Oxygen Forensic® KeyScout is a built-in module of Oxygen Forensic® Detective that extracts data from macOS, including pre-installed Apple apps, user-installed apps, system files, and user credentials. Let’s take a look at macOS system artifacts that are supported by Oxygen Forensic® KeyScout. System Artifacts Extracted with Oxygen Forensic® KeyScout…
Support for Virtual Machines in Oxygen Forensic® Detective
We have added support in Oxygen Forensic® Detective for the import and analysis of images of virtual machines of VMX and VBOX formats. What is a Virtual Machine? A virtual machine is similar to a physical computer like a laptop, smart phone, or server. It stores files on a CPU, memory,…
Analysis of Volume Shadow Copies in Oxygen Forensic® Detective
What is Volume Shadow Copy? Volume Shadow Copy is a technology included in Microsoft Windows that can create backup copies or snapshots of computer files or volumes, even when they are in use. It requires the file system to be NTFS in order to create and store these backup copies.…
7 Web Browsers Supported in Oxygen Forensic® Detective
Web browsers are used for accessing the World Wide Web or local websites. When a user requests a web page from a website, the web browser will then retrieve the content from a web server and display the page on the user’s device. Users can choose from a variety of…
Oxygen Forensic® Detective v.14.4
We present the latest update of our flagship software, Oxygen Forensic® Detective, v.14.4! This version introduces support for: Huawei 820 chipset Decryption of ProtonMail RunKeeper cloud extraction Wickr Pro acquisition from Android devices Import of macOS Time Machine backups For a full list of updates, refer to the “What’s New”…