Elcomsoft
548 subscribers
574 photos
1 video
1 file
459 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Synology NAS Encryption: Forensic Analysis of Synology NAS Devices

Home users and small offices are served by two major manufacturers of network attached storage devices (NAS): QNAP and Synology, with Western Digital being a distant third. All Qnap and Synology network attached storage models are advertised with support for hardware-accelerated AES encryption. Encrypted NAS devices can be a real roadblock on the way of forensic investigations. In this article, we’ll review the common encryption scenarios used in home and small office models of network attached storage devices made by Synology.

👉 https://blog.elcomsoft.com/2019/11/synology-nas-encryption-forensic-analysis-of-synology-nas-devices/

#encryption #crypto #itsecurity #nasforensics #synology #aes #stogaredevices
It's been a great pleasure meeting with you at China Computer Forensics Conference this month! Thank you for your sheer interest to our forensic technologies, for your numerous questions and involvement! We could not possibly cover all of your questions at the conference, but you can definitely dive deeper at our trainings where you are always welcome to participate:

👉 https://www.elcomsoft.com/elcomsoft_trainings.html

#dataextraction #dfir #elcomsoft #itsecurity #software #cybersecurity #informationtechnology #computerscience #riskmanagement #privacy #pentest #bruteforce #passwordcracking #code #apple #windows #innovation #security #digitalforensics #computercrime
What is Password Recovery and How It Is Different from Password Cracking

Why wasting time recovering passwords instead of just breaking in? Why can we crack some passwords but still have to recover the others? Not all types of protection are equal. There are multiple types of password protection, all having their legitimate use cases. In this article, we’ll explain the differences between the many types of password protection.

👉 https://blog.elcomsoft.com/2019/11/what-is-password-recovery-and-how-it-is-different-from-password-cracking/

#password #security #cryptography #software #passwordcracking #passwordrecovery #decryption #passwordprotection
Forensic Acquisition of Apple TV with checkra1n Jailbreak

Are you excited about the new checkm8 exploit? If you haven’t heard of this major development in the world of iOS jailbreaks, I would recommend to read the Technical analysis of the checkm8 exploit aricle, as well as Developer of Checkm8 explains why iDevice jailbreak exploit is a game changer. The good news is that a jailbreak based on this exploit is already available, look at the checkra1n web site.

The jailbreak based on checkm8 supports iPhone devices based on Apple’s 64-bit platform ranging from the iPhone 5s all the way up to the iPhone 8 and iPhone X. Unlike previous jailbreaks, this one...

👉 https://blog.elcomsoft.com/2019/11/forensic-acquisition-of-apple-tv-checkra1n-jailbreak/

#jb #jailbreak #checkra1n #ios #security #mobileforensics #appletv #dataextraction #dfir #eift
iOS Device Acquisition with checkra1n Jailbreak

We’ve just announced a major update to iOS Forensic Toolkit, now supporting the full range of devices that can be exploited with the unpatchable checkra1n jailbreak. Why is the checkra1n jailbreak so important for the forensic community, and what new opportunities in acquiring Apple devices does it present to forensic experts? We’ll find out what types of data are available on both AFU (after first unlock) and BFU (before first unlock) devices, discuss the possibilities of acquiring locked iPhones, and provide instructions on installing the checkra1n jailbreak.

checkra1n is not about just the iPhones. We have recently tested checkra1n with Apple TV 4. Today is the day to try the new jailbreak with Apple’s bread-and-butter product, the iPhone...

👉 https://blog.elcomsoft.com/2019/11/ios-device-acquisition-with-checkra1n-jailbreak/

#checkra1n #jailbreak #jb #mobileforensics #eift #toolkit #ios #iPhone #exploit
iOS Forensic Toolkit 5.20 adds future-proof file system extraction support for Apple devices with checkra1n jailbreak

Elcomsoft iOS Forensic Toolkit 5.20 is updated with file system extraction support for select Apple devices running all versions of iOS from iOS 12 to iOS 13.3. Making use of the new future-proof bootrom exploit built into the checkra1n jailbreak, EIFT is able to extract the full file system image, decrypt passwords and authentication credentials stored in the iOS keychain.

👉 https://www.elcomsoft.com/news/728.html

#checkra1n #jailbreak #jb #mobileforensics #eift #toolkit #ios #iPhone #exploit #informationtechnology #computerscience #riskmanagement #imessage #privacy #pentest #bruteforce #passwordcracking #code #apple #innovation #security #digitalforensics #computercrime
ElcomSoft Phone Breaker 9.40 is out with support for Skype chats, files and metadata

Elcomsoft Phone Breaker 9.40 adds support for Skype chats, media files, contact lists and metadata. The update enables experts to download conversation histories, pictures and files, while the updated Elcomsoft Phone Viewer can display downloaded data as well as metadata for deleted chats and files purged from Skype servers.

