard disk decryption for two new vendors: Seagate and LaCie. This feature supports models 2018–2022, disks with multiple accounts, and GPU acceleration for password recovery. The average speed is 6,580 passwords per second on NVIDIA RTX 4070 Ti.

Password recovery for VeraCrypt volumes with BLAKE2s-256 encryption

Latest versions of VeraCrypt, starting from 1.26.7, feature a new hashing algorithm – BLAKE2s-256. Passware Kit 2025 v2 supports containers encrypted with this algorithm for GPU-accelerated password recovery. The average speed is 50 passwords per second on NVIDIA RTX 4070 Ti.

VeraCrypt memory analysis: support for hidden OS for latest versions and faster processing

Passware has upgraded its VeraCrypt decryption capabilities through memory analysis, now supporting hidden OS partitions in the latest VeraCrypt versions, while also doubling the overall decryption speed.

It also reports whether any of the VeraCrypt encryption keys extracted from a memory image may correspond to a different container.

Smart resource allocation algorithm for distributed and batch processes

Efficient utilization of hardware resources for batch password recovery is a top priority. Passware Kit 2025 v2 introduces a new resource allocation algorithm for concurrent file processing, minimizing hardware idle time and boosting batch mode efficiency.

Users can now monitor progress in real-time, with detailed information about the password recovery process displayed for each file, including current speed, the number of passwords checked, time elapsed, and more. The updated footer provides a comprehensive summary of the process.

Password recovery for individual Apple Notes

Passware Kit now offers selective password recovery for Apple Notes. Users can choose to recover passwords for all notes or individual ones, enabling the recovery of custom Apple Notes passwords.

Password recovery for Bitcoin Core wallets v.20 and higher

Password recovery for Bitcoin Core wallets has been expanded to support versions starting from v.20. The recovery speed now reaches 34,000 passwords per second on an NVIDIA RTX 4090.

Password recovery for WinRAR v.7 and RAR hashes

Passware expands password recovery for WinRAR archives by adding support for version 7.

Passware Kit also allow users to recover WinRAR passwords from hash files extracted by third-party tools, such as John the Ripper. The recovery speed exceeds 258,000 passwords per second on NVIDIA RTX 4090.

Usability improvements

Passware Kit 2025 v2 introduces redesigned “Items” (former “Files”) and “Attacks” tabs for batch password recovery. These updated tabs provide detailed information about the recovery process and hardware resource usage.

Additionally, the updated footer includes a “Save Passwords” button. This feature enables users to export the list of recovered passwords to a TXT file at the end of the batch process.

Website improvements: search option and updated Hardware Benchmark

To enhance navigation through Passware products, features, technical inquiries, and other requests, we have added a universal search feature to our website. It covers product pages, Knowledge Base articles, How-To guides, and blog posts.

Thanks to our customers who have shared their hardware performance tests, our Hardware Benchmark page now includes data for the NVIDIA RTX 5090, along with updated measurements for other GPUs. Want to contribute your own benchmark? Submit your CSV file generated by Passware Kit or Passware Kit Demo.

Read more about this update on the Passware blog.

Oxygen Remote Explorer v.1.8 Is Now Available

Agent Management Center Updates 

Remote Slack data extraction from Android devices 

We have added the ability to extract Slack data from Android devices via Wi-Fi using the new Android Agent available in the Agent Management Center. The extracted data set includes user info, linked devices, chats, contacts, later tasks, scheduled messages, and more. The ability to collect data from Slack addresses a critical need for modern investigations, as the platform is widely used in both personal and professional  environments. 

Computer Artifacts Updates 

New artifacts  

The following new computer artifacts are supported for extraction:  

  • Passwords from Bitwarden Password Manager web extension used in Brave, Chromium,  Google Chrome, Microsoft Edge, Opera, Vivaldi and Safari browsers from Windows, macOS and GNU/Linux 
  • Passwords from NordPass from Windows, macOS and GNU/Linux 
  • RustDesk data from Windows, macOS and GNU/Linux 
  • MetaMask web extension used in Brave, Brave Nightly, DuckDuckGo, Google Chrome, Microsoft Edge, Opera, Vivaldi browsers from Windows, macOS, and GNU/Linux

Additionally, we have introduced the ability to recognize virtual machines on target desktop  devices. 

Mobile Forensic Updates 

Selective app extraction for FFS extractions 

Now, specific applications can be selected when extracting the Full File System from  Android devices, eliminating the need and time required to extract all applications. This feature is currently available only when using the CVE-2024-31317 exploit. 

