
Now, the updated Huawei Kirin method brute forces the device while simultaneously extracting the hardware keys. Previously, the password brute force was performed on a dump. Thus, we had to optimize our Huawei Kirin method so that it could support updated Huawei devices. Huawei Kirin Methodįor certain Huawei devices based on Kirin chipsets (980, 990, and 990 5G), the encryption algorithm changed after the SPL (Security Patch Level) update in May. Therefore, this blog article will be dedicated to highlighting the minor and major updates of Oxygen Forensic® Device Extractor included in Oxygen Forensic® Detective v.14.1 and 14.2.

While significant and impactful, many of the improvements presented were minor and may have gone unnoticed. Last year we released the new Oxygen Forensic® Device Extractor, which was designed to gradually replace our previous Oxygen Forensic® Extractor. Not only did we introduce new mechanisms, we also improved the GUI for existing methods by speeding up extraction and optimizing the code. In addition to screen lock methods, we provide several mechanisms to allow investigators to access data from unlocked Android devices: Other Qualcomm, MTK and Spreadtrum devices.Currently, our software supports advanced methods for the following groups of locked Android devices: Added opportunity to export current Google Map, coordinates and routes to external files.Our device acquisition methods have progressed a lot over the past two years, especially within screen lock bypass techniques. Added opportunity to set filters for several time periods and display social communications for specified time frames only.

Added contacts filter which enables experts to analyze social communications from selected contacts only. Added filter for several types of communication that allows to view social links from particular communication types only: calls, SMS, application chats, etc. As a result this method gives an access to applications cache and log files as well as additional user data. It bypasses iTunes backup protection by utilizing advanced logical protocols and acquires more application data than standard iTunes backup procedure. This approach is recommended for non-jailbroken iOS devices with a password protected iTunes backup.

Added Advanced Logical data extraction from iOS devices.

- file hosted by A mobile forensic software that goes beyond standard logical analysis of cell phones, smartphones and PDAs.
