Legal Cyber Academy
ToolPaidCurrent

MSAB XRY

MSAB · 2026

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A commercial mobile forensics family from the Swedish vendor MSAB, sold as separate modules rather than one product: XRY Logical for live and file system extraction, XRY Physical for bypassing the operating system, XRY Pro combining advanced extraction and decryption, plus XRY Cloud, XRY Photon for screen-scraping app data, and XRY Camera for device documentation.

Who it is for, and when

XRY is the main European alternative to Cellebrite in mobile extraction, and it is widely deployed in law enforcement, so an expert reviewing disclosure in those matters needs to read its output. The modular structure lets an organisation buy only the extraction depth it can lawfully use. XRY Photon is worth knowing about specifically: screen-scraping recovers app content that is otherwise inaccessible on a device that cannot be extracted conventionally, though what it produces is a recording of a session rather than the underlying data.

What it does not cover

Pricing is not published — MSAB directs enquiries to sales, and the modular licensing means the capability you need may not be in the licence you have. Device support is not identical to Cellebrite's, so a handset one tool cannot reach may still be reachable by the other; never treat a failed extraction on one vendor's tool as proof the data is unobtainable. It is a mobile tool only, with no role in computer, memory, or network examination.

Go to the source

Open at msab.com (opens in a new tab)

https://www.msab.com/products/xry/

Details

Type
Tool
Written for
Working examinerAdvancedWorking examiner, Advanced
Publisher
MSAB
Year
2026
Topics
commercial-suite, mobile, ios, android, cloud, reporting
Checked at source
  • Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.

  • A family of open-source Python parsers for mobile and returns data: iLEAPP for iOS logs, events and plists, ALEAPP for Android, and RLEAPP for returns and records from cloud and carrier providers. All three are released very frequently and are among the most actively maintained tools in mobile forensics.

  • A device-by-device walkthrough of mobile acquisition and analysis: iOS and Android internals and file systems, logical and physical extraction, app and SQLite artifacts, cloud extraction, mobile malware and reporting.

  • Belkasoft's flagship acquisition and analysis product, covering computer, mobile, drone, vehicle, and cloud evidence in one case. It is split by customer type: Belkasoft X Forensic is offered to government customers, while Belkasoft X Corporate targets businesses for internal investigations and ediscovery. Belkasoft also publishes free Triage and Live RAM Capturer utilities.

  • A commercial digital forensics platform that acquires, processes, and reports on computer, mobile, cloud, and vehicle data in a single case, organised around artefact recovery rather than raw file system browsing. AXIOM Cyber is the variant aimed at corporate incident response, internal investigations, and ediscovery, adding remote endpoint collection.