Decryption of additional user data from Qualcomm devices 

We have added support for extracting encryption keys and decrypting user data for additional users on Android devices based on Qualcomm chipsets. 

Android Agent supporting Android 15 

We have enhanced the Android Agent functionality, allowing data extraction from devices running Android OS 15. Extending Android Agent support to Android OS 15 enables investigators to gather evidence from more devices, enhancing efficiency and expanding  forensic capabilities. 

Import Updates  

Data Import via CLI  

Introducing the ability to import single or multiple extractions of the same type via the  command line. This ability can save time when importing multiple extractions into Oxygen Remote Explorer simultaneously and enables seamless integration with other solutions. 

Import of exported WhatsApp chats  

Oxygen Remote Explorer now supports importing exported WhatsApp chats and parsing messages with attachments and shared contacts. Providing an additional source of data from WhatsApp, one of the most widely used messaging platforms, is always valuable for  investigations.  

General 

Speech and Text recognition enhancements 

You can now perform speech and text recognition on files in the Messages, Applications,  Timeline, and Files sections. Simply right-click a file in the grid and select “Speech and Text  Recognition.” The recognized results will appear in the right panel. 

Export Updates  

Data export to Reveal eDiscovery software format

We have expanded our data export capabilities to include the export of data in the load file format, specifically designed for integration with the Reveal eDiscovery platform.  

Other updates to the Export engine include the ability to:  

  • Exclude messages based on tags when exporting from the Messages section
  • Export the Accounts and Passwords section data to JSON file format

For a full list of updates, refer to the “What’s New” file in the “Options” menu.  Interested in learning more about Oxygen Remote Explorer v.1.8?  

Contact Oxygen Forensics

About Oxygen Forensics 

Oxygen Forensics is a global leader in digital forensics software, enabling law enforcement,  government agencies, enterprises, law firms, and service providers to gain critical insights  into their data faster than ever before. Specializing in remote and onsite access to digital data from cloud services, mobile and IoT devices, drones, device backups, UICC, and media  cards, Oxygen Forensics provides the most advanced digital forensics data extraction  capabilities, innovative analytics tools, and seamless collaborative analysis for criminal and  corporate investigations to bring insight and truth to data. 

Oxygen Analytic Center v.1.4 Is Now Available

The Oxygen Analytic Center v.1.4 update is now available and includes the features described below:  

Visualizing Common Locations  

Oxygen Analytic Center v.1.4 enables users to visualize common locations in the Map section, indicating whether multiple people were at the same place within a specified timeframe. Visualizing common locations in several clicks enables users to quickly determine where device owners were, eliminating the need for time-consuming manual analysis. 

Bulk User Creation Via CSV File 

Oxygen has simplified user administration. Now you can create multiple users at once by uploading a CSV file. There are two ways to do this: 

  • Download a CSV file with existing users from Active Directory 
  • Use our CSV template to enter your user data manually 

Bulk user creation from Active Directory CSV file or a CSV template streamlines user administration, eliminating the need for time-consuming manual data entry.  

Import Enhancements  

Oxygen has introduced several enhancements to data import and processing.  

  • Enabling and disabling advanced analytics. Users can manage device analytics processing to optimize system resources and performance. By default, all analytics  features are enabled, but you can disable ElasticSearch, Text Analyzer, Image  Categorization, Facial Categorization, or OCR if they are not needed for your investigation. Analytics can be re-enabled at any time.
  • Multiple Image Import. Users can now select and upload multiple images at once. They will be processed in a queue, saving time with just a few clicks. 
  • Detailed Import Progress. The import process now provides step-by-step details,  showing exactly what the software is doing in real time. 
  • Faster Import Speeds. Thanks to internal optimizations, extractions are imported and processed faster. However, speed may still vary based on extraction size. 

Accelerating data import while providing detailed progress improves efficiency and enhances interface clarity.  

Interested in finding out more about Oxygen Analytic Center?

Schedule Demo

About Oxygen Forensics 

Oxygen Forensics is a global leader in digital forensics software, enabling law enforcement,  government agencies, enterprises, law firms, and service providers to gain critical insights into their data faster than ever before. Specializing in remote and onsite access to digital data from cloud services, mobile and IoT devices, drones, device backups, UICC, and media  cards, Oxygen Forensics provides the most advanced digital forensics data extraction  capabilities, innovative analytics tools, and seamless collaborative analysis for criminal and  corporate investigations to bring insight and truth to data. 

