
The updated Oxygen Forensic® KeyScout allows investigators to capture memory (RAM) and save it in RAW format for further analysis in third-party solutions, like Volatility. To do this, switch to the Settings menu and select one or several preferred hash sets: SHA1, SHA256, SHA3-256 or MD5. Investigators can now choose to calculate hashes for extracted physical dumps in the Oxygen Forensic ® Android Extractor. The evidence set includes contacts, messages, calls, calendars, available files and supported third-party apps. Investigators can now use the powerful OxyAgent utility to extract evidence from any unlocked Android device. OxyAgent is now compatible with Android devices running OS 11. The Security Patch Level (SPL) must not be greater than December 2020. The new exploit allows investigators to gain root rights and extract a full file system. The Android full file system extraction method now offers additional capabilities for devices using Qualcomm chipsets and running Android OS 7 through 10. The functionality is available within the Huawei Android Dump method. To decrypt this securely hidden data, investigators will need to either enter the password or find it with the built-in brute force module. Oxygen Forensic ® Detective v.13.5 now gives investigators the ability to access data in the Huawei Private Space. Huawei Private Space lets users store their private information in a hidden space within the device that can only be accessed with a fingerprint or password. Only for Samsung Exynos devices with FBE. That enables users to store private data.

The Secure Folder is a secure location within a Samsung device New approach also gives investigators access to the Samsung Secure Folder and (FDE), this method does not currently include the ability to brute force the

Unlike our SamsungĮxynos method for Android OS 7 through 9 devices with Full-Disk Encryption If a user passcode is set on a device, it shouldīe entered in the corresponding field in the software.

Samsung devices running pre-installed Android OS 9 and 10 which also haveįile-Based Encryption (FBE). Now investigators can perform full-file system extractions of Facebook 0 Tweet 0 LinkedIn 0 Support for Samsung Exynos devicesįorensic ® Detective v.13.5 brings enhanced support for SamsungĮxynos devices.
