Elcomsoft
548 subscribers
574 photos
1 video
1 file
459 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Elcomsoft iOS Forensic Toolkit 5.10 is updated to support physical acquisition of Apple devices running iOS 12.2 and 12.4. The Toolkit enables file system extraction for all devices supported by unc0ver and Chimera jailbreaks including the iPhone Xr and iPhone Xs. In addition, the Toolkit allows decrypting the keychain to extract stored passwords and authentication credentials (with the exception of A12/A12X devices).

👉 https://www.elcomsoft.com/news/725.html

#iOS #toolkit #iphone #jailbreak #chimera #unc0ver #jb #iOS12.4 #filesystem #passwords #keychain #decryption #mobileforensics #dfir
iOS Acquisition on Windows: Tips&Tricks

When you perform Apple iCloud acquisition, it almost does not matter what platform to use, Windows or macOS (I say almost, because some differences still apply, as macOS has better/native iCloud support). Logical acquisition can be done on any platform as well. But when doing full file system acquisition of jailbroken devices using Elcomsoft iOS Forensic Toolkit, we strongly recommend using macOS. If you are strictly tied to Windows, however, there are some things you should know.

👉 https://blog.elcomsoft.com/2019/09/ios-acquisition-on-windows-tipstricks/

#ios #toolkit #windows #mobileforensics #decryption #shh #dmg
USB Restricted Mode in iOS 13: Apple vs. GrayKey, Round Two

While the dust surrounding the controversy of rushed iOS 13 release settles, we are continuing our research on what has changed in iOS forensics. In this article we’ll review the new policy on USB restrictions and lockdown record expiration in the latest iOS release. We’ll also analyze how these changes affect experts investigating iPhone devices updated to the latest OS release.

👉 https://blog.elcomsoft.com/2019/09/usb-restricted-mode-in-ios-13-apple-vs-graykey-round-two/

#ios #usbrestrictedmode #apple #graykey #grayshift #access #iphone #accessorypairing #lockdown
Elcomsoft Phone Breaker 9.20 extracts Screen Time passwords and Voice Memos from iCloud

Elcomsoft Phone Breaker 9.20 expands the list of supported data categories, adding iOS Screen Time and Voice Memos. Screen Time passwords and some additional information can be extracted from iCloud along with other synchronized data, while Voice Memos can be extracted from local and cloud backups and iCloud synchronized data.

Elcomsoft Phone Breaker and Elcomsoft Phone Viewer are updated with support for two additional data categories. Users of EPB 9.20 and EPV 4.70 can now extract and analyze audio recordings made with Apple’s Voice Memos app. In addition, the tools allow extracting and analyzing Screen Time passwords as well as certain additional data.

👉 https://www.elcomsoft.com/news/726.html

#iphone #ios #icloud #screentime #password #passcode #voicememo #audiorecording #mobileforensics #cloudforensics
How to Extract Screen Time Passcodes and Voice Memos from iCloud

With Elcomsoft Phone Breaker 9.20, the following Screen Time data is extracted: the Screen Time password (both parents’ and children’s, if any child accounts are present); information about all devices sharing Screen Time data through iCloud, including the list of installed applications on these devices (including Mac computers and Apple Watch). In addition, the tool extracts information about configured restrictions. You can view all of that data in Elcomsoft Phone Viewer 4.70.

👉 https://blog.elcomsoft.com/2019/10/how-to-extract-screen-time-passcodes-and-voice-memos-from-icloud/
#password #passcode #dfir #mobilesecurity #iossecurity #screentime #iphone
Installing and using iOS Forensic Toolkit on macOS 10.15 Catalina

The release of macOS Catalina brought the usual bunch of security updates. One of those new security features directly affects how you install Elcomsoft iOS Forensic Toolkit on Macs running the new OS. In this guide we’ll provide step by step instructions on installing and running iOS Forensic Toolkit on computers running macOS 10.15 Catalina. Note: on macOS Catalina, you must use iOS Forensic Toolkit 5.11 or newer (older versions may also work but not recommended).

👉 https://blog.elcomsoft.com/2019/10/installing-and-using-ios-forensic-toolkit-on-macos-catalina/

#Catalina #macOS #eift #toolkit #apple #update #upd #dataacquisition
Four and a Half Apple Passwords

Passwords are probably the oldest authentication method. Despite their age, passwords remain the most popular authentication method in today’s digital age.
Passwords are everywhere. Even your phone has more than one password. Speaking of Apple iPhone, the thing may require as many as four (and a half) passwords to get you going. To make things even more complicated, the four and a half passwords are seriously related to each other. Let’s list them:

♦️Screen lock password;
♦️iCloud password;
♦️iTunes backup password;
♦️Screen Time password;
🔻One-time codes

In this article, we will provide an overview on how these passwords are used and how they are related to each other; what are the default settings and how they affect your privacy and security. We’ll tell you how to use one password to reset another

👉 https://blog.elcomsoft.com/2019/10/four-and-a-half-apple-passwords/

#password #passcode #appleid #mobilesecurity #iossecurity #screentime #iphone
ElcomSoft Phone Breaker 9.30 is out with new iCloud engine, low-level iCloud Drive access, iOS 13.2 and macOS Catalina support

Elcomsoft Phone Breaker 9.30 delivers a new iCloud downloading engine and low-level access to iCloud Drive data. Thanks to the new iCloud engine, the tool can download backups produced by devices running all versions of iOS up to iOS 13.2. The new and improved iCloud downloading engine, the new iCloud Drive analysis core and the many bug fixes make EPB 9.30 a highly recommended update.

