Oxygen Forensic Detective 18.3 (Features & Guide)

Oxygen Forensic Detective 18.3 (Features & Guide)

Overview of Oxygen Forensic Detective

Oxygen Forensic® Detective serves as a comprehensive digital forensics toolkit designed for law enforcement, corporate security teams, and forensic investigators. The platform enables extraction of evidence from mobile devices running Android, iOS, and other operating systems, as well as cloud accounts, drones, and computer systems.

The software stands out for its ability to recover deleted messages, extract encrypted data, and create visual connections between people, locations, and communications. Users consistently praise its reliability and efficiency, with one expert noting it “keeps evolving, staying ahead of challenges like encrypted data, cloud extractions, and ever-changing app security”.

Key capabilities include:

  • Mobile device extraction and analysis

  • Cloud data collection from 107+ services

  • Computer forensic acquisition and artifact analysis

  • Passcode recovery for encrypted files and partitions

  • AI-powered facial categorization and speech recognition

Key Features

Comprehensive Mobile Extraction

Oxygen Forensic Detective supports data acquisition from a wide range of mobile devices. The platform extracts information from Android devices using multiple methods including physical acquisition, full file system extraction, and logical backups. For Qualcomm-based Android devices, the software can extract encryption keys and decrypt user data across multiple user profiles.

iOS device extraction supports methods including checkm8, iOS Agent, and iOS SSH, with continuous updates for newer iOS versions. The platform also handles feature phones, including Unisoc-based devices like Alcatel 3080G, Nokia 225 4G, and various other models.

Supported platforms and connection methods:

  • Android, iOS, KaiOS, and feature phone operating systems

  • USB cable and Bluetooth connectivity

  • Multiple extraction methods per device type

  • Single-session sequential extraction methods via the Chain method

Cloud Extractor

Oxygen pioneered cloud extraction in 2014 and continues leading this space with support for over 107 cloud services. Investigators can collect account information, chats, posts, notifications, and subscriptions from platforms including Google, Discord, Steam, TikTok, X (Twitter), and Snapchat.

Cloud extractions operate point-to-point, with no data passing through Oxygen servers. Users can configure proxies for additional operational security.

Computer Forensics with KeyScout

KeyScout, the portable acquisition utility included with Oxygen Forensic Detective, collects system and user artifacts from Windows, macOS, and Linux computers. Recent updates added file carving capabilities, enabling recovery of JPEG, PDF, TXT, ZIP, and other file types from unallocated NTFS space.

Computer forensic capabilities include:

  • Bit-by-bit disk imaging to RAW or E01 formats

  • Microsoft Office and plain text file searching by signature

  • Hash set searches and NOT IN operator support

  • Virtual machine detection on target devices

  • Artifact collection from Telegram, Dropbox, and iCloud Drive data

Passcode Recovery with KeyDiver

KeyDiver helps recover passcodes for encrypted partitions, files, and applications. The module supports brute force attacks using dictionaries, masks, or user personal data from extractions.

Supported encryption formats:

  • iTunes and Android backups

  • Huawei HiSuite backups

  • VeraCrypt containers and partitions

  • 7-ZIP and RAR archives

  • MS Office files (Word, Excel, PowerPoint)

  • Adobe Acrobat PDF files

  • 1Password account passwords via known hashes

Malware Detection

A built-in malware scanning module identifies over 13 threat types including adware, backdoors, droppers, exploits, phishing tools, ransomware, Trojans, worms, and more. This capability helps investigators identify compromised systems and potential security breaches.

Speech Recognition and Transcription

Investigators can transcribe speech from audio and video files in over 50 languages. The engine supports advanced language models downloadable from the Customer Area. Transcribed content becomes searchable and exportable to reports.

Translation Module

Messages in Applications, Messages, and Timeline sections can be translated into 30+ supported languages including Arabic, Bengali, Dutch, English, French, German, Hindi, Italian, Portuguese, and Spanish. The autodetect option identifies the original language automatically.

Data Visualization and Analysis

Five key visualization tools enhance investigative analysis:

  1. Case-Level Timeline View: Consolidates data from all sources into a single navigable overview with an Activity Matrix for identifying communication patterns

  2. Graph Mode: Visualizes relationships between people, locations, and interactions

  3. Oxygen Maps: Displays geolocation data with distinct icons for device owner coordinates

  4. Facial Categorization Wizard: Speeds identification by extracting faces from video footage and searching for matches across case data

  5. Export Wizard and Report Reader: Creates clear, curated reports with searchable, filterable data for team collaboration

Database and App Analysis

Advanced parsing capabilities handle complex SQLite database structures and application data. For applications not officially supported, users can apply parent application parsing rules to analyze third-party app data. The platform also parses Google Semantic Location artifacts showing detailed user movement patterns with precise timestamps.

