首页 > 其他分享 >Oxygen Forensic Detective 17.1 新增功能简介

Oxygen Forensic Detective 17.1 新增功能简介

时间:2024-12-27 14:27:29浏览次数:7  
标签:Detective Added ability Oxygen extract Forensic data

Oxygen Forensic Detective 17.1 - 领先的一体化数字取证软件

digital forensic software

请访问原文链接:https://sysin.org/blog/oxygen-forensic-detective/ 查看最新版。原创作品,转载请保留出处。

作者主页:sysin.org


Oxygen Forensic® Detective

Sherlock icon for Oxygen Forensic Detective software

An all-in-one digital forensic software designed to extract, decode, and analyze data. Extract data and artifacts from multiple devices with the capability for both mobile and computer forensic investigations.

一款一体化数字取证软件,旨在提取、解码和分析数据。从多个设备中提取数据和工件,并具有移动和计算机取证调查的能力。

一体化数字取证解决方案

Oxygen Forensic® Detective 的特性、工具和功能比市场上任何数字取证产品都要多。通过 100 多种受支持的服务从云中获取更多信息,并从 40,000 多个应用程序版本中提取数据。

Oxygen Forensic Detective

  • 比市场上任何其他数字取证工具提取更多的云服务 (sysin)。访问 WhatsApp、Telegram、iCloud、Google、Samsung、Microsoft、Facebook、Instagram 和 Twitter 等流行的云服务。

Oxygen Forensic Detective

  • 移动设备

    从超过 31,000 个设备中提取数据。Oxygen Forensic® Detective 支持多种 Apple iOS 和 Android 设备。

Oxygen Forensic Detective

  • 无人机

    从物理转储、无人机日志和移动应用程序中提取和分析无人机数据。

Oxygen Forensic Detective

  • 物联网设备

    从最流行的物联网设备中提取和分析数据:Amazon、Alexa 和 Google Home。

Oxygen Forensic Detective

  • 电脑

    从 Windows、Linux 和 macOS 提取并分析数据 (sysin)。Oxygen Forensic® KeyScout 无需额外付费,可查找网络浏览器和桌面应用程序的密码和令牌。

Oxygen Forensic Detective

  • 可穿戴设备

    摘自最流行的健康应用程序:Apple Health、Samsung Health、Huawei Health、Fitbit 等。

新增功能

Oxygen Forensic® Detective

Changes in version 17.1 (December 2024):

