In digital forensics, access is everything. Investigators often face encrypted accounts, cloud services, and scattered artifacts that hold the answers to critical cases. Without the right “keys”, important evidence remains locked away — slowing investigations, driving up costs, and risking incomplete outcomes. 

That’s why Oxygen Forensics software includes two powerful tools — KeyScout and KeyDiver — designed to help investigators find, collect, and unlock the “keys to the kingdom.” Together, they provide access to critical credentials, tokens, and artifacts across computers, devices, and cloud services, accelerating case resolution and reducing investigative blind spots. 

Identify & Extract Artifacts with KeyScout 

KeyScout is a portable acquisition utility in Oxygen Forensic® Detective that scans Windows, macOS, and Linux systems to identify and extract relevant artifacts. These can include: 

  • User credentials and authentication tokens stored in browsers or apps 
  • Cloud service logins and account information 
  • Chat and messaging data from more than 80 supported applications 
  • Web browser histories 
  • Wi-Fi connections 
  • RAM data 
  • System artifacts 

KeyScout’s technology is especially valuable when used to: 

  • Target acquisitions 
  • Acquire credentials 
  • Analyze user activity and system usage 
  • Triage multiple machines concurrently 

WATCH: Collect Computer Artifacts from Windows, macOX, and Linux with KeyScout  

Recover Passwords & Unlock with KeyDiver 

KeyDiver is a password recovery tool in Oxygen Forensic® Detective for computer partitions, files, and applications, available at no extra charge. KeyDiver uses CPU and/or multiple GPUs and various candidate password generation methods to find unknown passwords. 

KeyDiver’s technology is particularly valuable when used to: 

  • Create hash-cracking attacks in a format supported by the Hashcat utility using various dictionaries and masks 
  • Run sequential attacks until the password is successfully guessed 
  • Save the obtained password/key to decrypt the original data or use it for other authorized purposes 

WATCH this Oxygen Tech Byte – How Investigators Crack Passwords with KeyDiver 

KeyScout + KeyDiver = Increased Chances for Recovering Passwords 

When used in tandem KeyScout and KeyDiver can force multiply your chances of recovering passwords, and here’s why: 

  • Humans use the same passwords 
  • Technology stores those passwords 
  • KeyScout recovers those passwords 
  • KeyDiver leverages those passwords 

Unlock, Access & Collect Data That Matters Most With KeyScout & KeyDiver  

Credentials and artifacts are the true keys to unlocking critical evidence in today’s complex investigations. With KeyScout and KeyDiver, Oxygen Forensics puts the keys to the kingdom in your hands to access, collect, and analyze the data that matters most — faster and more efficiently. 

Get started exploring KeyScout and KeyDiver and discover how you can unlock deeper insights in your next investigation.