Cryptocurrency Investigation

Investigators can search for cryptocurrency addresses and words from mnemonic seed phrases using BIP39 and SLIP39 dictionaries. Specific cryptocurrencies can be selectively targeted during searches.

What’s New in Oxygen Forensic Detective 18.3.0.80

Expanded Android Support

Version 18.3.0.80 introduces enhanced Android extraction capabilities with a focus on broader chipset coverage:

  • Unisoc-based Android devices: Support for SC9863, SC9832E, SC7731E, and T606 chipsets released from 2020 onward

  • Qualcomm-based Android: Extraction of encryption keys and user data decryption for additional user profiles

  • Unisoc feature phones: New extraction method for T117 and T107 chipsets

  • Android OS 15: Full data extraction support for the latest Android version

Enhanced Cloud Extraction

Line iCloud backup extraction now supports contacts, calls, chats, and notifications. Discord extraction allows channel, private chat, or group chat selection for targeted collection.

Advanced Passcode Recovery

KeyDiver now supports CPU-based brute forcing, Adobe Acrobat PDF password recovery, and 1Password account password brute forcing using known hashes.

Computer Forensics Upgrades

KeyScout file carving recovers JPEG, PDF, TXT, ZIP, and other file types from unallocated NTFS space. Virtual machine detection and expanded artifact collection for macOS, Windows, and Linux systems provide deeper computer forensic capabilities.

Expanded Data Import Sources

New import sources include UFED Advanced Logical iOS extractions, Samsung Smart Switch backups (version 37+), unencrypted DMG iPhone backups, AD1 memory card dumps, and encrypted DJI Avata drone flight logs. AT&T and Verizon call data records in XLSX/CSV formats are also supported.

Data Analysis Improvements

Privileged data can be password-protected and automatically hidden in reports, with full visibility after entering the correct password. The Translation module now handles Optical Character Recognition and Speech-to-Text outputs. Multi-language search translates values into specified languages before searching.

Mathematical Filtering and Call Analytics

Recent academic research highlights the platform’s call history analysis capabilities, complementing existing extraction pipelines with enhanced filtering and visualization tools for call pattern analysis.

System Requirements

Recommended Minimum Specifications

Component Requirement
Processor Intel Core i7 or higher
Memory 32 GB DDR4 RAM minimum
Storage 1 TB SSD minimum
USB Ports 2x USB 3.0
Graphics Dedicated graphics card
Operating System Microsoft Windows 64-bit
Download Space ~30 GB for installation and packages

Important Installation Notes

Administrative privileges are required for installation. Antivirus software may block components using Common Vulnerabilities and Exposures (CVEs) for device access. Pausing real-time protection during installation prevents blocking of essential libraries.

Whitelist these paths after installation:

  • C:\Program Files\Oxygen Forensics\Oxygen Forensic Detective (application folder)

  • C:\Users\Username\AppData\Roaming\OxygenEngine (case database and temporary files)

Installation Guide

Step 1: Prepare Your System

  1. Verify system meets minimum requirements

  2. Log in with administrative privileges

  3. Pause antivirus real-time protection during installation

Step 2: Download Software

  1. Access the Oxygen Forensics Customer Area with your SaleID credentials

  2. Download the executable installation file

  3. Download additional packages for your use case:

Package Type Size Purpose
Firehose packs 22 MB Qualcomm EDL device support
Bootloader packs 195 MB Exynos device support
Spreadtrum packs 27 MB Spreadtrum/Unisoc device support
APK downgrade pack 318 MB App version downgrade methods
Device photos 106 MB Visual device identification
Test points 106 MB Hardware access points

Step 3: Install

  1. Run the executable file

  2. Choose installation folder or use default (C:\Program Files\Oxygen Forensics)

  3. Accept the License Agreement

  4. Complete installation process

Step 4: Install Additional Packages

Install downloaded packages in sequence to maximize device compatibility.

Step 5: Whitelist Component Locations

Add the application folder and database location to Windows Security exclusions to prevent antivirus interference during investigations.

Step 6: Resume Security

Re-enable real-time protection after confirming successful installation.

How to Use Oxygen Forensic Detective

Connect a Device

Click “Connect new device” and choose between:

  • Auto device connection: Automatic detection

  • Manual device selection: For connecting multiple devices sequentially

Connection options include USB cable and Bluetooth.

