Elcomsoft
548 subscribers
574 photos
1 video
1 file
459 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Forensic Implications of iOS Jailbreaking

Jailbreaking is used by the forensic community to access the file system of iOS devices, perform physical extraction and decrypt device secrets. Jailbreaking the device is one of the most straightforward ways to gain low-level access to many types of evidence not available with any other extraction methods.

In this article we’ll talk about the risks and consequences of using various jailbreak tools and installation methods.

👉 https://blog.elcomsoft.com/2019/06/forensic-implications-of-ios-jailbreaking/

#jb #jailbreaking #cryptography #encryption #dfir #mobileforensics #cloudforensics #dataextraction #iphone #cybersecurity #jailbreak
The Most Unusual Things about iPhone Backups

In this article we tried to gather everything we know about iTunes backup passwords to help you break (or reset) their passwords in the most efficient way.

👉 https://blog.elcomsoft.com/2019/06/unusual-iphone-backups/

#iphone #crypto #mobileforensics #cloudforensics #elcomsoft #mobilesecurity #cloud #icloud #iOS #dataextraction
Apple TV and Apple Watch Forensics 01: Acquisition

While the iPhone is Apple’s bread and butter product, is not the only device produced by the company. We’ve got the Mac (in desktop and laptop variations), the complete range of tablets (the iPad line, which is arguably the best tablet range on the market), the music device (HomePod), the wearable (Apple Watch), and the Apple TV. In today’s article, we are going to cover data extraction from Apple TV and Apple Watch. They do contain tons of valuable data, and are often the only source of evidence.

👉 https://blog.elcomsoft.com/2019/06/apple-tv-and-apple-watch-forensics-01-acquisition/

#iphone #iwatch #appletv #iosforensics #encryption #mobileforensics #evidence #digitalevidence #mobilesecurity
In general, iOS devices are very well protected, while some Android devices provide an even better level of security, Katalov said.

To protect your smart phone, Katalov recommends the following:

- Use at least a 6-digit passcode
- Make the passcode complex
- Enable USB restricted mode
- Know how to activate it (S.O.S.)
- Best of all, use an iPhone Xr or Xs model or newer

"For normal users, I think there is no risk at all," Katalov said. "Though, of course, I am looking for better iOS security in the future

👉 https://www.computerworld.com/article/3403385/what-the-latest-ios-passcode-hack-means-for-you.html

#apple #ios #ios12 #unlock #passcode #security #iOS12.3
Apple Watch Forensics 02: Analysis

During the years, starting from 2015, Apple manufactured five different models with WatchOS, a wearable OS based on iOS and specifically developed for the Apple Watch.

Since then, not a lot of research was done on how to extract data from this kind of devices. I have been working on this topic over the last months, by researching methods on how to extract and analyze data stored on the internal memory of the Apple Watch.

by Mattia Epifani
👉https://blog.elcomsoft.com/2019/06/apple-watch-forensics-02-analysis/

#iphone #iwatch #appletv #iosforensics #encryption #mobileforensics #evidence #digitalevidence #mobilesecurity #dataanalysis
Digital Forensics: Training Required

If you are working in the area of digital forensics, you might have wondered about one particular thing in the marketing of many forensic solutions. While most manufacturers are claiming that their tools are easy to use and to learn, those very same manufacturers offer training courses with prices often exceeding the cost of the actual tools. Are these trainings necessary at all if the tools are as easy to use as the marketing claims?

We believe so. A “digital” investigation is not something you can “fire and forget” by connecting a phone to a PC, running your favorite tool and pushing the button. Dealing with encrypted media, the most straightforward approach of brute-forcing your way is not always the best.

by Oleg Afonin
👉 https://blog.elcomsoft.com/2019/06/digital-forensics-training-required/

#police #cyber #cybersecurity #digitalforensics #cloudforensics #decryption #mobileforensics #training #elcomsoft
The Art of iPhone Acquisition

We all know how much important data is stored in modern smartphones, making them an excellent source of evidence. However, data preservation and acquisition are not as easy as they sound. There is no silver bullet or “fire and forget” solutions to solve cases or extract evidence on your behalf. In this article, which is loosely based on our three-day training program, we will describe the proper steps in the proper order to retain and extract as much data from the iPhone as theoretically possible.

