iOS Forensic Toolkit 6.20: filling the gaps
Elcomsoft iOS Forensic Toolkit 6.20 fills the gaps for jailbreak-free extraction of previously unsupported versions of iOS. The new release expands the availability of the extraction agent all the way back to the original iOS 10.0, while adding compatibility for previously unsupported versions of iOS 12 on the iPhone 5s and 6.
👉 https://www.elcomsoft.com/news/751.html
📝 Get Release Notes in PDF
#eift #mobileforensics #dfir #keychain #filesystem #iphone #dataextraction #ios
Elcomsoft iOS Forensic Toolkit 6.20 fills the gaps for jailbreak-free extraction of previously unsupported versions of iOS. The new release expands the availability of the extraction agent all the way back to the original iOS 10.0, while adding compatibility for previously unsupported versions of iOS 12 on the iPhone 5s and 6.
👉 https://www.elcomsoft.com/news/751.html
📝 Get Release Notes in PDF
#eift #mobileforensics #dfir #keychain #filesystem #iphone #dataextraction #ios
iOS Extraction Without a Jailbreak: Full iOS 10 Support
One is hardly likely to encounter an iOS 10 in the wild, however forensic labs still process devices running the older version of the OS. In today's update of Elcomsoft iOS Forensic Toolkit, we’ve brought support for jailbreak-free extraction back to the roots, adding support for the oldest version of iOS capable of running on the iPhone 7 generation of devices.
Let’s see what it takes to extract an older iPhone without a jailbreak!
Keep reading: https://blog.elcomsoft.com/2020/06/ios-extraction-without-a-jailbreak-full-ios-10-support/
#ios10 #iphone7 #dfir #mobileforensics #datasecurity #infosec #extractionagent
One is hardly likely to encounter an iOS 10 in the wild, however forensic labs still process devices running the older version of the OS. In today's update of Elcomsoft iOS Forensic Toolkit, we’ve brought support for jailbreak-free extraction back to the roots, adding support for the oldest version of iOS capable of running on the iPhone 7 generation of devices.
Let’s see what it takes to extract an older iPhone without a jailbreak!
Keep reading: https://blog.elcomsoft.com/2020/06/ios-extraction-without-a-jailbreak-full-ios-10-support/
#ios10 #iphone7 #dfir #mobileforensics #datasecurity #infosec #extractionagent
iOS, watchOS and tvOS Acquisition Methods Compared: Compatibility Notes
How can you obtain the highest amount of data from an iPhone, iPad, Apple TV or Apple Watch? This is not as simple as it may seem. Multiple overlapping extraction methods exist, and some of them are limited to specific versions of the OS. Let’s go through them and summarize their availability and benefits.
👉 https://blog.elcomsoft.com/2020/06/ios-watchos-and-tvos-acquisition-methods-compared-compatibility-notes/
#iOS #tvOS #watchOS #mobilesecurity #dfir #mobileforensics #cloud #keychain #dataaccess
How can you obtain the highest amount of data from an iPhone, iPad, Apple TV or Apple Watch? This is not as simple as it may seem. Multiple overlapping extraction methods exist, and some of them are limited to specific versions of the OS. Let’s go through them and summarize their availability and benefits.
👉 https://blog.elcomsoft.com/2020/06/ios-watchos-and-tvos-acquisition-methods-compared-compatibility-notes/
#iOS #tvOS #watchOS #mobilesecurity #dfir #mobileforensics #cloud #keychain #dataaccess
The Mysterious Apple DCSD Cable Demystified
A lot of people have asked me over the past couple of months – “What’s that cable on your desk, James?”. Today I’ll tell you all about it. Every accessory that connects to your iPhone via lightning is ‘flashed’ with an Accessory ID. The Accessory ID essentially identifies the device connected to the iPhone as a specific type. For example, a Lightning-To-Ethernet adapter will identify itself with it’s assigned Accessory ID so the iPhone knows how to treat the device and interact with it. It’s sort of like directing the iPhone to use a specific driver to interact with said device.