  • Oxygen Forensic Device Extractor. Added automatic detection of connected devices.
  • Oxygen Forensic Device Extractor. Added the ability to manually extract data via Android Agent.
  • Oxygen Forensic Device Extractor. Added the ability to extract Slack data via Android Agent.
  • Oxygen Forensic Device Extractor. Added the ability to extract Telegram scheduled messages via Android Agent.
  • Oxygen Forensic Device Extractor. Added the ability to record sound while making a screen recording of device data.
  • Oxygen Forensic Device Extractor. Extended the list of supported devices.
  • Oxygen Forensic Device Extractor. Updated the ability to extract Firefox data via Android Agent.
  • Oxygen Forensic Device Extractor. Updated the ability to extract Google Chrome data via Android Agent.
  • Oxygen Forensic Device Extractor. Updated the ability to extract Zoom contacts via Android Agent.
  • Oxygen Forensic Device Extractor. Updated the ability to extract Samsung Internet Browser data via Android Agent.
  • Oxygen Forensic Cloud Extractor. Now iCloud Agent is built into iOS Agent in special mode.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Samsung Cloud Data.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Samsung Cloud Backup.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Samsung Secure Folder Backup.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Telegram and extract Telegram data.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Zoom.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Box.
  • Oxygen Forensic Cloud Extractor. Updated the ability to authorize in Google services.
  • Oxygen Forensic KeyDiver. Added the ability to create custom attack templates.
  • Oxygen Forensic KeyDiver. When an encrypted Huawei HiSuite backup is imported into Oxygen Forensic® Detective, Oxygen Forensic KeyDiver is automatically opened for a passcode brute force.
  • Oxygen Forensic KeyDiver. Added the attack settings window.
  • Oxygen Forensic KeyDiver. Added the ability to brute force Windows OS system account passwords using NTLM hashes.
  • Oxygen Forensic KeyDiver. Added the option to pause all attacks using the same hash and hash type if the active attack has brute forced the password.
  • Oxygen Forensic KeyDiver. Added the ability to brute force passwords to decrypt containers and partitions protected with VeraCrypt.
  • Oxygen Forensic KeyDiver. Now attacks are automatically grouped when they use the same hash and hash type or when a group of hashes for password brute forcing is imported from Oxygen Forensic® Detective or Oxygen Forensic KeyScout.
  • Oxygen Forensic KeyScout. Added the ability to extract NTLM hashes from Windows.
  • Oxygen Forensic KeyScout. Added the ability to search by hash sets.
  • Oxygen Forensic KeyScout. Added the ability to extract passwords from Bitwarden from Windows, macOS and GNU/Linux.
  • Oxygen Forensic KeyScout. Added the ability to extract NordPass data from Windows, macOS and GNU/Linux.
  • Oxygen Forensic KeyScout. Added the ability to extract Brave Nightly data from Windows, macOS and GNU/Linux.
  • Oxygen Forensic KeyScout. Added the ability to extract FrostWire data from Windows, macOS and GNU/Linux.
  • Oxygen Forensic KeyScout. Added the ability to extract SSH keys from Windows.
  • Oxygen Forensic KeyScout. Added the ability to extract 7-Zip data from Windows.
  • Oxygen Forensic KeyScout. Added the ability to extract Flatpak data from GNU/Linux.
  • Oxygen Forensic KeyScout. Added support for the new Search Index data storage format for Windows 11.
  • Oxygen Forensic KeyScout. Updated the ability to extract Microsoft Outlook data from macOS.
  • Oxygen Forensic KeyScout. Updated the ability to extract Discord data from Windows, macOS and GNU/Linux.
  • Oxygen Forensic KeyScout. Updated the ability to extract Mozilla Thunderbird data from Windows, macOS and GNU/Linux.
  • Malware. Added the ability to selectively scan files for malware.
  • Malware. Updated SDK Avira used for scanning files for malware.
  • Speech Recognition. Added an improved Large (turbo) speech recognition model and improved support for GPU.
  • General. Added the ability to save hash set binary files in the Hash Set Manager.
  • Import. Added the ability to import physical dumps of MTK-based devices with a simplified encryption algorithm (no TEE).
  • Import. Added the ability to decrypt physical dumps of Samsung Galaxy A32 A325F and Samsung Galaxy A32 SM-A325F devices.
  • Import. Added the ability to import and decrypt physical dumps of Oukitel WP10.
  • Import. Added the ability to import and parse Android virtual device images in VHD and VHDX formats.
  • Import. Added the ability to import and parse ArduPilot drone logs.
  • Import. Added the ability to import and parse drone flight missions in AWM format.
  • Import. Added the ability to import TikTok account data.
  • Import. Added parsing of Google Voice data from Google Takeout.
  • Import. Added free disk space check before import of .ofbx and .ofbr backups.
  • Import. Updated support for MTK-based Android devices having TEE Kinibi.
  • Maps. Added the ability to include map previews in the report.
  • Export. Added the ability to exclude files marked with a specific tag from the report.
  • Export. Added the ability to export video frames marked as Key evidence from the Files section.
  • Applications. Added data parsing from over 890 new app versions. The total number of supported versions exceeds 49100.
  • Applications. OS artifacts. Added parsing of Clipboard from Android devices.
  • Applications. Web Browsers. Added data parsing from Brave Browser (Nightly) (1.73.60) from Android devices.
  • Applications. Finance. Added data parsing from AirCash (5.31.0) from Apple iOS devices and from AirCash (5.31.0) from Android devices.
  • Applications. Cryptocurrency. Added data parsing from Exodus (24.39.7) from Apple iOS devices and from Exodus (24.41.7) from Android devices.
  • Applications. Web Browsers. Updated data parsing from web browsers based on the Blink engine from Apple iOS devices and from Android devices.
  • Applications. Messengers. Updated data parsing from Viber (23.6.1) from Apple iOS devices and from Viber (23.9.1.0) from Android devices.
  • Applications. Messengers. Updated data parsing from Threema (6.3.1) from Apple iOS devices.
  • Applications. Social Networks. Updated data parsing from Instagram (356.0.0.41.101) from Android devices.