Amped Software Upgrades Amped Replay With Improved Features For Police Investigators

Advanced Bookmarking, Improved Motion Detection, and More Efficient Audio Redaction

Amped Software is starting the year strong with a significant update to Amped Replay, the forensic video player for police investigators. This latest release introduces enhanced bookmark customization, refined motion detection capabilities, improved audio redaction and a shift to the modern MKV format. These developments allow for greater efficiency in your day-to-day investigative workflow.

Update Now
Learn More

Enhanced Bookmark Exporting – More Control, Better Reporting

With this update, Amped Replay gives you the possibility to export multiple bookmarks for the same frame. You can now generate up to three bookmarks for a single frame – original, enhanced, and annotated.

This allows you to present evidence with more clarity. Whether you need to maintain an unprocessed log or highlight crucial objects, you can customize how each bookmark appears in your report. This feature ensures seamless organization and documentation of critical video evidence.

Improved Motion Detection – Enhanced Accuracy

Motion detection is essential when analyzing lengthy CCTV footage, and now it is more adaptive and precise, with an improved threshold slider that automatically adjusts to the maximum detected motion during analysis. This enhancement allows you to fine-tune motion sensitivity with greater accuracy, filtering out irrelevant movement and saving you time while ensuring significant events are not overlooked.

Audio Redaction Made Easier

Amped Replay’s Audio Redaction tool has been upgraded to provide you with greater precision and flexibility. You can now visually stretch an audio redaction interval in the waveform bar for precise frame-by-frame adjustments. This makes it easier to redact sensitive information efficiently, maintaining the integrity of your investigation while protecting privacy.

MKV Conversion – A More Reliable and Robust Format

Amped Replay now defaults to the MKV format for video conversion and export, replacing the legacy AVI format. The MKV (Matroska) format is more stable as it reduces decoding errors and ensures better compatibility with modern forensic tools. If an older codec is incompatible with MKV, the software automatically reverts to AVI, ensuring smooth video processing without interruption.

Why Does This Matter for Police Investigators?

Amped Replay is designed to empower law enforcement with an intuitive, simple and powerful video analysis tool. These latest improvements mean faster video evidence handling and processing, improved accuracy, and flawless reporting. Replay helps you work faster and more effectively when analyzing video evidence.

Ready to Upgrade?

If you are an Amped Software user with an active support plan, you can easily update your software version directly from within the application. If you need to renew your Software Maintenance and Support (SMS) plan, contact Amped Software or an authorized distributor. For more details, visit the Amped Support Portal.

Don’t delay – read the full blog post to explore these powerful new updates in greater depth!

Introducing Oxygen Remote Explorer Version 1.7.1 – Available Now

The latest version of our remote collection solution is here! Oxygen Remote Explorer v.1.7.1 introduces enhancements to the Agent Management Center, new extraction capabilities, and more. Take your corporate or law enforcement investigation to the next level with this new version. 

Selective Remote WhatsApp Extraction Enhancements  

We’ve added a new extraction option for selective remote collection of WhatsApp and WhatsApp Business data from Android devices. Users can now extract all messages or only new ones from WhatsApp chats and communities based on a selected time range.

This feature enhances data extraction flexibility and improves efficiency, saving time during investigations. 

Integration of OCR and AST Results in Messages 

Optical Character Recognition (OCR) and Automated Speech Transcription (AST) results are now seamlessly embedded within the Messages section, maintaining a natural conversation flow.  

Users benefit from seamless integration of OCR and AST results within messages, ensuring a natural conversation flow without disruptions.  

Translation of Recognized Text 

Recognized texts from the Optical Character Recognition (OCR) and Speech-to-Text engines can now be translated into all supported languages listed in the Speech and Text Recognition section.  

This feature streamlines the process by allowing investigators to recognize and translate text within the same interface, and seamlessly export translations into reports. Consolidating these tasks enhances efficiency and ensures accurate, consistent documentation for more effective investigations.  

For a full list of updates, refer to the Release Notes

Interested in learning more about Oxygen Remote Explorer v.1.7.1? Contact us.  

About Oxygen Forensics 

Oxygen Forensics is a global leader in digital forensics software, enabling law enforcement, government agencies, enterprises, law firms, and service providers to gain critical insights into their data faster than ever before. Specializing in remote and onsite access to digital data from cloud services, mobile and IoT devices, drones, device backups, UICC, and media cards, Oxygen Forensics provides the most advanced digital forensics data extraction capabilities, innovative analytics tools, and seamless collaborative analysis for criminal and corporate investigations to bring insight and truth to data.