👉 https://blog.elcomsoft.com/2020/06/the-mysterious-apple-dcsd-cable-demystified/
#ios #iphone #mobileforensics #itsecurity #dcsd #cybersecurity
A lot of people have asked me over the past couple of months – “What’s that cable on your desk, James?”. Today I’ll tell you all about it. Every accessory that connects to your iPhone via lightning is ‘flashed’ with an Accessory ID. The Accessory ID essentially identifies the device connected to the iPhone as a specific type. For example, a Lightning-To-Ethernet adapter will identify itself with it’s assigned Accessory ID so the iPhone knows how to treat the device and interact with it. It’s sort of like directing the iPhone to use a specific driver to interact with said device.
👉 https://blog.elcomsoft.com/2020/06/the-mysterious-apple-dcsd-cable-demystified/
#ios #iphone #mobileforensics #itsecurity #dcsd #cybersecurity
Unlocking BitLocker Volumes by Booting from a USB Drive
BitLocker is Windows default solution for encrypting disk volumes. A large number of organizations protect startup disks with BitLocker encryption. While adding the necessary layer of security, BitLocker also has the potential of locking administrative access to the encrypted volumes if the original Windows logon password is lost. We are offering a straightforward solution for reinstating access to BitLocker-protected Windows systems with the help of a bootable USB drive.
👉 https://blog.elcomsoft.com/2020/06/unlocking-bitlocker-volumes-by-booting-from-a-usb-drive/
#bitlocker #password #recoverykey #usbkey #boot #encryption #fde #cybersecurity #itsecurity #tpm
BitLocker is Windows default solution for encrypting disk volumes. A large number of organizations protect startup disks with BitLocker encryption. While adding the necessary layer of security, BitLocker also has the potential of locking administrative access to the encrypted volumes if the original Windows logon password is lost. We are offering a straightforward solution for reinstating access to BitLocker-protected Windows systems with the help of a bootable USB drive.
👉 https://blog.elcomsoft.com/2020/06/unlocking-bitlocker-volumes-by-booting-from-a-usb-drive/
#bitlocker #password #recoverykey #usbkey #boot #encryption #fde #cybersecurity #itsecurity #tpm
Elcomsoft System Recovery adds BitLocker support
We updated Elcomsoft System Recovery, a Windows PE-based tool to recover or reset passwords to local Windows accounts and Microsoft accounts in all versions of Windows. The tool adds native support for BitLocker volumes, enabling users to mount BitLocker-encrypted partitions using one of the three supported disk protectors.
📝 Release Notes
👉 https://www.elcomsoft.com/news/752.html
#bitlocker #password #recoverykey #usbkey #boot #encryption #fde #cybersecurity #itsecurity #computerforensics
We updated Elcomsoft System Recovery, a Windows PE-based tool to recover or reset passwords to local Windows accounts and Microsoft accounts in all versions of Windows. The tool adds native support for BitLocker volumes, enabling users to mount BitLocker-encrypted partitions using one of the three supported disk protectors.
📝 Release Notes
👉 https://www.elcomsoft.com/news/752.html
#bitlocker #password #recoverykey #usbkey #boot #encryption #fde #cybersecurity #itsecurity #computerforensics
Extracting and Using Stored Passwords from Web Browsers
Breaking passwords becomes more difficult with every other update of popular software. Microsoft routinely bumps the number of hash iterations to make Office document protection coherent with current hardware. Apple uses excessive protection of iTunes backups since iOS 10.1, making brute force attacks a thing of the past. VeraCrypt and BitLocker were secure from the get go. However, everything is not lost if you consider human nature.
👉 https://blog.elcomsoft.com/2020/07/extracting-and-using-stored-passwords-from-web-browsers/
#browsers #password #passwordrecovery #cybersecurity #itsecurity #digitalforensics
Breaking passwords becomes more difficult with every other update of popular software. Microsoft routinely bumps the number of hash iterations to make Office document protection coherent with current hardware. Apple uses excessive protection of iTunes backups since iOS 10.1, making brute force attacks a thing of the past. VeraCrypt and BitLocker were secure from the get go. However, everything is not lost if you consider human nature.