The first steps: data preservation...

👉 https://blog.elcomsoft.com/2019/07/the-art-of-iphone-acquisition/

by Vladimir Katalov

#dfir #iphone #iOSforensics #mobile #cloud #dataextraction #digitalforensics #cybersecurity #elcomsoft #faradaybag
ElcomSoft Phone Breaker 9.15 supports iOS 13 and iPadOS beta, extracts iCloud tokens from macOS

Elcomsoft Phone Breaker 9.15 adds the ability to download iCloud backups created with iPhone and iPad devices running iOS 13 and iPadOS beta. In addition, the tool is now able to extract fully-featured iCloud authentication tokens from macOS computers and use that token on any other computer. The token can be used to authenticate into iCloud without using the login, password and two-factor authentication process.

👉 https://www.elcomsoft.com/news/722.html

#iOS13 #iPhone #Apple #iCloud #iPadOS #masOS #password #keychain #encryption #decryption #protection #authentication #token #dataaccess #extract #software
iOS 13 (Beta) Forensics


iOS 13 is on the way. While the new mobile OS is still in beta, so far we have not discovered many revolutionary changes in the security department. At the same time, there are quite a few things forensic specialists will need to know about the new iteration of Apple’s mobile operating system. In this article, we’ll be discussing the changes and their meaning for the mobile forensics.

by Vladimir Katalov

👉 https://blog.elcomsoft.com/2019/07/ios-13-beta-forensics/

#iOS13 #iPhone #smartphone #forensics #backups #decryption #dfir #software #encryption
Elcomsoft pinned a photo
Accessing iCloud With and Without a Password in 2019

In iOS forensics, cloud extraction is a viable alternative when physical acquisition is not possible. The upcoming release of iOS 13 brings additional security measures that will undoubtedly make physical access even more difficult. While the ability to download iCloud backups has been around for years, the need to supply the user’s login and password followed by two-factor authentication was always a roadblock.

It took us more than a year to figure out a workaround allowing experts to transfer authentication tokens from the user’s computer...

👉 https://blog.elcomsoft.com/2019/07/accessing-icloud-with-and-without-a-password-in-2019/

#software #forensics #dfir #encryption #iOS13 #icloud #password #2FA #backup #decryption #messages #token #keychain
Breaking and Securing Apple iCloud Accounts

The cloud becomes an ever more important (sometimes exclusive) source of the evidence whether you perform desktop or cloud forensics. Even if you are not in forensics, cloud access may help you access deleted or otherwise inaccessible data.

Let’s review all the possibilities of accessing Apple iCloud data with or without a password.

👉 https://blog.elcomsoft.com/2019/07/breaking-and-securing-apple-icloud-accounts/

#iCloud #iOS #forensocs #dfir #forensicsoftware #smartphone #encryption #2FA #toolkit #jailbreak #token #security #cloudsecurity #mobileforensics
Extended Mobile Forensics: Analyzing Desktop Computers

When it comes to mobile forensics, experts are analyzing the smartphone itself with possible access to cloud data. However, extending the search to the user’s desktop and laptop computers may (and possibly will) help accessing information stored both in the physical smartphone and in the cloud. In this article we’ll list all relevant artefacts that can shed light to smartphone data.

👉 https://blog.elcomsoft.com/2019/07/extended-mobile-forensics-analyzing-desktop-computers/

#iphone #ios #mobileforensics #cloud #dfir #cloudexplorer #phone #smartphone #phonebreaker #icloud #password
New Elcomsoft Cloud Explorer 2.20 fixes Google Photos support, boosts the number of data types available for acquisition, speeds up Photos downloading speed, switches from Google Maps to OpenStreetMap for showing you the user’s location history.

