

Mobile Device Data Extraction
Advanced Resources represents MSAB in Portugal— global leader in mobile forensic technology. From unlocking the most secure devices to analyzing and reporting on digital evidence, the MSAB ecosystem covers the entire investigative process.
XRY PRO
Access to the most secure devices on the market
XRY Pro is MSAB’s most advanced data extraction tool. Designed for experienced investigators who regularly deal with locked and heavily protected devices, it uses state-of-the-art proprietary exploits and brute-force techniques to access data that other tools cannot reach.
All data extraction is performed on-site at the client’s facilities by certified personnel, ensuring the chain of custody and complying with the organization’s internal policies. The process is fully offline and auditable.
Unique proprietary exploits
Proprietary techniques developed by MSAB to bypass the security mechanisms of modern smartphones, including Qualcomm, Exynos, Tensor, UNISOC, MediaTek, and Kirin chipsets.
Support for FDE, FBE, and Secure Startup
Compatible with Full Disk Encryption (FDE) and File-Based Encryption (FBE)—the most common encryption methods in modern Android—as well as Secure Startup.
RAM extraction and analysis
The only tool on the market capable of extracting RAM data from mobile devices. It allows you to capture volatile and sensitive data—decryption keys, active sessions, application data—that disappears after a reboot.
Python scripting integration
Automate and customize data extraction directly in XRY Pro using Python scripts—at no additional licensing cost.
License with no geographic restrictions
The XRY Pro license is not limited to a specific location. It is available as either an unlimited license or a token-based license, adaptable to the volume and nature of the organization’s investigations.
Comprehensive audit and chain of custody
Every action is recorded and can be exported. A secure proprietary file format ensures the integrity of the evidence from start to finish—ready for presentation in court.
BruteStorm Surge
Next-generation password recovery solution that leverages the processing power of GPUs to unlock devices much faster than traditional CPU-based methods. The process is performed offline, without the device being powered on, thereby eliminating risks to the integrity of the evidence.
- Smart dictionary attacks — the system automatically generates and tests password variations based on known patterns, without manual intervention
- Multiple attack modes that can be configured based on the complexity of the case
- Linear scalability with multiple GPUs — ideal for high-volume labs
- Compatible with Android FBE and FDE encryption
- Includes 2 hours of consulting for initial setup
- Also available as a managed service provided by MSAB Professional Services
RAM Forensics (RAMalyser)
RAM extraction and analysis on mobile devices is a capability unmatched in the forensic market. XRY Pro allows you to capture the volatile memory of a running device—data that no other tool can retrieve after a reboot.
- The industry's only solution for extracting RAM from smartphones
- Capture active decryption keys, application sessions, and ongoing communications
- Critical data that exists only while the device is turned on and active
- Integrated analysis with MSAB RAMalyser — a tool designed for RAM data processing
- Essential for operations involving arrests in the act or devices seized while in use
- Recommended for highly critical situations involving AFU devices
XAMN PRO
From extraction to testing: the fastest route
XAMN Pro is the most comprehensive forensic analysis and reporting tool for mobile device data. Designed with a single goal in mind—to enhance analytical efficiency—it allows you to search, filter, view, and cross-reference massive volumes of data to quickly and accurately identify relevant evidence.
It processes XRY extracts, third-party tools, call data records (CDR), cloud data, warrant returns, and much more—all within a single analytics environment.
Supported data sources
- XRY Exractions (Logical, Physical, Cloud)
- Third-party tools (Cellebrite, Oxygen, etc.)
- Call Data Records (CDR)
- Warrant returns from operators and platforms
- Data from drones, GPS, and vehicle systems
- Requests for personal data (GDPR/court orders)
Connection View
A graphical view of the relationships between devices, accounts, and people—automatically identifies relevant connections and interactions between individuals.
Conversations View
It displays WhatsApp, Telegram, Signal, and other app conversations exactly as they appear in the original app, with the full context of the thread.
Maps View
Geolocation of artifacts using location data — visualize routes, points of interest, and correlate them with a timeline.
Timeline View
Chronological browsing of all device activity — allows you to construct a factual account of the events under investigation.
Gallery View
Efficient review of images and media files using advanced filters, including automatic AI-powered classification (weapons, drugs, people, etc.).
Hex View + Carving
Advanced hex carving tool for experts — allows you to dig deeper into undeciphered or fragmented data and reconstruct critical artifacts.
For additional information about forensic investigation solutions, from MSAB or other partners, please contact us.