Select Extraction Method

For Android devices, choose from:

  • Android Backup (for devices running Android 4.0+)

  • Android Agent (logical acquisition for multiple third-party apps)

  • Physical Methods (rooted or non-rooted)

  • Chain method (sequential application of multiple methods in one session)

For iOS devices, options include:

  • checkm8 (vulnerability-based extraction)

  • iOS Agent

  • iOS SSH

Cloud Extraction

  1. Navigate to Cloud Extractor

  2. Select target service from 107+ supported options

  3. Authenticate with credentials

  4. Specify extraction scope (e.g., specific Discord channels or date ranges)

Data Analysis

After extraction, leverage the platform’s analysis tools:

  1. Timeline View: Review consolidated data across all sources

  2. Search: Use keyword searches, cryptocurrency address searches, or multi-language searches

  3. Graph Mode: Visualize relationships between entities

  4. Facial Categorization: Identify individuals across case data

Generate Reports

  1. Use Export Wizard to select content for inclusion

  2. Password-protect privileged data if needed

  3. Export to PDF or share via Report Reader for team collaboration

Best Use Cases

Criminal Investigations

Law enforcement agencies use Oxygen Forensic Detective to extract evidence from suspect devices. A notable example involves recovering deleted WhatsApp messages and GPS locations from an Android device, providing crucial evidence linking a suspect to a fraud case.

Fraud Detection

Financial crime investigators analyze communication patterns, location data, and financial applications to identify fraudulent activities. The platform’s ability to import call data records from AT&T and Verizon in XLSX/CSV formats enhances financial crime investigations.

Corporate Security

Corporate investigators handle internal investigations, intellectual property theft cases, and employee misconduct. The platform’s computer forensics capabilities with KeyScout enable acquisition of evidence from company devices while maintaining chain of custody.

Cross-Platform Investigations

Investigators managing multiple devices benefit from the ability to import third-party extractions and review multiple devices simultaneously. This helps link conversations, locations, and activities across different sources.

International and Multi-Language Cases

Translation capabilities across 30+ languages support investigations involving global communication patterns. Speech-to-text functionality transcribes audio and video evidence in over 50 languages, dramatically reducing manual review time.

Advantages and Limitations

Advantages

  1. Comprehensive extraction: Supports multiple device types, cloud services, and computer operating systems in a single platform

  2. Processing speed: Users report processing speeds 5-10 times faster than competitors, reducing time-to-results and investigation costs

  3. User-friendly design: Designed by practitioners for practitioners, with investigator-centric interface and practical functionality

  4. Built-in analysis tools: Facial categorization, speech recognition, translation, and malware detection are included at no additional cost

  5. Regular updates: Features added frequently without extra charges, keeping pace with evolving device security and applications

  6. Security focus: Point-to-point cloud extraction, optional proxy configuration, and air-gapped workstation support

Limitations

  1. Resource requirements: Demands high-end hardware (32 GB RAM, 1 TB SSD, dedicated graphics) for optimal performance

  2. Windows only: Currently limited to Windows 64-bit operating systems

  3. User-based licensing: Distributed via USB dongle and valid for a single user

  4. Training investment: Comprehensive feature set requires training and practice to maximize effectiveness

  5. Cost considerations: Enterprise-tier pricing ($5,000-$20,000+ annually) positions it as a significant investment

Alternatives to Oxygen Forensic Detective

Cellebrite UFED

Cellebrite UFED represents the leading enterprise solution, widely adopted by law enforcement agencies worldwide. The platform offers comprehensive extraction capabilities with Cellebrite UFED Touch 2 licenses starting at $15,000+ annually. A Ukrainian study identified UFED as the primary tool for law enforcement, significantly reducing data collection and analysis time.

Cellebrite offers extensive certification programs and established credibility in court testimony, making it preferred for high-stakes cases.

Magnet AXIOM

Magnet AXIOM provides comprehensive digital forensics for computers, mobile devices, and cloud sources. Annual subscriptions range $5,000-$10,000+. The platform excels at digital artifact recovery and offers robust reporting capabilities.

X-Ways Forensics

A professional computer forensics solution focusing on Windows-based investigations. It offers deep file system analysis and data recovery capabilities at a lower price point than enterprise alternatives.

Mid-Market Alternatives

For organizations handling fewer cases or operating on constrained budgets, Sherlock Forensics offers a toolkit covering email, Windows event logs, Android logical acquisition, and browser forensics for under $1,000 lifetime. While these tools lack the comprehensive extraction capabilities of Oxygen Forensic Detective, they provide forensic-grade output for specific evidence types.

Comparison Overview

Tool Annual Cost Mobile Extraction Cloud Extraction Computer Forensics Key Strength
Oxygen Forensic Detective $5,000-$20,000+ ✓✓✓ ✓✓✓ (107+ services) ✓✓✓ All-in-one platform
Cellebrite UFED $15,000+ ✓✓✓ ✓✓ Market leader, court-tested
Magnet AXIOM $5,000-$10,000+ ✓✓ ✓✓ ✓✓✓ Computer artifact recovery
Sherlock Forensics ~$1,000 lifetime Limited Budget-friendly alternative

Frequently Asked Questions

What is Oxygen Forensic Detective used for?