👉 https://www.elcomsoft.com/news/727.html

#iphone #ios #icloud #screentime #password #passcode #voicememo #audiorecording #mobileforensics #cloudforensics
Synology NAS Encryption: Forensic Analysis of Synology NAS Devices

Home users and small offices are served by two major manufacturers of network attached storage devices (NAS): QNAP and Synology, with Western Digital being a distant third. All Qnap and Synology network attached storage models are advertised with support for hardware-accelerated AES encryption. Encrypted NAS devices can be a real roadblock on the way of forensic investigations. In this article, we’ll review the common encryption scenarios used in home and small office models of network attached storage devices made by Synology.

👉 https://blog.elcomsoft.com/2019/11/synology-nas-encryption-forensic-analysis-of-synology-nas-devices/

#encryption #crypto #itsecurity #nasforensics #synology #aes #stogaredevices
It's been a great pleasure meeting with you at China Computer Forensics Conference this month! Thank you for your sheer interest to our forensic technologies, for your numerous questions and involvement! We could not possibly cover all of your questions at the conference, but you can definitely dive deeper at our trainings where you are always welcome to participate:

👉 https://www.elcomsoft.com/elcomsoft_trainings.html

#dataextraction #dfir #elcomsoft #itsecurity #software #cybersecurity #informationtechnology #computerscience #riskmanagement #privacy #pentest #bruteforce #passwordcracking #code #apple #windows #innovation #security #digitalforensics #computercrime
What is Password Recovery and How It Is Different from Password Cracking

Why wasting time recovering passwords instead of just breaking in? Why can we crack some passwords but still have to recover the others? Not all types of protection are equal. There are multiple types of password protection, all having their legitimate use cases. In this article, we’ll explain the differences between the many types of password protection.

👉 https://blog.elcomsoft.com/2019/11/what-is-password-recovery-and-how-it-is-different-from-password-cracking/

#password #security #cryptography #software #passwordcracking #passwordrecovery #decryption #passwordprotection
Forensic Acquisition of Apple TV with checkra1n Jailbreak

Are you excited about the new checkm8 exploit? If you haven’t heard of this major development in the world of iOS jailbreaks, I would recommend to read the Technical analysis of the checkm8 exploit aricle, as well as Developer of Checkm8 explains why iDevice jailbreak exploit is a game changer. The good news is that a jailbreak based on this exploit is already available, look at the checkra1n web site.

The jailbreak based on checkm8 supports iPhone devices based on Apple’s 64-bit platform ranging from the iPhone 5s all the way up to the iPhone 8 and iPhone X. Unlike previous jailbreaks, this one...

👉 https://blog.elcomsoft.com/2019/11/forensic-acquisition-of-apple-tv-checkra1n-jailbreak/

#jb #jailbreak #checkra1n #ios #security #mobileforensics #appletv #dataextraction #dfir #eift
iOS Device Acquisition with checkra1n Jailbreak

We’ve just announced a major update to iOS Forensic Toolkit, now supporting the full range of devices that can be exploited with the unpatchable checkra1n jailbreak. Why is the checkra1n jailbreak so important for the forensic community, and what new opportunities in acquiring Apple devices does it present to forensic experts? We’ll find out what types of data are available on both AFU (after first unlock) and BFU (before first unlock) devices, discuss the possibilities of acquiring locked iPhones, and provide instructions on installing the checkra1n jailbreak.

checkra1n is not about just the iPhones. We have recently tested checkra1n with Apple TV 4. Today is the day to try the new jailbreak with Apple’s bread-and-butter product, the iPhone...

👉 https://blog.elcomsoft.com/2019/11/ios-device-acquisition-with-checkra1n-jailbreak/

#checkra1n #jailbreak #jb #mobileforensics #eift #toolkit #ios #iPhone #exploit
iOS Forensic Toolkit 5.20 adds future-proof file system extraction support for Apple devices with checkra1n jailbreak

Elcomsoft iOS Forensic Toolkit 5.20 is updated with file system extraction support for select Apple devices running all versions of iOS from iOS 12 to iOS 13.3. Making use of the new future-proof bootrom exploit built into the checkra1n jailbreak, EIFT is able to extract the full file system image, decrypt passwords and authentication credentials stored in the iOS keychain.

