Sherlock icon for Oxygen Forensic Detective software

Oxygen Forensic® Detective.

An all-in-one digital forensic software designed to extract, decode, and analyze data. Extract data and artifacts from multiple devices with the capability for both mobile and computer forensic investigations.

Get a Free Trial

How does it work?

Understand a criminal's every move with Oxygen Forensic® Detective. Extract from multiple devices, tag key evidence, collect data for analysis, and easily build reports. With the ability to extract from over 30,000 devices and over 100 cloud-supported applications, you can simplify your workflow, close cases faster, and help make the world safer.

Oxygen Forensic® Detective comes with multiple tools such as the Cloud Extractor, Device Extractor, KeyScout, OxyAgent, and more.

The Benefits.

Oxygen Forensic® Detective is trusted by law enforcement, enterprises, and government agencies globally. Here’s why.

Extract Data from Locked Devices

Extract data from locked Android devices and perform both logical and physical extractions to uncover all types of evidence, including hidden and deleted data.

Easily Search Through Data

Global search over a single device, multiple devices, an entire case, or multiple extractions in a single interface.

Streamline Analysis with Included Tools

Streamline data analysis with all entries relevant to a case in one place. Facial and image categorization, social graphing, and merge extraction features.

Increase efficiency

Simultaneous upload of data from multiple devices and device types to a single platform. Speed up extraction with customizable artifact selection.

Expand your knowledge.

With the purchase or renewal of your software maintenance and support for Oxygen Forensic® Detective, you will receive an All-Access Pass allowing you to choose from a wide range of standard training courses to expand your skill set and become certified.

Learn more

Key Product Features.

The features and tools offered in Oxygen Forensic® Detective are what make it the best digital forensic software on the market. Each feature is designed and built to help fill the evidential gaps and close your cases quicker, avoiding case backlog.


Accounts and passwords

Decrypt passwords and authentication tokens to user accounts in social networks, messengers, and email apps. Reveal passwords that were used to connect to wi-fi networks.


Advanced physical methods

Physical collection while bypassing device security.


Application support

Extract, decrypt, and examine user data from today's most popular apps.


Backup and image import

Import and parse various backups and images made from today's devices like iOS, Android, and more as well as import from other forensic tools like Cellebrite and MSAB.


Call data

View dialed, answered, and failed calls - including deleted ones. Apply filters to show calls only for a specific period of time.


CDR analysis

Process and analyze call data records obtained from wireless providers. Visualize geo coordinates on the map and identify links between callers.


Cloud data

Gain access to over 100 cloud services like WhatsApp, Telegram, iCloud, Google, Samsung, Microsoft, Facebook, Instagram, and Twitter.


Uncover contacts

Uncover and reveal names, usernames, emails, and more from different sources on the device.


Export in different formats

Customize and generate data reports in many formats like pdf, xls, rtf, xml and html.


Data search

Powerful global search over a single device, multiple devices, or entire cases.


View device information

View detailed information about a device and its owner.


Extract drone data

Extract and analyze drone data from physical dumps, drone logs, and mobile applications.


Find passwords to encrypted backups and images

Find passwords to encrypted backups and images by using various attacks and optimize the attacks to deliver unrivaled results at record speeds.


Facial categorization

Categorize human faces using the built-in facial recognition technology.


Access user files

Access a device's photos, audio and video files, databases, and other acquired evidence at the file-system level. View any file in a raw, hex mode, or native view.


Geo data

Extract and view geo coordinates from various sources - applications data, photo and video EXIF headers, history of wi-fi connections, etc.


Image categorization

Detect significant images including pornography, extremism, drugs, guns, and more with the built-in image categorization engine.


IoT device support

Extract and analyze data from IoT devices.


Tag key evidence

Mark important entries as key evidence in any program section and view them later in a single list.


Search for keywords

Create and use keyword lists to quickly find the relevant data during or after data extraction.


Live data extraction

Extract data from mobile devices based on iOS, Android, bada OS, or feature phones. Additionally, acquire device media and sim cards.


Location visualization

Open geo coordinates on the built-in maps, visualize the the user's movements, determine their frequently visited places, and find out if several people were at the same time at the same place.


Access messages

Gain access to SMS, MMS, email, and iMessage communications, and read them either in a table or chat view..


Optical character recognition

Automatically convert text on photos into machine-encoded text.


PList viewer

Open and examine PList files found in iOS device extractions. Use the converter panel to convert values into a readable format.


Social graph

Explore social connections between the device owner and their contacts or several devices by analyzing calls, messages, and app communication activities.



Navigating the enormous amount of data efficiently has always been our development objective. To prove this point, we have introduced the statistics section that offers an overview of the entire extraction and allows the investigator to quickly identify sections of interest.



Examine SQLite databases, recover deleted data, convert values, build SQL queries, perform searches, and export selected entries to reports.



View all events in chronological order: chats, calls, voicemails, photos, video history, wi-fi connections, geo files, and web cache.


User data collection on computer

Collect computer credentials and passwords using Oxygen Forensic® KeyScout.


Webkit data

Parse users’ emails from the webmail interface and the content of visited webpages. Gain access to email messages, web search history, locations, and other data stored in WebKit databases.


Wireless connections

Find out when and where the device owner used Internet access and gather information about frequent locations of iOS users.

System Requirements

Convinced yet?

Try our innovative all-in-one digital forensic solution, Oxygen Forensic® Detective, risk-free for 15 days.

Get a Free Trial