👉 https://blog.elcomsoft.com/2020/07/extracting-and-using-stored-passwords-from-web-browsers/
#browsers #password #passwordrecovery #cybersecurity #itsecurity #digitalforensics
Extracting Passwords from Tencent QQ Browser
QQ Browser is one of China’s most popular Web browsers. With some 10% of the Chinese market and the numerous Chinese users abroad, QQ Browser is used by the millions. Like many of its competitors, QQ Browser offers the ability to store website passwords. The passwords are securely encrypted, and can be only accessed once the user signs into their Windows account. Learn what you need to do to extract passwords from Tencent QQ Browser.
👉 https://blog.elcomsoft.com/2020/07/extracting-passwords-from-tencent-qq-browser/
#browsers #password #passwordrecovery #tencent #qqbrowser #cybersecurity #itsecurity #digitalforensics
QQ Browser is one of China’s most popular Web browsers. With some 10% of the Chinese market and the numerous Chinese users abroad, QQ Browser is used by the millions. Like many of its competitors, QQ Browser offers the ability to store website passwords. The passwords are securely encrypted, and can be only accessed once the user signs into their Windows account. Learn what you need to do to extract passwords from Tencent QQ Browser.
👉 https://blog.elcomsoft.com/2020/07/extracting-passwords-from-tencent-qq-browser/
#browsers #password #passwordrecovery #tencent #qqbrowser #cybersecurity #itsecurity #digitalforensics
Elcomsoft Internet Password Breaker 3.20 extracts Yandex Browser, Tencent QQ and UC Browser passwords
Elcomsoft Internet Password Breaker 3.20 adds the ability to extract stored passwords from the newest versions of Yandex Browser, Tencent QQ and UC Browser. Yandex Browser is Russia’s second most popular desktop Web browser based on usage with some 17.2 per cent of the market, while QQ Browser in China floats around the 10% mark.
👉 https://www.elcomsoft.com/news/753.html
#browsers #password #passwordrecovery #tencent #qqbrowser #ucbrowser #cybersecurity #itsecurity #digitalforensics
Elcomsoft Internet Password Breaker 3.20 adds the ability to extract stored passwords from the newest versions of Yandex Browser, Tencent QQ and UC Browser. Yandex Browser is Russia’s second most popular desktop Web browser based on usage with some 17.2 per cent of the market, while QQ Browser in China floats around the 10% mark.
👉 https://www.elcomsoft.com/news/753.html
#browsers #password #passwordrecovery #tencent #qqbrowser #ucbrowser #cybersecurity #itsecurity #digitalforensics
Advanced Office Password Recovery 6.60 adds Hancom Office, iWork 2020 v10 support
Advanced Office Password Recovery (AOPR) adds support for the latest edition of Hancom Office 2020, now supporting Hancom documents saved in the new format. Version 6.60 offers full compatibility with Hancom Office Word 2020 documents and Cell 2020 workbooks, as well as the documents produced by iWork 2020.
👉 https://www.elcomsoft.com/news/754.html
#password #hancom #office #iwork #passwordprotection #cybersecurity #itsecurity #infosec
Advanced Office Password Recovery (AOPR) adds support for the latest edition of Hancom Office 2020, now supporting Hancom documents saved in the new format. Version 6.60 offers full compatibility with Hancom Office Word 2020 documents and Cell 2020 workbooks, as well as the documents produced by iWork 2020.
👉 https://www.elcomsoft.com/news/754.html
#password #hancom #office #iwork #passwordprotection #cybersecurity #itsecurity #infosec
checkra1n Installation Tips & Tricks
Having trouble installing the checkra1n jailbreak? If you do it right, you achieve a nearly 100% success rate. We have collected the most important information on how to install and troubleshoot the checkra1n jailbreak. By following these advises, you will be able to jailbreak like a pro, whether you just want to research your own device or perform the file system and keychain acquisition.
👉 https://blog.elcomsoft.com/2020/07/checkra1n-installation-tips-tricks/
by Vladimir Katalov
#jb #checkra1n #jailbreak #iphone #ios #mobilesecurity #dfir #mobileforensics
Having trouble installing the checkra1n jailbreak? If you do it right, you achieve a nearly 100% success rate. We have collected the most important information on how to install and troubleshoot the checkra1n jailbreak. By following these advises, you will be able to jailbreak like a pro, whether you just want to research your own device or perform the file system and keychain acquisition.