👉 https://www.elcomsoft.com/news/729.html

#skype #microsoft #dataextraction #dataprotection #security #chats #synced #contacts #mobileforensics #cloud #messages #conversations #deleteddata
Extracting Skype Histories and Deleted Files Metadata from Microsoft Account

Skype synchronizes chats, text messages and files sent and received with the Microsoft Account backend. Accessing Skype conversation histories by performing a forensic analysis of the user’s Microsoft Account is often the fastest and easiest way to obtain valuable evidence. Learn how to use Elcomsoft Phone Breaker to quickly extract the complete conversation histories along with attachments and metadata from the user’s Microsoft Account.

What’s It All About?

👉 https://blog.elcomsoft.com/2019/12/extracting-skype-histories-and-deleted-files-metadata-from-microsoft-account/

#skype #microsoft #microsoftaccount #messages #contacts #synceddata #protection #clouds #conversationhistories
iOS Forensic Toolkit 5.21 extracts keychain from locked iOS devices

Elcomsoft iOS Forensic Toolkit 5.21 is updated to support the extraction of iOS keychain from locked and disabled devices. Before-first-unlock (BFU) extraction is available on select Apple devices via the checkra1n jailbreak.

👉 https://www.elcomsoft.com/news/730.html

#iphone #iOS #keychain #checkra1n #dataextraction #mobileforensics #encryption #apple #locked #passwords
BFU Extraction: Forensic Analysis of Locked and Disabled iPhones

We have recently updated Elcomsoft iOS Forensic Toolkit, adding the ability to acquire the file system from a wide range of iOS devices. The supported devices include models ranging from the iPhone 5s through the iPhone X regardless of the iOS version; more on that in iOS Device Acquisition with checkra1n Jailbreak. In today’s update, we’ve added the ability to extract select #keychain records in the BFU (Before First Unlock) mode. We have a few other changes and some tips on extracting locked and disabled devices.

BFU Forensics

The BFU stands for “Before First Unlock”. BFU devices are those that have been powered off or rebooted and have never been subsequently unlocked, not even once, by entering the correct screen lock passcode.

In Apple’s world, the content of the iPhone remains securely encrypted until the moment...

👉 https://blog.elcomsoft.com/2019/12/bfu-extraction-forensic-analysis-of-locked-and-disabled-iphones/

#checkra1n
Challenges in Computer and Mobile Forensics: What to Expect in 2020

The past two years introduced a number of challenges forensic experts have never faced before. In 2018 Apple made it more difficult for the police to safely transport a seized iPhone to the lab by locking the USB port with USB restricted mode, making data preservation a challenge.

On desktop and especially laptop computers, the widespread use of SSD drives made it impossible to access deleted data due to trim and garbage collection mechanisms. The users’ vastly increased reliance on cloud services and mass migration off the forensically transparent SMS platform towards the use of end-to-end encrypted messaging apps made communications more difficult to intercept and analyze.

Sheer amounts of data are greater than ever... Does hi-tech forensic stand a chance with more data, more apps, more devices and increasingly strong encryption?

https://blog.elcomsoft.com/2019/12/challenges-in-computer-and-mobile-forensics-what-to-expect-in-2020/
Our Developments and Achievements in 2019

For us, this year has been extremely replete with all sorts of developments in desktop, mobile and cloud forensics. We are proud with our achievements and want to share with you. Let’s have a quick look at what we’ve achieved in the year 2019.

👉 https://blog.elcomsoft.com/2019/12/our-developments-and-achievements-in-2019/

#ios #software #mobileforensics #cloudsecurity #google #iphone #skype #whatsapp #signal #screentime #applehealth #dataextraction #passwords
Attached Storage Forensics: Security Analysis of Thecus NAS

Thecus has been manufacturing NAS devices for more than 15 years. The company develops an in-house Linux-based NAS OS, the ThecusOS. At this time, the most current version of the OS is ThecusOS 7. Thecus advertises secure data encryption in most of its NAS devices. The company’s volume-based encryption tool allows users to fully encrypt their entire RAID volume, defending essential data in instances of theft of the physical device. We found Thecus’ implementation of encryption somewhat unique. In this research, we’ll verify the manufacturer’s claims and check just how secure is Thecus’ implementation of 256-bit AES encryption.

by Oleg Afonin

👉🏻 https://blog.elcomsoft.com/2020/01/attached-storage-forensics-security-analysis-of-thecus-nas/

#ThecusOS #Thecus #NAS #Encryption #Forensics
Attached Storage Forensics: Security Analysis of TerraMaster NAS

TerraMaster is a relatively new company specializing in network attached storage and direct attached storage solutions. The majority of TerraMaster NAS solutions are ARM64 and Intel-based boxes aimed at the home and SOHO users. TerraMaster’s OS (TOS) is based on Linux. At this time, TOS 4.1 is the current version of the OS.
TerraMaster advertises secure AES encryption with unspecified key length through the entire range of its current NAS devices. This time around, we’re dealing with folder-based encryption that runs on top of the open-source encrypting file system eCryptfs. TerraMaster’s implementation of data encryption is extremely simplistic and lacks any sort of management for either the encryption key or the encrypted data.

