Oxygen Forensic Suite 2014 Analyst with USB dongle
lets you to extract most of the information from Nokia, Blackberry, Windows Mobile (PDA), Samsung, Benq-Siemens, Sony-Ericsson, Motorola, Panasonic and Vertu mobile phones. A special software for Police Departments, Law Enforcement units and all government services that wish to use the power of Oxygen Forensic Suite 2 for investigation purposes. Forensic Edition secures phone data to remain unchanged during extraction and exporting.
GSM-SUPPORT has direct authorization from producer to
sell all Oxygen Software products.
You can examine:
Contacts list (in phone memory as well as at SIM card) including all contact fields available for the specific phone model.
Incoming/outgoing/missed calls data.
Tasks and to-do items.
Logos (startup, operator, group).
SMS and MMS messages (including the messages stored in custom folders).
FM stations list.
Gallery and Flash card files.
Java applications and games.
WAP settings and bookmarks.
GPRS access points.
All information can be either viewed using the convenient program interface or exported to many different formats. .
Oxygen Phone Manager II has full Unicode support - you can easily view and extract information in any language.
Device information section displays complete technical information about the device. This includes Manufacturer, Retail Model Name, Platform and its revision, IMEI, MAC addresses, IMSI, Serial Number, phone number and any other model specific data.
Here experts can find a brief statistics of the device, the number of entries in each section split by data type and quickly move to the needed data.
Section also summarizes and displays user accounts gathered through all data extracted from the device.
To make device recognizable in the database, forensic experts add device/user photos and brief description of the item.
Phonebook section contains users' contacts with all its data: name, occupation, phone numbers, addresses, emails, notes.
Depending on the device experts gain access to the private information of the contacts, like birthdays, relatives' names and anniversaries.
Section provides convenient way to find information using Quick filter. Found contacts will appear immediately once expert starts typing query. Favorites and Birthday Center are the tools that indirectly points to the important contacts.
Experts can customize report layout and then easily print or export all marked or filtered contacts. Important contacts can be marked as Key Evidence and then analyzed separately with additional marked data.
Messages section contains users' correspondence including SMS, MMS, Emails, iMessages and other depending on the device type.
Recovering deleted messages is available for certain types of devices: iOS, Android OS and Symbian OS smartphones.
There are a lot of messages in seized devices usually. Messages section provides convenient way to analyze them: quick filter on toolbar, context filters in grid headers, folders tree view. These tools help exerts find needed data and prepare it for report.
Experts can preview generated report, customize its layout if needed, and then print or export messages with or without attachments.
Using built-in viewer experts can analyze attachments and technical headers of the message. Each attachment can be saved in a separate file for future analysis.
Event Log section contains users' voice communication: dialed, received and missed calls. Experts find here call time, duration and remote party.
Recovering deleted calls is available for certain types of devices: iOS and Android OS smartphones.
Making calls is a primary feature for a phone. Event log section provides access to all calls made by the phone user and provides tools to analyze them. These are quick filter on toolbar, context filters in grid headers, date filter on sidebar. These tools help exerts find user calls at a certain period of time, call direction or communication with a contact.
When the call event doesn't have the name of the caller, Oxygen Forensic® Suite looks for this data in Phonebook. If the phone number is found, it displays the name in Event Log and fills the cell background with green.
Calendar & Tasks
Organizer section displays notes, tasks, and calendar entries created or synchronized by device user.
The set of sub-sections and their features depends on the seized device manufacturer and exact model.
Calendar is the most data-rich part of organizer. Events have text label, location, start date, end date, alarm and recurrence. Notes are the entries with large text fields and time stamp. Tasks are the kind of calendar events that have special Done flag to mark the state of the item.
In Oxygen Forensic® Suite experts get access to all these types of data in a convenient sheet-like view. Quick filter and sorting capabilities helps to find and analyse data. Special Time Zones tool converts dates to a local or any other time zone.
Forensic experts can mark the items as Key Evidence with one click, report, and print all or selected entries only.
File Browser section is a powerful tool to access and analyze user photos, videos, documents and device databases.
Built-in text, hex, multimedia, SQLite, Plist viewers, Geo-location and EXIF extractors help experts to view files and their properties.
File Browser gives the access to all files extracted from the device in a tree-based structure. Additionally experts can view files in selected only folders, grouped in tabs by type, or in search tabs created when Quick filter was applied.
Oxygen Forensic® Suite automatically extracts Geo-location data from multimedia files and offers shortcut to view the place on the map where the action took place. Additionally, it looks into EXIF headers for specific tags like Make, Model, time stamps which helps forensic experts to determine file origin. Basic data about the file is displayed on the left sidebar, while file attributes and additional tags are available via popup menu.