👉 https://blog.elcomsoft.com/2020/07/checkra1n-installation-tips-tricks/
by Vladimir Katalov
#jb #checkra1n #jailbreak #iphone #ios #mobilesecurity #dfir #mobileforensics
Today is a memorable day for Elcomsoft! 19 years ago Elcomsoft employee, Dmitry Sklyarov, was put to jail for his research...
Read more in our retrospective article about those days!
Defending Americans’ Right to Decrypt
19 years ago, on July 16, 2001, the FBI arrested Dmitry Sklyarov, almost immediately after his speech at the DEF CON hacker conference, on a number of charges by Adobe. Dmitry was accused of many things, from software trafficking to conspiring with Elcomsoft and “third parties”, who put up the software for sale that could bypass technological protection on copyrighted material. Dmitry’s career at Elcomsoft began with a project on gaining access to protected Access databases. Soon, Dmitry got an idea about the security of PDF, and so he started working on it. From this idea the never-to-be-forgotten Advanced eBook Processor was born, because of which Dmitry was arrested in 2001 at DEF CON in Las Vegas, NV.
👉 https://blog.elcomsoft.com/2020/07/defending-americans-right-to-decrypt/
Read more in our retrospective article about those days!
Defending Americans’ Right to Decrypt
19 years ago, on July 16, 2001, the FBI arrested Dmitry Sklyarov, almost immediately after his speech at the DEF CON hacker conference, on a number of charges by Adobe. Dmitry was accused of many things, from software trafficking to conspiring with Elcomsoft and “third parties”, who put up the software for sale that could bypass technological protection on copyrighted material. Dmitry’s career at Elcomsoft began with a project on gaining access to protected Access databases. Soon, Dmitry got an idea about the security of PDF, and so he started working on it. From this idea the never-to-be-forgotten Advanced eBook Processor was born, because of which Dmitry was arrested in 2001 at DEF CON in Las Vegas, NV.
👉 https://blog.elcomsoft.com/2020/07/defending-americans-right-to-decrypt/
checkra1n, USB Restrictions and Breaking Into Locked iPhones
The checkra1n jailbreak is fantastic. Not only does it work with the latest versions of iOS the other jailbreaks aren’t even available for, but it also allows performing partial data extraction from disabled and locked iPhones even if the passcode is not known. Still, you can encounter some problems if the USB restricted mode has been activated on the device. The latest build of chechra1n is to the rescue.
👉 https://blog.elcomsoft.com/2020/07/checkra1n-usb-restrictions-and-breaking-into-locked-iphones/
The checkra1n jailbreak is fantastic. Not only does it work with the latest versions of iOS the other jailbreaks aren’t even available for, but it also allows performing partial data extraction from disabled and locked iPhones even if the passcode is not known. Still, you can encounter some problems if the USB restricted mode has been activated on the device. The latest build of chechra1n is to the rescue.
👉 https://blog.elcomsoft.com/2020/07/checkra1n-usb-restrictions-and-breaking-into-locked-iphones/
Elcomsoft Phone Breaker 9.61 adds iOS 14 support, fixes iCloud backups
Elcomsoft Phone Breaker 9.61 adds support for cloud backups created with devices running the beta version of iOS 14. In addition, the update fixes access to iCloud backups created in iOS 12 and 13. Updating is strongly recommended for everyone requiring access to iCloud backups.
👉https://www.elcomsoft.com/news/755.html
#ios14 #icloud #iphone #mobilesecurity #dfir #cloudsecurity #dataextraction #forensics
Elcomsoft Phone Breaker 9.61 adds support for cloud backups created with devices running the beta version of iOS 14. In addition, the update fixes access to iCloud backups created in iOS 12 and 13. Updating is strongly recommended for everyone requiring access to iCloud backups.