Oxygen Forensic Detective is a digital forensics platform used by law enforcement, corporate security teams, and investigators to extract, decode, and analyze evidence from mobile devices, cloud services, computers, and IoT sources. The software recovers deleted messages, bypasses encryption, and processes large datasets to support criminal investigations, fraud detection, and internal security matters.

What devices are supported by Oxygen Forensic Detective?

The platform supports a wide range of devices including Android and iOS smartphones, Unisoc-based feature phones, Windows and macOS computers, Linux systems, drones, and IoT devices. Supported extraction methods vary by device type and operating system version.

Is Oxygen Forensic Detective safe to install?

Yes, Oxygen Forensic Detective is safe and legitimate forensic software. During installation, antivirus software may temporarily block components because they use Common Vulnerabilities and Exposures (CVEs) to access mobile device data. Pausing antivirus during installation and whitelisting application folders prevents interference. The software contains no malicious components and does not collect data from the host workstation.

How much does Oxygen Forensic Detective cost?

Oxygen Forensic Detective falls into the enterprise pricing tier, with annual licenses typically ranging from $5,000 to $20,000+ depending on the organization’s scale and specific requirements. The software is distributed via USB dongle and valid for a single user. Features are updated regularly at no additional cost.

What cloud services can Oxygen Forensic Detective extract data from?

Oxygen Forensic Detective extracts data from 107+ cloud services including Google (Drive, Gmail, Photos), Discord, Steam, TikTok, X (Twitter), Snapchat, WhatsApp backups, Telegram, Signal, Viber, and Line iCloud backups. Extraction scope can be narrowed to specific channels, chats, or date ranges.

What are the system requirements for Oxygen Forensic Detective?

Recommended minimum requirements include an Intel Core i7 processor, 32 GB DDR4 RAM, 1 TB SSD storage, 2 USB 3.0 ports, a dedicated graphics card, and Windows 64-bit operating system. Installation consumes approximately 30 GB of storage for software and supporting packages.

Does Oxygen Forensic Detective support macOS or Linux?

While the software runs only on Windows 64-bit operating systems, it extracts evidence from macOS and Linux computers through KeyScout. The platform supports artifact collection from macOS, Windows, and Linux target devices, including system and user artifacts. The forensic workstation itself must run Windows.

How does Oxygen Forensic Detective recover deleted messages?

The platform uses advanced SQLite database parsing to recover deleted messages from messaging apps like WhatsApp, Telegram, and Signal. The software reconstructs fragmented database tables and recovers embedded numbers even when manual inspection might miss them. The Chain method can apply multiple extraction approaches in a single session to maximize data recovery.

Can Oxygen Forensic Detective extract data from encrypted devices?

Yes, the platform supports data extraction from encrypted devices using multiple methods. KeyDiver recovers passcodes for encrypted partitions, files, and applications. For Android devices, the software extracts encryption keys from Qualcomm-based devices to decrypt user data. Cloud extraction operates point-to-point without data passing through third-party servers.

How does Oxygen Forensic Detective compare to Cellebrite?

Both represent leading digital forensics solutions with comprehensive extraction capabilities. Oxygen Forensic Detective users report processing speeds 5-10 times faster than competitors. The platform supports 107+ cloud services, while Cellebrite maintains broader law enforcement adoption and deeper certification programs. Pricing for both solutions falls within the $5,000-$20,000+ annual range. The choice often depends on specific agency requirements, existing workflows, and user preference.

Final Thoughts

Oxygen Forensic Detective 18.3.0.80 represents a mature, comprehensive digital forensics platform that continues to evolve with the challenges of modern investigations. The software’s all-in-one approach—covering mobile devices, cloud services, computers, and IoT sources—eliminates the need for multiple specialized tools and streamlines investigative workflows.

The platform’s strength lies in practical, investigator-focused design backed by experience from career digital forensics practitioners. Users consistently praise its reliability, speed, and ease of use. Updates arrive frequently at no additional cost, ensuring the platform stays ahead of encrypted data, evolving app security, and new device releases.

For organizations requiring enterprise-grade digital forensics capabilities, Oxygen Forensic Detective delivers value through faster processing, comprehensive extraction options, and built-in analysis tools. The investment delivers returns through reduced investigation time, lower billable hours, and more efficient case resolution.

Smaller teams or organizations with limited case volumes may find mid-market alternatives sufficient for basic evidence recovery. However, for comprehensive digital investigations requiring mobile, cloud, and computer forensics with advanced analysis capabilities, Oxygen Forensic Detective remains a compelling choice in the competitive digital forensics market.

Our Paid Service

“We do not sell or provide any software. We only offer professional support services. If any software on your system is not working properly, or you are facing installation errors, crashes, or any other technical issue — just contact us. We will help you fix the problem quickly and remotely via AnyDesk. No software will be provided from our side — only expert troubleshooting and support.”

 

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *