Oxygen Forensic® Detectivev.10
Total Page:16
File Type:pdf, Size:1020Kb
Release notes November 2017 Oxygen Forensic® Detective v.10 NEW CLOUD SERVICES ADVANCED WHATSAPP EXTRACTION Oxygen Forensics extends inves�ga�on capabili�es with a We’ve added two industry-first features in the algorithm of number of new cloud services and delivers the industry first WhatsApp data extrac�on. support for them. Mi Cloud. Xiaomi phones are quite popular these WhatsApp backup decryp�on with 2-step days as they give users great specs and value for verifica�on. money. Xiaomi users can store their contacts, calls, This verifica�on is an op�onal feature that adds messages, calendar, and other personal data in Mi Cloud. more security to the account. If it is enabled, any The updated Oxygen Forensic® Cloud Extractor offers a a�empt to verify the phone number on WhatsApp must be brand-new ability to extract all available informa�on from accompanied by the six-digit PIN created by the user. The Mi Cloud via login/password or token. decryp�on of WhatsApp backup is not possible without Workplace by Facebook. This is a collabora�ve the PIN code. The latest Oxygen Forensic® Cloud pla�orm used to communicate via groups and to Extractor offers either the opportunity to enter the PIN (if chat with colleagues in a corporate environment. it is known) or several ways to deac�vate it. Once the While extrac�ng a mobile device, forensic experts may find PIN is entered or deac�vated forensic experts can an app token that can be used to enter Workplace account extract and decrypt full WhatsApp backup from iCloud or and download groups, chats with a�achments, and other Google Drive. The backup usually contains data on the available data. account owner, his/her contacts, chats, and calls. Samsung Gallery. Oxygen Forensic® Detec�ve now Unique WhatsApp data from the server. extracts photos, videos and documents (both live We’ve added a special WhatsApp Cloud service and deleted) from Samsung Cloud. Photos and videos are that allows forensic experts to acquire undelivered acquired together with geo coordinates that can be opened messages with a�achments, missed calls, contacts, in Oxygen Forensic® Maps. and informa�on about groups and their par�cipants Samsung Cloud backup. Now forensic experts can directly from the WhatsApp server. This service can be import and parse complete Samsung Cloud extremely useful in case when the device is damaged, backups that can be accessed via login/password locked, or missing. Following the instruc�ons for the or token. Backups may contain contacts, calls, messages, WhatsApp Cloud service, forensic experts can obtain calendars, files, and Wi-Fi history. access to WhatsApp server even without the need for a mobile device itself. Oxygen Forensics, Inc 901 N. Pitt St, Suite 100100 Alexandria, VAVA 22314 TelTel : 844 537-2537 Fax : 877 462-2134 Release notes November 2017 Oxygen Forensic® Detective v.10 APPLICATIONS UNSUPPORTED APPS PARSING Some popular apps have their own clones NEW that are not widely-known and can be used IOS by criminals to hide their ac�vi�es. In Bread Wallet (0.6.7) Oxygen Forensic® Detec�ve v.10 forensic Facebook Workplace (143.0) experts can parse such unsupported clone apps using a supported app template. For FreeFlight Pro (5.0.2) example, there is a number of Telegram ANDROID Messenger clones that now can be parsed Facebook Workplace in Oxygen Forensic® Detec�ve even if they (141.0.0.31.91) are not officially supported. FreeFlight Pro (5.0.2) SELECTIVE PHYSICAL EXTRACTION Workplace Chat (141.0.0.32.76) Now, before performing a physical extrac�on or dump import, forensic experts UPDATED can choose which sec�ons should be IOS parsed from a mobile device. Oxygen Facebook Messenger (141.0) Forensic® Extractor shows a list of sec�ons Google Chrome (60.0.3112.72) to be selected for parsing. This feature can Google Duo (21.0) be of u�ermost importance when an inves�gator is authorized to extract only GroupMe (5.12.5) par�cular type of evidence. Moreover, Instagram (21.0) selec�ve reading significantly speeds up the KakaoTalk (6.5.1) extrac�on process. Kik Messenger (11.33.0) DRONE SUPPORT ENHANCEMENTS Passbook (11.0) The updated program version allows to Skype (8.8) import and merge several dumps of the Telegram (4.4) same drone together. If forensic experts Twitter (7.10) have two separate dumps of external and Viber (7.9) internal drone storages, now, they can merge them to be able to analyze drone Visa Qiwi Wallet (5.19) data in one view. Moreover, Oxygen Wechat (6.5.21) Forensic® Detec�ve v.10 supports DJI WhatsApp (2.17.71) Metrice 600 drone and parses FreeFlight ANDROID Pro app from iOS and Android devices. Facebook Messenger (142.0.0.18.63) SCREEN LOCK BYPASS FOR MOTOROLA DEVICES Google Chrome (60.0.3112.116) Now, forensic experts can bypass screen lock on a larger amount of Motorola Google Duo (21.0) devices: Moto XT1684, Moto XT1685 (Dual SIM), Moto XT1687 (USA), Moto XT1681, Google Hangouts (22.0) and Moto XT1683. Instagram (21.0) 2FA SUPPORT FOR ICLOUD SERVICES KakaoTalk (6.4.6) We’ve added support for 2-factor authen�ca�on to iCloud services. Now, forensic Kik Messenger (11.37.0.18906) experts can acquire iCloud data even with the 2FA enabled. Telegram (4.4.2) PREDEFINED KEYWORD LISTS Twitter (7.20.0) Three new predefined keyword lists are now available in Keyword Manager. Forensic Viber (7.9.0.6) experts can apply Guns, Human Trafficking or Money Laundering keyword lists to find Visa Qiwi Wallet (3.7.0) the required evidence. Wechat (6.5.16) IMPROVED SQLITE VIEWER WhatsApp (2.17.395) We’ve added several significant interface improvements to the SQL Editor: display of And many more! the linked table, naviga�on in the linked table, and highligh�ng of the linked fields. Oxygen Forensics, Inc 901 N. Pitt St, Suite 100 Alexandria, VA 22314 Tel : 844 537-2537 Fax : 877 462-2134 .