👉https://www.elcomsoft.com/news/755.html
#ios14 #icloud #iphone #mobilesecurity #dfir #cloudsecurity #dataextraction #forensics
Downloading iOS 13 and iOS 14 iCloud Backups
The long-awaited update for Elcomsoft Phone Breaker has arrived. The update brought back the ability to download iCloud backups, which was sorely broken since recent server-side changes introduced by Apple. We are also excited to become the first forensic company to offer support for iCloud backups saved by iOS 14 beta devices, all while supporting the full spectrum of two-factor authentication methods. We are proud to provide the most comprehensive forensic support of Apple iCloud with unmatched performance, accelerating forensic investigations and providing access to critical evidence stored in the cloud.
👉https://blog.elcomsoft.com/2020/07/downloading-ios-13-and-ios-14-icloud-backups/
#iOS14 #iOS13 #iphone #smartphone #icloud #dataetraction #cloudsecurity #mobileforensics
The long-awaited update for Elcomsoft Phone Breaker has arrived. The update brought back the ability to download iCloud backups, which was sorely broken since recent server-side changes introduced by Apple. We are also excited to become the first forensic company to offer support for iCloud backups saved by iOS 14 beta devices, all while supporting the full spectrum of two-factor authentication methods. We are proud to provide the most comprehensive forensic support of Apple iCloud with unmatched performance, accelerating forensic investigations and providing access to critical evidence stored in the cloud.
👉https://blog.elcomsoft.com/2020/07/downloading-ios-13-and-ios-14-icloud-backups/
#iOS14 #iOS13 #iphone #smartphone #icloud #dataetraction #cloudsecurity #mobileforensics
Elcomsoft Encrypted Disk Hunter discovers encrypted disk volumes on live systems
Elcomsoft expands its range of forensic products with a new portable tool. Elcomsoft Encrypted Disk Hunter is a free command-line tool to help experts quickly discover the presence of encrypted volumes when performing live system analysis. TrueCrypt/VeraCrypt, BitLocker, PGP WDE, FileVault2, and LUKS are supported.
👉 https://www.elcomsoft.com/news/757.html
#encrypteddisk #cryptocontainer #truecrypt #veracrypt #pgp #filevault2 #luks #bitlocker #windows #macos #linux
Elcomsoft expands its range of forensic products with a new portable tool. Elcomsoft Encrypted Disk Hunter is a free command-line tool to help experts quickly discover the presence of encrypted volumes when performing live system analysis. TrueCrypt/VeraCrypt, BitLocker, PGP WDE, FileVault2, and LUKS are supported.
👉 https://www.elcomsoft.com/news/757.html
#encrypteddisk #cryptocontainer #truecrypt #veracrypt #pgp #filevault2 #luks #bitlocker #windows #macos #linux
Live System Analysis: Discovering Encrypted Disk Volumes
The wide spread of full-disk encryption makes live system analysis during incident response a challenge, but also an opportunity. A timely detection of full-disk encryption or a mounted crypto container allows experts take extra steps to secure access to encrypted evidence before pulling the plug. What steps are required and how to tell if the system is using full-disk encryption? “We have a tool for that”.
👉 https://blog.elcomsoft.com/2020/07/live-system-analysis-discovering-encrypted-disk-volumes/
#fde #encrypteddisks #cryptocontainer #bitlocker #truecrypt #pgp #luks #filevault #forensictool
The wide spread of full-disk encryption makes live system analysis during incident response a challenge, but also an opportunity. A timely detection of full-disk encryption or a mounted crypto container allows experts take extra steps to secure access to encrypted evidence before pulling the plug. What steps are required and how to tell if the system is using full-disk encryption? “We have a tool for that”.
👉 https://blog.elcomsoft.com/2020/07/live-system-analysis-discovering-encrypted-disk-volumes/
#fde #encrypteddisks #cryptocontainer #bitlocker #truecrypt #pgp #luks #filevault #forensictool
The Four Ways to Deal with iPhone Backup Passwords
In this publication, we have collected the most important information about the things you can do with iPhone backup passwords under different circumstances, some software recommendations, and some other practical tips and tricks, in a brief and simple form.