Section has a two-panel multipurpose viewer, where experts view the file in a raw, hex mode, or run appropriate player for the media file. Additionally, double clicking on a file opens appropriate viewer in a separate window. Databases and configuration files will be opened with built-in Oxygen Forensic® SQLite Viewer and Oxygen Forensic® Plist Viewer.
Investigators can save files, whole folders on PC, mark the items as Key Evidence, print and prepare reports, export Geo data to Google Earth.
When it comes to solving a crime, reports are one of the most important things for the investigator. Popular file formats and ability to export or print the whole set of data or only important parts helps experts to show the result of their work in the best way.
In Oxygen Forensic® Suite forensic experts can export any data from any section. This can be a report of the whole device or several sections or even several entries. Everything depend on the need of the investigator.
We support all popular file formats: Adobe PDF, Microsoft Excel, HTML, Rich Text Format (RTF), and XML. Each format has own best place to apply. For example, PDF is good for printing, while XML can be used by 3rd party data parsers to import data extracted by Oxygen Forensic® Suite.
Reports section is a place where expert can find reports generated for selected device with brief data about the report: date of creation, sections in the report, its path and name. Section also can check if the report was changed after generation and let expert know about it.
Analyze contacts from multiple sources such as the Phonebook, Messages, Event Log, Skype, chat and messaging applications in Aggregated Contacts.
Section automatically reveals same people in different sources and groups them together in one meta-contact.
When the contacts have no matches, but forensic expert detected that the contacts in various sources belong to one person, he can manually merge these contacts. Later this contact will be used as a single item for Links and Stats analysis.
Section offers quick filter functionality, convenient data sources filter and sorting for faster analysis.
Preparing and printing reports is easy as in every section of Oxygen Forensic® Suite.
Rooting a device based on Android OS reveals the complete set of user data to the investigator.
Generally this procedure needs certain knowledge and research, but Oxygen Forensic® Suite helps experts to automate this operation.
Rooting procedure is a part Data Extraction Wizard that guides you through the whole process of gaining the root rights to the device. The important benefit of the proprietary method is that the root access will be revoked immediately after rebooting the device. This method makes rooting and further extraction completely forensic and safe.
Android Rooting add-on grants an access to:
Full file system, stored both on internal memory and memory card
Application saved data including logins, passwords, history, cache and much more
Geo-location information for tracking suspect position in the past
Deleted data in database tables
No 100% successful rooting is guaranteed. The procedure is available for the most of Android devices with versions 1.6 - 2.3.4 and 3.0 - 4.2.2.
Oxygen Forensic® Suite retrieves numerous application data from a mobile device. In the Applications section, forensic experts view the list of pre-installed and user applications with the files created by these programs.
Each application can contain valuable user data, like passwords, logs, history, files and so on.
Section offers the following main features:
Get logins and passwords to the app
Find geo-location of the last run
Inspect all used or created app files
Know exactly when the app was used
Access to system and user apps
Filter apps by a certain term
Export and print selected items
Many popular applications have a special User Data data tab where investigators find application data categorized and prepared for effective analysis.
Forensic experts can always access source files to learn how Oxygen Forensic® Suite gathers information for User Data tab or to analyze applications that were not automatically prepared.
Oxygen Forensic® Suite is the only smart phone forensics software that allows analyzing Applications in such a deep and structured way.
Oxygen Forensic® Suite grants the access to popular Navigation applications and reveals POIs, routes and searches that device user made.
Skype & Messengers
Oxygen Forensic® Suite supports a lot of mobile messengers like Skype, Facebook, WhatsApp, Viber and others.
Oxygen Forensic® Suite can detect spyware apps installed on Android and Apple devices, discover and process their logs and configuration files.
Oxygen Forensic® Suite supports all popular Web browsers for Android OS, Apple iOS and Symbian OS platforms.
Extract data from the backup files acquired from suspects' computers or portable drives.
iTunes, Android, Blackberry backups, DMG or other forensic software images will appear in Oxygen Forensic® Suite like data extracted from the real device.
BBB and IPD are the Blackberry device backup files made with Blackberry Desktop Manager. These files can be found on a suspect computer or external media like CD, DVD, memory disks and cards etc.
Oxygen Forensic® Suite is able to extract and present forensically important information from these backup files.
iTunes backup found on a suspect computer is a regular practice due to the popularity of Apple devices.
Oxygen Forensic® Suite offers experts an easy way to extract suspects' private data from the iTunes backup files.
Chinese Phones Support
Chinese Phones Support enables forensic experts to extract data from popular phone replicas and low-cost devices.
Oxygen Forensic® Suite is able to acquire from Chinese devices important user data like event log, messages, contacts and files.
Chinese-branded phones occupy a major part of the Asian mobile market, and are on the rise in North American, European and international markets due to their low cost and a better value-for-money than offered by traditional manufacturers. In emerging markets, Chinese-branded phones dominate in the low-budget niche. North American and European wireless communication companies often give these low-cost devices away to new customers and prepaid users.
Oxygen Forensic® Suite handles a huge variety of devices based on MTK (Mediatek) chipset and grants forensic access to the following user data:
Basic information. This including IMEI/IMEI2, hardware revision, firmware revision and baseband.
Phonebook. Retrieve contacts from SIM and phone memory, access groups details.
Call Log Includes dialed, answered and missed calls..
Messages: SMS and MMS in default folders.
Files In phone memory and external memory card.
Various data viewers help experts to analyze extracted data in a convenient way.
Oxygen Forensic® Suite has built-in HEX-viewer, picture viewer, music and video players, text viewer with code page converter, HTML, SQLite and Plist Viewers.
Modern mobile devices create numerous number of files during their life cycle. The very basic tool to open them is HEX viewer that will allow analyzing data in a raw manner. Built-in HEX viewer in Oxygen Forensic® Suite allows experts to search data, make bytes conversions of the selected parts, save files on disk.
In case of multimedia files it is convenient to use built-in media player that will allow to play recorded video and voice messages, and view camera shots. Additionally, forensic experts can view EXIF information and Geo-data if they are available.
For text documents and saved or cached web pages Oxygen Forensic® Suite offers text viewer with code page setup and safe web browser.
SQLite Viewer allows to explore the database files with the following extensions: .sqlite, .sqlite3, .sqlitedb, .db, .db3.
Experts have the access to the actual and deleted data stored in databases created by system and user applications.
Plist files, known as Property List XML Files, contain a lot of valuable forensic information in Apple devices. Browser history, Wi-Fi access points, speed dials, Bluetooth settings, global applications settings, Apple Store settings and even more data can be extracted from .plist files.
Dictionaries section shows all the words ever entered in device messages, notes and calendar.
These are not words from the device system dictionary, they are from unique user dictionary that is created by device owners when using it.
Dictionaries section main features:
View all words entered by a suspect
Choose certain language on demand
Find out each word usage frequency
Reveal the order words were used
Filter words by language
Export and print selected items
Dictionaries section provides a list of words entered by a suspect. Forensic expert can determine the order that the words appeared, how often the word was used, filter and reorder the words in the list.
Phrase simulation feature is a highly valuable tool for an expert. Using it he can suppose the phrases that the suspect typed. This can be a password, address, or even a deleted message.
Global Search allows discovering user data in every section of the device.
Tool offers searching for text, phone numbers, emails, geo coordinates, IP addresses, MAC addresses, Credit Card numbers. Regular expressions library is available for more custom search.
Forensic experts can search data in a single device, all devices of the case, or all acquired devices. They can choose the sections where to search the query, apply boolean terms, or chose any of predefined patterns.
Keyword list manager allows creating custom set of terms and perform search for all these terms at once. For example, these can be the lists of names or the set of offensive words and phrases.
Global Search tool saves all results and offers printing and preparing reports for any number of searches.
Key Evidence section offers a clean, uncluttered view of evidence marked as essential by investigators.
Forensic specialists can mark certain items belonging to various sections as being essential evidence, then review them all at once regardless of their original location.
Key Evidence is an aggregated view that can display selected items from Phonebook, Calendar, Messages, Camera shots, Web Connections and Location Services, Applications, as well as other sections available in Oxygen Forensic® Suite. The section offers the ability to review relevant information at a single glance, concentrating one’s efforts on what really matters and filtering out distracting, unimportant data.
Forensic examiners are able to sort, filter and group data for the best viewing results. Tagging and notes makes Key Evidence section even more convenient to use.
Oxygen Forensic® Suite is the only one cell phone forensics software that allows investigator to browse all important data in one place.
Links and Stats
Quickly reveal social connections between users of mobile devices under investigation and their contacts.
Links and Stats section provides a convenient tool to explore social connections between device users by analyzing calls, text, multimedia and e-mail messages and Skype activities.
Diagram view with a graphical chart presents a quick overlook of communication circles, allowing forensic experts to determine and analyze suspects’ communications with all details at a glance.
Switching to the table view offers in-depth analysis of the device user’s communication including all contacts, phone numbers, and remote parties. Along with communication duration it produces a concise summary of the forensically important data.