by Oleg Afonin

👉 https://blog.elcomsoft.com/2020/01/attached-storage-forensics-security-analysis-of-terramaster-nas/

#TerraMaster #NAS #Encryption #Forensics #AES
🔥 The True Meaning of iOS Recovery, DFU and SOS Modes for Mobile Forensics

What is DFU, and how is it different from the recovery mode? How do you switch the device to recovery, DFU or SOS mode, what can you do while in these modes and what do they mean in the context of digital forensics? Can you use DFU to jailbreak the device and perform the extraction if you don’t know the passcode? Read along to find out.

by Oleg Afonin

👉 https://blog.elcomsoft.com/2020/01/ios-recovery-dfu-and-sos-modes-forensics/

#iphone #iOS #DFU #DFUmode #SOSmode #recoverymode #mobileforensics #apple #locked #iPadOS #dataextraction
Elcomsoft Cloud Explorer 2.25 fixes Google Account authentication for some accounts

Elcomsoft Cloud Explorer 2.25 is a maintenance release with minor bug fixes and a major change under the hood. The fix resolves authentication issues on some Google accounts with specific two-factor authentication settings. The brand-new authentication algorithm we have under the hood is significantly more robust than the one it replaces.

👉 https://www.elcomsoft.com/news/731.html

#Cloud #GoogleAccount #2FA #authentication
Apple vs. Law Enforcement: Cloud Forensics

Тoday’s smartphones collect overwhelming amounts of data about the user’s daily activities, like users’ location and number of steps they walked, pictures and videos they take and every message they send or receive. Let's see the types of data that Apple does and does not deliver when served with a government request or while processing the user’s privacy request.

👉 https://blog.elcomsoft.com/2020/01/apple-vs-law-enforcement-cloud-forensics/

By Oleg Afonin

#dfir #mobileforensics #iossecurity #icloud #apple #iphone #dataextraction #cloudsecurity #smartphone #data #privacy
Introduction to BitLocker: Protecting Your System Disk

BitLocker is Microsoft’s implementation of full-disk encryption that is built into many versions of Windows. At the same time, BitLocker encryption is not available by default on desktops if you are using the Home edition of Windows 10. Activating BitLocker on your system disk can be tricky and may not work right away even if your Windows edition supports it. In this article, we are offering an introduction to BitLocker encryption. We’ll detail the types of threats BitLocker can effectively protect your data against, and the type of threats against which BitLocker is useless. Finally, we’ll describe how to activate BitLocker on systems that don’t meet Microsoft’s hardware requirements, and evaluate whether it’s worth it or not security-wise.

👉 https://blog.elcomsoft.com/2020/01/introduction-to-bitlocker-protecting-your-system-disk/

By Oleg Afonin

#BitLocker #systemdisk #windows10 #passwords #encryption #windows #hiddendisks #crypto #encryptionkey
A Comprehensive Guide on Securing Your System, Archives and Documents

How can you make your system and documents secure? Today, 256-bit AES encryption is offered by everyone and their dog. However, AES encryption does not mean much when it comes to the real security of your data. Implementing encryption at the right time and in the right spot is no less important than choosing strong encryption credentials and managing the encryption keys.
If you are a Windows user, it all comes down to choosing the optimal data protection strategy for your particular usage scenario; protecting your storage media and the data you keep on them.

👉 https://blog.elcomsoft.com/2020/01/a-comprehensive-guide-on-securing-your-system-archives-and-documents/

By Oleg Afonin


#systemdisk #windows10 #passwords #encryption #windows #AES #crypto #encryptionkey #archive #disk
The Worst Mistakes in iOS Forensics

What can possibly go wrong with that iPhone? I’ll have a look (oh, it’s locked!), then switch it off, eject the SIM card and pass it on to the expert. Well, you’ve just made three of the five most common mistakes making subsequent unlock and extraction attempts significantly more difficult. Learn about the most common mistakes and their consequences.

👉 https://blog.elcomsoft.com/2020/01/the-worst-mistakes-in-ios-forensics/

by Vladimir Katalov

#mistakes #mobileforensics #ios #apple #forensics #iossecurity #icloud #iphone #dataextraction #cloudsecurity #smartphone
Apple vs Law Enforcement: Cloudy Times

Apple is using point-to-point encryption to protect certain types of data. However, it has not always been that way. Apple security model changed year after year. This article reviews the timeline of Apple security changes over time. We’ll list the security measures and discuss whether the real purpose of these changes were the customers’ security and privacy, or throwing a monkey wrench into the work of the law enforcement.

We will also try to understand where iCloud security stands today, and how safe your data is against hackers and the law enforcement.

Are you a forensic professional? I think you’ll find this article handy.

👉 https://blog.elcomsoft.com/2020/02/apple-vs-law-enforcement-cloudy-times/

by Vladimir Katalov

#dfir #mobileforensics #iossecurity #icloud #apple #iphone #dataextraction #cloudsecurity #smartphone