News
Oxygen Remote Explorer: The main updates for 2024
Remote Data Collection Updates
The ability to reduce costs and streamline investigations through remote collection are key benefits provided byOxygen Remote Explorer.
Remote Data Collection from Windows-Based Endpoints
In 2024, Oxygen Forensics improved remote data collection from Windows-based endpoints.
First, Oxygen Forensics added the ability to remotely capture a Windows operating system crash dump. Users can now right-click on the endpoint of interest and select the option to create a crash dump. The created dump is sent to the server. Later, users can download the dump from the server and use a third-party tool for analysis.
Secondly, Oxygen Forensics introduced the ability to remotely capture a bit-by-bit image of the Windows operating system disk or partition in E01 format. Researchers can now create dumps of both unencrypted and Bitlocker-protected disks and partitions. The created dump can be saved to local storage or sent to the server.
Finally, Oxygen Forensics implemented recovery of deleted files from remote endpoints for NTFS, FAT, and exFAT file systems.
Remote Data Collection from Android and Apple iOS Devices
In 2024, Oxygen Forensics added new features that makeOxygen Remote Exploreran even more powerful tool for remote data collection from Android and Apple iOS devices.
Oxygen Forensics dramatically improved the iOS remote extraction algorithm to enable selective data extraction. Researchers can now choose to extract only specific artifacts to meet their search requirements. This change also helps alleviate server load and speeds up the collection and transfer of extracted data for analysis.
Oxygen Forensics also added the ability to collect WhatsApp and WhatsApp Business data remotely from anywhere in the world with a cellular or Wi-Fi connection. This new feature allows researchers to collect a variety of data from WhatsApp, including user information, chats, contacts and calls. Before extraction, users can adjust the extraction options to select the data that should be obtained. WhatsApp data extraction options are highly customizable, allowing for fast and targeted data collection.
Agent Management Center Feature Enhancements
In 2024, Oxygen Forensics added several functional improvements to theAgent Management Center, including:
- ANotification Centerwhere users can now see all important system notifications.
- A utility for configuring server parameters, where researchers can choose parameters for server connections, logs, pull repositories, and backup or reset server settings to their default values.
- The ability to configure Agent work logging. Users can now set the logging level and delete or compress intervals in the endpoint configuration.
- Researchers now have the option to export all or selected user logs to CSV, TSV, XLSX and HTML formats. Logs can be used for internal reporting or problem resolution.
- Users can automatically restart data extraction tasks that ended with errors. They just have to set the number of attempts and the Agent will automatically restart data extraction if the task fails.
Remote File Explorer
Users now have the ability to remotely access the endpoint file system, allowing them to select specific artifacts for extraction and import them intoOxygen Remote Explorerfor analysis and reporting.
Finally, Oxygen Forensics added the ability to work with the endpoint file system. Now researchers can explore the file system to select the artifacts they need to extract, set paths for temporary files, or choose local storage for disk images.
Selective Remote Extraction of WhatsApp and WhatsApp Business
Added new extraction options for remote collection of WhatsApp and WhatsApp Business data from Android devices, including selecting chat names and dates.
Improvements in Task Management
Oxygen Forensics added the ability to automatically restart data extraction jobs that ended with errors. Users can also set the number of task retry attempts and choose to prioritize them over other extraction tasks.
MSI Format for Windows Agent
Users can now download the Agent for Windows in MSI format, along with the existing EXE format, providing greater flexibility for deployment.
Computer Gadget Upgrades
Support was added for more computer artifacts, and users can now search by hash sets.
New Artifacts
The new computer artifacts supported for extraction are listed below:
- Windows NTLM Hashes
- Bitwarden passwords for Windows, macOS and GNU/Linux
- NordPass data from Windows, macOS and GNU/Linux
- Brave Nightly data for Windows, macOS and GNU/Linux
- FrostWire data from Windows, macOS and GNU/Linux
- Windows SSH Keys
- Windows 7-Zip Data
- GNU/Linux Flatpak Data
Search by Hash Sets
Oxygen Forensics added the ability to use hash sets when creating file search rules.
Cloud Forensics Updates
Our industry-best cloud extraction capabilities now include updated cloud service authorization.
Cloud Extraction Updates
Oxygen Forensics updated the ability to authorize in the following cloud services:
- box
- Samsung Cloud Data
- Samsung Cloud Backup
- Samsung Secure Folder Backup
- Telegram
- Zoom
KeyDiver Updates
Several updates have been added toKeyDiver, our decryption tool for computer partitions, files and applications.
New Brute Force Support
Now KeyDiver can find passcodes to decrypt:
- Containers and partitions protected with VeraCrypt
- Huawei HiSuite Backups
Oxygen Forensics also added support for NTLM hashes, allowing users to find passwords for a user account in Windows and decrypt data from the operating system and third-party applications associated with this password.
Template Manager
Oxygen Forensics added the ability to create custom attack templates. Users can create templates using two methods:
- Save attack parameters as a template while setting up a new attack.
- Use the “Create New Template” button in the Template Manager.
Configuration Window
Added a windowConfigurationto allow users to enable or disable drivers (CUDA, HIP, OpenCL, Temperature Monitoring), manage the attack queue, set a temperature threshold and tune the desired performance. The selected settings will be saved and automatically applied to all current and subsequent attacks.
Mobile Forensic Updates
Automatic Detection of Connected Devices
Automatic detection of connected devices is now supported onOxygen Remote Explorer. When startingDevice Extractor, the available information about the connected device will be displayed along with the available methods for data extraction.
Autodiscovery is supported on Android devices if ADB debugging is enabled and confirmed, and on iOS devices with the trusted option confirmed.
Agent Method Improvements
Several improvements were added to this method:
- Support for audio recording during video capture of the device screen, so both the video and audio of the on-screen activity are recorded.
- A new extraction mode inDevice Extractorthat guides users through the process of manual data extraction using theAndroid Agent.
- Added the ability to extract data from Slack using theAndroid Agent.
- Added the ability to extract scheduled Telegram messages using theAndroid Agent.
Import Updates
Oxygen Forensics also added support for importing and analyzing data from social media platform accounts, including:
Importing TikTok Account Data
Oxygen Remote Explorernow supports importing and analyzing TikTok account data. The extracted categories include the following information:
- Account owner authorization history
- Última ubicación conocida
- Main account details
- Followers and subscriptions
- direct messages
- Blocked users
- Application Settings
- Publications
- Search history
General Updates
Oxygen Forensics addressed one of its most requested features with the addition of an integrated module that allows selective scanning of extracted files for malware and potential threats. You can now unlock advanced malware detection, including searches usingYARA Rules.
Selective Malware Scanning
Now you can also configure malware scan settings and start a malware scan. Both the entire structure of extracted files and only selected files can be scanned. More than 10 identifiable threats are supported. The results will appear in the toolbar, showing the status of the scanned files, identified threats, scan start time, and other relevant details.