下载地址

准备开始学习和研究?请访问:https://sysin.org/blog/oxygen-forensic-detective/

更多:HTTP 协议与安全

标签:Detective,Added,ability,Oxygen,extract,Forensic,data
From: https://blog.csdn.net/sysinside/article/details/144428275

相关文章

  • Oxygen Forensic Detective 17.1 - 领先的一体化数字取证软件
    OxygenForensicDetective17.1WindowsMultilingual-领先的一体化数字取证软件digitalforensicsoftware请访问原文链接:https://sysin.org/blog/oxygen-forensic-detective/查看最新版。原创作品,转载请保留出处。作者主页:sysin.orgOxygenForensic®Detective......
  • Doxygen 学习指南: 生成图的类型
    目录标题1.**类图(ClassDiagram)****生成原理**:**生成结果**:2.**调用图(CallGraph)****生成原理**:**生成结果**:1.**继承图(InheritanceDiagram)**2.**协作图(CollaborationDiagram)**3.**包含图(IncludeDependencyGraph)**4.**依赖图(DependencyGraph)**5......
  • Autopsy Forensic Browser 是一个开源的数字取证工具,主要用于分析电脑文件系统和存储
    AutopsyForensicBrowser是一个开源的数字取证工具,主要用于分析电脑文件系统和存储设备,帮助调查人员识别和恢复可能的证据。它设计用于在调查和法医实验室中使用,支持各种操作系统,包括Windows、Linux和macOS。该工具的主要特点和功能包括:文件系统分析:可以深入分析和检查存储......
  • DownUnderCTF 2024 - Forensics
    DownUnderCTF2024-ForensicsBaby'sFirstForensics他们整个上午都在试图破坏我们的基础设施!他们正试图获得更多关于我们秘密袋鼠的信息!我们需要您的帮助,我们已经捕获了一些他们攻击我们的流量,您能告诉我们他们使用的是什么工具及其版本吗?注意:将您的答案包装在DUCTF{}中,......
  • 使用Doxygen为C++项目生成文档
    使用Doxygen为C++项目生成文档目录使用Doxygen为C++项目生成文档1.Doxygen简介2.Doxygen安装3.Doxygen注释标记4.Doxyfile配置选项5.Doxygen生成文档示例1.Doxygen简介Doxygen是一个用于自动生成文档的开源工具,主要用于生成软件源代码的文档。它可以处理多种编程语言,包括......
  • 利用Doxygen生成代码文档
    说明在vscode上使用doxygendocumentgenerate写好代码后,想要生成文档的话可以使用doxygen来进行生成下载Doxygendownload打开安装好后打开Doxywizard配置......
  • 学习网络取证 (Network Forensics) - WiFi分析笔记
    MAC地址:MAC地址是无线接入点(WAP)的媒体访问控制地址,用于唯一标识网络中的设备。它是一个由12个十六制数字组成的地址,通常表示为6对冒号分隔的双字节(例如:00:1A:2B:3C:4D:5E)。关于MAC地址的两个例子:网络入侵检测:在网路入侵检测中,可以通过监视和记录网络流量中的MAC地址来检测潜......
  • 2024獬豸杯-forensics
    备战数字中国,争取和队里一起冲进线下。web取证双修!(仙武双修)继续取证!APK分析JADX打开apk包。APK分析-1点开即得:APK分析-2直接资源文件=>AndroidManifest.xml=>android:name:StartShowAPK分析-3APKSignature=> SHA1withRSAAPK分析-4还是这页:1.0A......
  • VCTF-Forensics
    这个取证有点意思,也没有套太多。下载附件,直接FTK打开,我们发现两个分区,其中一个又hint.zip和一个图片,发现里面图片一致,一眼丁真明文攻击:打开见key:直接PasswordkitForensics开梭:然后FTK继续开,找到flag.txt,里面是个字符串,一眼十六进制转出摩斯密码:解密,是个奶牛快传:......
  • doxygen/addon/doxywizard/wizard.cpp
    Step2::Step2(Wizard*wizard,constQHash<QString,Input*>&modelData) :m_wizard(wizard),m_modelData(modelData){ QRadioButton*r; QVBoxLayout*layout=newQVBoxLayout(this); //--------------------------------------------------- m_extractMo......