MSAB
A publicly-traded Stockholm-based mobile device forensics company whose XRY and XAMN product family extracts court-admissible evidence for law enforcement, government, and incident response investigations.
Visit Website ↗ + Add to CompareOverview
MSAB (Micro Systemation AB) is a Stockholm, Sweden-based digital forensics company, incorporated in 1984 and publicly listed on Nasdaq Stockholm under the ticker MSAB B. The company’s sole focus is mobile device forensics: extracting, decrypting, and analyzing data from phones and tablets in a forensically sound, court-admissible manner for use as evidence in investigations.
Its flagship product, XRY, has been used since 2003 to retrieve data from mobile devices, and the current product family — XRY, XAMN, XEC, and UNIFY — covers extraction, analysis, and case-management workflows. MSAB states its tools are used by more than 4,000 customer organizations in over 140 countries, primarily law enforcement, defense, government agencies, and forensic laboratories, for criminal investigations, fraud cases, and eDiscovery.
As a decades-old public company with roughly 200-300 employees across offices on multiple continents, MSAB is a mature, stable vendor rather than an emerging startup. Its relevance to this site’s enterprise cybersecurity audience is narrower and more specific than platform security vendors: it is most useful in incident response, insider threat investigation, and litigation contexts where an organization needs forensically defensible evidence from a mobile device, rather than as a preventive or detective security control.
Innovation Matrix Assessment
MSAB has continuously evolved its product family from XRY (2003) to XAMN, XEC, and UNIFY over two decades, a steady but measured pace consistent with a mature public company rather than a fast-moving startup.
As a publicly traded company reporting more than 4,000 customer organizations across 140+ countries, MSAB demonstrates clear operational scale and financial transparency uncommon among private forensics vendors.
Employee headcount has grown modestly (from roughly 209 to 289 employees in recent years) with no major funding events since going public; growth is steady rather than accelerating.
XRY and XAMN are established category-defining products in mobile forensics rather than a novel technical approach; MSAB's advantage is deep, incremental device-compatibility coverage built up over 20+ years.
MSAB's extraction tools are used to produce evidence relied upon in actual court proceedings across a stated 140+ countries, providing a real-world efficacy signal that is independently reinforced by the breadth of its public customer base rather than resting on unverified vendor claims alone.
Mobile forensics is essential to incident response, insider-threat investigation, and litigation, but MSAB's core market is law enforcement and government rather than commercial enterprise security operations, narrowing its direct relevance to this site's typical buyer.
Why CISOs Should Care
For CISOs and incident response teams handling insider threat investigations, litigation holds, or coordination with law enforcement after a breach involving mobile devices, MSAB provides forensically sound, court-admissible evidence extraction that in-house teams typically cannot replicate.
What Makes It Different
Unlike broader digital forensics suites that cover many evidence types, MSAB has specialized specifically in mobile device extraction and analysis for over two decades, building device-compatibility depth that generalist forensics vendors struggle to match.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A mature, publicly-traded, category-defining mobile forensics vendor with genuine scale and real courtroom-tested credibility; its relevance to this site's enterprise-security audience is narrower than platform vendors and centers on incident response and insider-threat investigation use cases.
Editorial Note: Claims vs. Verified Findings
MSAB's customer count (4,000+ organizations in 140+ countries) and public-company status (Nasdaq Stockholm: MSAB B) are independently verifiable through public financial filings, a stronger evidentiary basis than typical private-vendor marketing claims. MSAB's products are sold for lawful forensic investigation and courtroom evidence to law enforcement, government, and defense customers -- distinct from covert offensive surveillance tooling -- but its core market remains government/law enforcement rather than commercial enterprise security teams.
Sources
Alternatives to MSAB
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…
Google Security Operations
Google's cloud-scale SIEM/SOAR (formerly Chronicle), unifying a petabyte-scale data lake with Mandiant frontline threat intelligence and Gemini-powered investigation.