Silent Phone Data Extraction in Oxygen Forensic® Detective

Silent Phone App

Silent Phone is positioned as an app that enables secure calls and messaging on Apple iOS and Android devices. The app was developed by Silent Circle, an encrypted communications firm based in Washington, DC.

Silent Phone is described as “an incredible end-to-end military-grade encryption app that can be used by anyone who wishes to keep their communication private”.

This app is considered to be more secure than its competitors, providing not only end-to-end encryption but also backdoor policy, self-destructing messages, and marginal access to personal data.

Not surprisingly, such a level of security is appealing to those trying to keep their conversations private. Not all conversations are businesses conducting confidential negotiations; sometimes confidentiality is needed for illegal affairs.

 

Silent Phone Data Extraction

We first added support for Silent Phone app last year. To extract and decrypt it from Apple iOS devices, full file system extraction via checkm8 is required.

The following artifacts can be extracted:

  • Account
  • Cache
  • Calls
  • Chats
  • Contacts
  • Group chats info

From Android devices, investigators can acquire Silent Phone data using the Android full file system method. This method will extract encryptions keys from the Android KeyStore to decrypt app data.

The following artifacts can be extracted:

  • Account
  • Calls
  • Chats
  • Chats info
  • Contacts
  • Cookies
  • Devices
  • Group chats info

 

In Oxygen Forensic® Detective v.14.5, we introduced an alternative method of Silent Phone extraction. Now, investigators can quickly collect Silent Phone data from any unlocked Android device using OxyAgent.

OxyAgent can be installed on a device via USB, WiFi, or OTG device. Once OxyAgent is installed, investigators can choose all or selected entries for extraction.

OxyAgent installed on cellphone that is going to have silent phone data extracted

Extracted evidence includes account information, contacts, private and group chats, and attachments. Please note that the Silent Phone app stores chats for a limited time only and then wipes them.

Once the acquisition process is finished, the OxyAgent extraction can be imported into Oxygen Forensic® Detective for review and analysis.

Data that was collected from the extraction of Silent Phone app in Oxygen Forensic® Detective

Besides Silent Phone, investigators can extract many other popular apps from any unlocked Android device via OxyAgent: WhatsApp, Signal, Telegram, Wickr, etc.

Conclusion

Having the ability to extract data from the Silent Phone app via OxyAgent allows for investigators to see conversations, calls, and videos that without Oxygen Forensic® Detective they would’ve not been unable to access due to end-to-end encryption.

Interested in trying this new feature but don’t have an Oxygen Forensic® Detective license? Request a free trial by clicking here.