👉 https://www.elcomsoft.com/news/728.html

#checkra1n #jailbreak #jb #mobileforensics #eift #toolkit #ios #iPhone #exploit #informationtechnology #computerscience #riskmanagement #imessage #privacy #pentest #bruteforce #passwordcracking #code #apple #innovation #security #digitalforensics #computercrime
ElcomSoft Phone Breaker 9.40 is out with support for Skype chats, files and metadata

Elcomsoft Phone Breaker 9.40 adds support for Skype chats, media files, contact lists and metadata. The update enables experts to download conversation histories, pictures and files, while the updated Elcomsoft Phone Viewer can display downloaded data as well as metadata for deleted chats and files purged from Skype servers.

👉 https://www.elcomsoft.com/news/729.html

#skype #microsoft #dataextraction #dataprotection #security #chats #synced #contacts #mobileforensics #cloud #messages #conversations #deleteddata
Extracting Skype Histories and Deleted Files Metadata from Microsoft Account

Skype synchronizes chats, text messages and files sent and received with the Microsoft Account backend. Accessing Skype conversation histories by performing a forensic analysis of the user’s Microsoft Account is often the fastest and easiest way to obtain valuable evidence. Learn how to use Elcomsoft Phone Breaker to quickly extract the complete conversation histories along with attachments and metadata from the user’s Microsoft Account.

What’s It All About?

👉 https://blog.elcomsoft.com/2019/12/extracting-skype-histories-and-deleted-files-metadata-from-microsoft-account/

#skype #microsoft #microsoftaccount #messages #contacts #synceddata #protection #clouds #conversationhistories
iOS Forensic Toolkit 5.21 extracts keychain from locked iOS devices

Elcomsoft iOS Forensic Toolkit 5.21 is updated to support the extraction of iOS keychain from locked and disabled devices. Before-first-unlock (BFU) extraction is available on select Apple devices via the checkra1n jailbreak.

👉 https://www.elcomsoft.com/news/730.html

#iphone #iOS #keychain #checkra1n #dataextraction #mobileforensics #encryption #apple #locked #passwords
BFU Extraction: Forensic Analysis of Locked and Disabled iPhones

We have recently updated Elcomsoft iOS Forensic Toolkit, adding the ability to acquire the file system from a wide range of iOS devices. The supported devices include models ranging from the iPhone 5s through the iPhone X regardless of the iOS version; more on that in iOS Device Acquisition with checkra1n Jailbreak. In today’s update, we’ve added the ability to extract select #keychain records in the BFU (Before First Unlock) mode. We have a few other changes and some tips on extracting locked and disabled devices.

BFU Forensics

The BFU stands for “Before First Unlock”. BFU devices are those that have been powered off or rebooted and have never been subsequently unlocked, not even once, by entering the correct screen lock passcode.

In Apple’s world, the content of the iPhone remains securely encrypted until the moment...

👉 https://blog.elcomsoft.com/2019/12/bfu-extraction-forensic-analysis-of-locked-and-disabled-iphones/

#checkra1n
Challenges in Computer and Mobile Forensics: What to Expect in 2020

The past two years introduced a number of challenges forensic experts have never faced before. In 2018 Apple made it more difficult for the police to safely transport a seized iPhone to the lab by locking the USB port with USB restricted mode, making data preservation a challenge.

On desktop and especially laptop computers, the widespread use of SSD drives made it impossible to access deleted data due to trim and garbage collection mechanisms. The users’ vastly increased reliance on cloud services and mass migration off the forensically transparent SMS platform towards the use of end-to-end encrypted messaging apps made communications more difficult to intercept and analyze.

Sheer amounts of data are greater than ever... Does hi-tech forensic stand a chance with more data, more apps, more devices and increasingly strong encryption?

https://blog.elcomsoft.com/2019/12/challenges-in-computer-and-mobile-forensics-what-to-expect-in-2020/
Our Developments and Achievements in 2019

For us, this year has been extremely replete with all sorts of developments in desktop, mobile and cloud forensics. We are proud with our achievements and want to share with you. Let’s have a quick look at what we’ve achieved in the year 2019.

👉 https://blog.elcomsoft.com/2019/12/our-developments-and-achievements-in-2019/

#ios #software #mobileforensics #cloudsecurity #google #iphone #skype #whatsapp #signal #screentime #applehealth #dataextraction #passwords
Attached Storage Forensics: Security Analysis of Thecus NAS

Thecus has been manufacturing NAS devices for more than 15 years. The company develops an in-house Linux-based NAS OS, the ThecusOS. At this time, the most current version of the OS is ThecusOS 7. Thecus advertises secure data encryption in most of its NAS devices. The company’s volume-based encryption tool allows users to fully encrypt their entire RAID volume, defending essential data in instances of theft of the physical device. We found Thecus’ implementation of encryption somewhat unique. In this research, we’ll verify the manufacturer’s claims and check just how secure is Thecus’ implementation of 256-bit AES encryption.

by Oleg Afonin

👉🏻 https://blog.elcomsoft.com/2020/01/attached-storage-forensics-security-analysis-of-thecus-nas/

#ThecusOS #Thecus #NAS #Encryption #Forensics