👉 https://www.elcomsoft.com/news/723.html

#google #security #cloud #smartphone #android #photo #locationhistory #maps #onestreetmap #download
Elcomsoft Phone Viewer 4.60 reveals Restrictions and Screen Time passwords, decrypts Signal history

Elcomsoft Phone Viewer can now recover and display Restrictions and Screen Time passwords when analysing iOS local backups. In addition, EPV 4.60 decrypts and displays conversation histories in Signal, one of the world’s most secure messaging apps.

👉 https://www.elcomsoft.com/news/724.html

#iphone #ios #signal #mobileforensics #screentime #password #messenger
Apple TV Forensics 03: Analysis

This post continues the series of articles about Apple companion devices. If you haven’t seen them, you may want to read Apple TV and Apple Watch Forensics 01: Acquisition first. If you are into Apple Watch forensics, have a look at Apple Watch Forensics 02: Analysis as well. Today we’ll have a look at what’s inside of the Apple TV.

A recent market analysis shows that Apple has sold more than 13 million Apple TV devices worldwide since 2016. Since 2007, Apple manufactured 6 different Apple TV models.

Read the complete article 👉 https://blog.elcomsoft.com/2019/09/apple-tv-forensics-03-analysis/

#ios #appletv #security #forensics #chimera #elcomsoft #filesystem #tvos #jailbreak
Elcomsoft iOS Forensic Toolkit 5.10 is updated to support physical acquisition of Apple devices running iOS 12.2 and 12.4. The Toolkit enables file system extraction for all devices supported by unc0ver and Chimera jailbreaks including the iPhone Xr and iPhone Xs. In addition, the Toolkit allows decrypting the keychain to extract stored passwords and authentication credentials (with the exception of A12/A12X devices).

👉 https://www.elcomsoft.com/news/725.html

#iOS #toolkit #iphone #jailbreak #chimera #unc0ver #jb #iOS12.4 #filesystem #passwords #keychain #decryption #mobileforensics #dfir
iOS Acquisition on Windows: Tips&Tricks

When you perform Apple iCloud acquisition, it almost does not matter what platform to use, Windows or macOS (I say almost, because some differences still apply, as macOS has better/native iCloud support). Logical acquisition can be done on any platform as well. But when doing full file system acquisition of jailbroken devices using Elcomsoft iOS Forensic Toolkit, we strongly recommend using macOS. If you are strictly tied to Windows, however, there are some things you should know.

👉 https://blog.elcomsoft.com/2019/09/ios-acquisition-on-windows-tipstricks/

#ios #toolkit #windows #mobileforensics #decryption #shh #dmg
USB Restricted Mode in iOS 13: Apple vs. GrayKey, Round Two

While the dust surrounding the controversy of rushed iOS 13 release settles, we are continuing our research on what has changed in iOS forensics. In this article we’ll review the new policy on USB restrictions and lockdown record expiration in the latest iOS release. We’ll also analyze how these changes affect experts investigating iPhone devices updated to the latest OS release.

👉 https://blog.elcomsoft.com/2019/09/usb-restricted-mode-in-ios-13-apple-vs-graykey-round-two/

#ios #usbrestrictedmode #apple #graykey #grayshift #access #iphone #accessorypairing #lockdown
Elcomsoft Phone Breaker 9.20 extracts Screen Time passwords and Voice Memos from iCloud

Elcomsoft Phone Breaker 9.20 expands the list of supported data categories, adding iOS Screen Time and Voice Memos. Screen Time passwords and some additional information can be extracted from iCloud along with other synchronized data, while Voice Memos can be extracted from local and cloud backups and iCloud synchronized data.

Elcomsoft Phone Breaker and Elcomsoft Phone Viewer are updated with support for two additional data categories. Users of EPB 9.20 and EPV 4.70 can now extract and analyze audio recordings made with Apple’s Voice Memos app. In addition, the tools allow extracting and analyzing Screen Time passwords as well as certain additional data.

👉 https://www.elcomsoft.com/news/726.html

#iphone #ios #icloud #screentime #password #passcode #voicememo #audiorecording #mobileforensics #cloudforensics