👉 https://blog.elcomsoft.com/2020/07/4-ways-to-handle-iphone-backup-passwords/
#iphone #passwords #itunes #mobileforensics #mobilesecurity #passwordrecovery #passwordreset
In this publication, we have collected the most important information about the things you can do with iPhone backup passwords under different circumstances, some software recommendations, and some other practical tips and tricks, in a brief and simple form.
👉 https://blog.elcomsoft.com/2020/07/4-ways-to-handle-iphone-backup-passwords/
#iphone #passwords #itunes #mobileforensics #mobilesecurity #passwordrecovery #passwordreset
Extracting and Decrypting iOS Keychain: Physical, Logical and Cloud Options Explored
The keychain is one of the hallmarks of the Apple ecosystem. Containing a plethora of sensitive information, the keychain is one of the best guarded parts of the walled garden. At the same time, the keychain is relatively underexplored by the forensic community. The common knowledge has it that the keychain contains the users’ logins and passwords, and possibly some payment card information. The common knowledge is missing the point: the keychain contains literally thousands of records belonging to various apps and the system that are required to access lots of other sensitive information. Let’s talk about the keychain, its content and its protection, and the methods used to extract, decrypt and analyze the various bits and pieces.
👉 https://blog.elcomsoft.com/2020/08/extracting-and-decrypting-ios-keychain-physical-logical-and-cloud-options-explored/
#ios #iphone #mobilesecurity #dfir #passwords #itsecurity #keychain
The keychain is one of the hallmarks of the Apple ecosystem. Containing a plethora of sensitive information, the keychain is one of the best guarded parts of the walled garden. At the same time, the keychain is relatively underexplored by the forensic community. The common knowledge has it that the keychain contains the users’ logins and passwords, and possibly some payment card information. The common knowledge is missing the point: the keychain contains literally thousands of records belonging to various apps and the system that are required to access lots of other sensitive information. Let’s talk about the keychain, its content and its protection, and the methods used to extract, decrypt and analyze the various bits and pieces.
👉 https://blog.elcomsoft.com/2020/08/extracting-and-decrypting-ios-keychain-physical-logical-and-cloud-options-explored/
#ios #iphone #mobilesecurity #dfir #passwords #itsecurity #keychain
iOS Forensic Toolkit 6.30: jailbreak-free iOS 9 support, user data extraction
Elcomsoft iOS Forensic Toolkit 6.30 expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9. In addition, the new release can now extract user data only, speeding up the acquisition process by skipping the static system files.
👉 https://www.elcomsoft.com/news/758.html
📝 Release Notes (PDF)
#ios9 #iphone #dataextraction #mobileforensics #dfir #agent #jailbreakfree
Elcomsoft iOS Forensic Toolkit 6.30 expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9. In addition, the new release can now extract user data only, speeding up the acquisition process by skipping the static system files.
👉 https://www.elcomsoft.com/news/758.html
📝 Release Notes (PDF)
#ios9 #iphone #dataextraction #mobileforensics #dfir #agent #jailbreakfree
iOS Extraction Without a Jailbreak: Full iOS 9 Support, Simplified File System Extraction
We updated iOS Forensic Toolkit to bring two notable improvements. The first one is the new acquisition option for jailbreak-free extractions. The new extraction mode helps experts save time and disk space by pulling only the content of the user partition while leaving the static system partition behind. The second update expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9.
👉 https://blog.elcomsoft.com/2020/08/ios-extraction-without-a-jailbreak-full-ios-9-support-simplified-file-system-extraction/
#ios #iphone #mobileforensics #dfir #ios9 #filesystem #dataextraction #agent
We updated iOS Forensic Toolkit to bring two notable improvements. The first one is the new acquisition option for jailbreak-free extractions. The new extraction mode helps experts save time and disk space by pulling only the content of the user partition while leaving the static system partition behind. The second update expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9.
👉 https://blog.elcomsoft.com/2020/08/ios-extraction-without-a-jailbreak-full-ios-9-support-simplified-file-system-extraction/
#ios #iphone #mobileforensics #dfir #ios9 #filesystem #dataextraction #agent