News

Oxygen Remote Explorer: The main updates for 2024

Remote Data Collection Updates

The ability to reduce costs and streamline investigations through remote collection are key benefits provided byOxygen Remote Explorer.

Remote Data Collection from Windows-Based Endpoints
In 2024, Oxygen Forensics improved remote data collection from Windows-based endpoints.

First, Oxygen Forensics added the ability to remotely capture a Windows operating system crash dump. Users can now right-click on the endpoint of interest and select the option to create a crash dump. The created dump is sent to the server. Later, users can download the dump from the server and use a third-party tool for analysis.

Secondly, Oxygen Forensics introduced the ability to remotely capture a bit-by-bit image of the Windows operating system disk or partition in E01 format. Researchers can now create dumps of both unencrypted and Bitlocker-protected disks and partitions. The created dump can be saved to local storage or sent to the server.

Finally, Oxygen Forensics implemented recovery of deleted files from remote endpoints for NTFS, FAT, and exFAT file systems.

Remote Data Collection from Android and Apple iOS Devices

In 2024, Oxygen Forensics added new features that makeOxygen Remote Exploreran even more powerful tool for remote data collection from Android and Apple iOS devices.

Oxygen Forensics dramatically improved the iOS remote extraction algorithm to enable selective data extraction. Researchers can now choose to extract only specific artifacts to meet their search requirements. This change also helps alleviate server load and speeds up the collection and transfer of extracted data for analysis.

Oxygen Forensics also added the ability to collect WhatsApp and WhatsApp Business data remotely from anywhere in the world with a cellular or Wi-Fi connection. This new feature allows researchers to collect a variety of data from WhatsApp, including user information, chats, contacts and calls. Before extraction, users can adjust the extraction options to select the data that should be obtained. WhatsApp data extraction options are highly customizable, allowing for fast and targeted data collection.

Agent Management Center Feature Enhancements

In 2024, Oxygen Forensics added several functional improvements to theAgent Management Center, including:

  • ANotification Centerwhere users can now see all important system notifications.
  • A utility for configuring server parameters, where researchers can choose parameters for server connections, logs, pull repositories, and backup or reset server settings to their default values.
  • The ability to configure Agent work logging. Users can now set the logging level and delete or compress intervals in the endpoint configuration.
  • Researchers now have the option to export all or selected user logs to CSV, TSV, XLSX and HTML formats. Logs can be used for internal reporting or problem resolution.
  • Users can automatically restart data extraction tasks that ended with errors. They just have to set the number of attempts and the Agent will automatically restart data extraction if the task fails.

Remote File Explorer

Users now have the ability to remotely access the endpoint file system, allowing them to select specific artifacts for extraction and import them intoOxygen Remote Explorerfor analysis and reporting.

Finally, Oxygen Forensics added the ability to work with the endpoint file system. Now researchers can explore the file system to select the artifacts they need to extract, set paths for temporary files, or choose local storage for disk images.

Selective Remote Extraction of WhatsApp and WhatsApp Business

Added new extraction options for remote collection of WhatsApp and WhatsApp Business data from Android devices, including selecting chat names and dates.

Improvements in Task Management

Oxygen Forensics added the ability to automatically restart data extraction jobs that ended with errors. Users can also set the number of task retry attempts and choose to prioritize them over other extraction tasks.

MSI Format for Windows Agent

Users can now download the Agent for Windows in MSI format, along with the existing EXE format, providing greater flexibility for deployment.

Computer Gadget Upgrades

Support was added for more computer artifacts, and users can now search by hash sets.

New Artifacts

The new computer artifacts supported for extraction are listed below:

  • Windows NTLM Hashes
  • Bitwarden passwords for Windows, macOS and GNU/Linux
  • NordPass data from Windows, macOS and GNU/Linux
  • Brave Nightly data for Windows, macOS and GNU/Linux
  • FrostWire data from Windows, macOS and GNU/Linux
  • Windows SSH Keys
  • Windows 7-Zip Data
  • GNU/Linux Flatpak Data

Search by Hash Sets

Oxygen Forensics added the ability to use hash sets when creating file search rules.

Cloud Forensics Updates

Our industry-best cloud extraction capabilities now include updated cloud service authorization.

Cloud Extraction Updates

Oxygen Forensics updated the ability to authorize in the following cloud services:

  • box
  • Google
  • Samsung Cloud Data
  • Samsung Cloud Backup
  • Samsung Secure Folder Backup
  • Telegram
  • Zoom

KeyDiver Updates

Several updates have been added toKeyDiver, our decryption tool for computer partitions, files and applications.

New Brute Force Support

Now KeyDiver can find passcodes to decrypt:

  • Containers and partitions protected with VeraCrypt
  • Huawei HiSuite Backups
    Oxygen Forensics also added support for NTLM hashes, allowing users to find passwords for a user account in Windows and decrypt data from the operating system and third-party applications associated with this password.

Template Manager

Oxygen Forensics added the ability to create custom attack templates. Users can create templates using two methods:

  1. Save attack parameters as a template while setting up a new attack.
  2. Use the “Create New Template” button in the Template Manager.

Configuration Window

Added a windowConfigurationto allow users to enable or disable drivers (CUDA, HIP, OpenCL, Temperature Monitoring), manage the attack queue, set a temperature threshold and tune the desired performance. The selected settings will be saved and automatically applied to all current and subsequent attacks.

Mobile Forensic Updates

Automatic Detection of Connected Devices

Automatic detection of connected devices is now supported onOxygen Remote Explorer. When startingDevice Extractor, the available information about the connected device will be displayed along with the available methods for data extraction.

Autodiscovery is supported on Android devices if ADB debugging is enabled and confirmed, and on iOS devices with the trusted option confirmed.

Agent Method Improvements

Several improvements were added to this method:

  • Support for audio recording during video capture of the device screen, so both the video and audio of the on-screen activity are recorded.
  • A new extraction mode inDevice Extractorthat guides users through the process of manual data extraction using theAndroid Agent.
  • Added the ability to extract data from Slack using theAndroid Agent.
  • Added the ability to extract scheduled Telegram messages using theAndroid Agent.

Import Updates

Oxygen Forensics also added support for importing and analyzing data from social media platform accounts, including:

Importing TikTok Account Data

Oxygen Remote Explorernow supports importing and analyzing TikTok account data. The extracted categories include the following information:

  • Account owner authorization history
  • Última ubicación conocida
  • Main account details
  • Followers and subscriptions
  • direct messages
  • Blocked users
  • Application Settings
  • Publications
  • Search history

General Updates

Oxygen Forensics addressed one of its most requested features with the addition of an integrated module that allows selective scanning of extracted files for malware and potential threats. You can now unlock advanced malware detection, including searches usingYARA Rules.

Selective Malware Scanning

Now you can also configure malware scan settings and start a malware scan. Both the entire structure of extracted files and only selected files can be scanned. More than 10 identifiable threats are supported. The results will appear in the toolbar, showing the status of the scanned files, identified threats, scan start time, and other relevant details.