Oxygen Forensic® Suite offers investigators the ability to analyze interactions among users of multiple seized mobile devices. The feature builds and displays a Links and Stats diagram with a chart for multiple devices, clearly visualizing connections between the phones’ users.
Passwords section displays logins and passwords extracted from default secure storage like keychain database.
Applications files can also contain this valuable data. Oxygen Forensic® Suite parses them for it and displays nearby
Password recovery is available for iOS and Android devices.
In Apple iOS devices including iPhone and iPad, sensitive information is stored in the keychain. The keychain provides means to securely store data such as passwords to email accounts, Web sites and certain third-party software, as well as other private, financial and sensitive data.
The content is stored securely encrypted with device-specific hardware keys that are unique to each individual device. Oxygen Forensic® Suite adds the ability to access protected content stored in the keychain, extracting and displaying user passwords.
More passwords are hidden in applications files. Passwords section also extracts this data and displays passwords from applications at one place.
Social Graph visualizes complex connections inside crime groups.
This is a highly adjustable workplace that allows forensic experts to review connections between mobile device owners and their contacts, pinpoint connections between multiple device owners, and detect their common contacts.
Oxygen Forensic® Suite builds Social Graph basing on communication activity of device owners. The graph is not static, experts are free to manipulate the way it looks like by moving, hiding and merging contacts.
Investigator can also change the date range to reveal most popular connections in a certain period of time or/and set the minimum number of connections for the contacts to be displayed.
Social Graph contains information about each displayed owner and contact like preferable types of communication, the first and the last date of communications, total time spent in talk and number of messages sent each other.
Additionally, forensic expert can the change layout of the graph using mouse and keyboard shortcuts, view it in full-screen mode, save to a file for future reports.
Timeline allows to view all facts of mobile device usage in one sorted list.
This section organizes all calls, messages, calendar events, geo data and other activities in chronological way, so you can easily follow the conversation history without the need to switch between different sections.
Timeline is available for a single device and for all devices belonging to a case, revealing the complete event list occurred.
Forensic examiners will be able to sort, filter and group phone activity list by dates, people specific phone numbers and geo data activity.
A graphical chart is available to display user activities for selected periods of time. The chart allows grouping all possible mobile device events over different time intervals (from one second to one year) and filtering them by various parameters.
The chart enables forensic experts to easily analyze detailed activities of a single contact or group of contacts at a glance.
Printing and exporting data in popular formats is also available in Timeline section.
Web Connections & Locations
Web Connections & Locations section reveals suspects' visited places and routes.
Experts can analyze several sources of Geo data: Wifi connections, IP connections and Locations databases.
With Wi-Fi Connections list forensic experts are able to determine where and when suspect used Wi-Fi internet access (public or even private) and ascertain his location.
Entries in hot spot list have the following parameters: hotspot name (SSID), hotspot BSSID (MAC-address) and RSSI (Signal level), last time when suspect used hotspot. Processing this data Oxygen Forensic® Suite acquires geo-coordinates and mini-maps for each location.
IP Connections tab shows all the history of Web connections (Wi-Fi, GPRS, LTE) and their details: MAC and VPN addresses, device and router IPs, DNS name, region, time stamp, etc.
Locations tab represents consolidated.db and cache_encryptedA.db files contents in an extremely convenient way. Initially these files store all the network activity of the device basing on GPS/Cell/Wi-Fi data. Experts can track device movements and determine device owner location basing in Locations data.
Experts can view geographical coordinates and maps directly in Oxygen Forensic® Suite or export data to KML format to see the route in Google Earth application. Standard reporting and printing features available.
More than 2500 mobile device models are supported. And the list is rapidly growing! Using low-level protocols and straight access to phones allows Oxygen Forensic Suite not to be limited by GSM models, but also support CDMA and DAMPS phones!
The list of supported models is constantly growing.
Oxygen Forensic Suite 2014 is generally recognized in police departments and law enforcement units of many countries: USA, United Kingdom, Germany, Netherlands, Australia, Finland, Norway, Sweden and others.
Oxygen Forensic Suite 2 works under Microsoft Windows 2000, Windows XP and Windows Server 2003 operating systems family.
Supported connection types: DAU-9P cable, any technological F-BUS cable, DLR-3P cable, DLR-3P cable, DKU-5 cable, DKU-2 cable, CA-42 cable, CA-53 cable, CA-70 cable, DKE-2 cable, Infrared adapter, Bluetooth adapter.
Oxygen Forensic Suite 2014 Analyst with USB dongle
license for 1 computer delivered via e-mail
free updates and technical support for 1 year since date of purchase