Elcomsoft Encrypted Disk Hunter discovers encrypted disk volumes on live systems
Elcomsoft expands its range of forensic products with a new portable tool. Elcomsoft Encrypted Disk Hunter is a free command-line tool to help experts quickly discover the presence of encrypted volumes when performing live system analysis. TrueCrypt/VeraCrypt, BitLocker, PGP WDE, FileVault2, and LUKS are supported.
👉 https://www.elcomsoft.com/news/757.html
#encrypteddisk #cryptocontainer #truecrypt #veracrypt #pgp #filevault2 #luks #bitlocker #windows #macos #linux
Elcomsoft expands its range of forensic products with a new portable tool. Elcomsoft Encrypted Disk Hunter is a free command-line tool to help experts quickly discover the presence of encrypted volumes when performing live system analysis. TrueCrypt/VeraCrypt, BitLocker, PGP WDE, FileVault2, and LUKS are supported.
👉 https://www.elcomsoft.com/news/757.html
#encrypteddisk #cryptocontainer #truecrypt #veracrypt #pgp #filevault2 #luks #bitlocker #windows #macos #linux
Live System Analysis: Discovering Encrypted Disk Volumes
The wide spread of full-disk encryption makes live system analysis during incident response a challenge, but also an opportunity. A timely detection of full-disk encryption or a mounted crypto container allows experts take extra steps to secure access to encrypted evidence before pulling the plug. What steps are required and how to tell if the system is using full-disk encryption? “We have a tool for that”.
👉 https://blog.elcomsoft.com/2020/07/live-system-analysis-discovering-encrypted-disk-volumes/
#fde #encrypteddisks #cryptocontainer #bitlocker #truecrypt #pgp #luks #filevault #forensictool
The wide spread of full-disk encryption makes live system analysis during incident response a challenge, but also an opportunity. A timely detection of full-disk encryption or a mounted crypto container allows experts take extra steps to secure access to encrypted evidence before pulling the plug. What steps are required and how to tell if the system is using full-disk encryption? “We have a tool for that”.
👉 https://blog.elcomsoft.com/2020/07/live-system-analysis-discovering-encrypted-disk-volumes/
#fde #encrypteddisks #cryptocontainer #bitlocker #truecrypt #pgp #luks #filevault #forensictool
The Four Ways to Deal with iPhone Backup Passwords
In this publication, we have collected the most important information about the things you can do with iPhone backup passwords under different circumstances, some software recommendations, and some other practical tips and tricks, in a brief and simple form.
👉 https://blog.elcomsoft.com/2020/07/4-ways-to-handle-iphone-backup-passwords/
#iphone #passwords #itunes #mobileforensics #mobilesecurity #passwordrecovery #passwordreset
In this publication, we have collected the most important information about the things you can do with iPhone backup passwords under different circumstances, some software recommendations, and some other practical tips and tricks, in a brief and simple form.
👉 https://blog.elcomsoft.com/2020/07/4-ways-to-handle-iphone-backup-passwords/
#iphone #passwords #itunes #mobileforensics #mobilesecurity #passwordrecovery #passwordreset
Extracting and Decrypting iOS Keychain: Physical, Logical and Cloud Options Explored
The keychain is one of the hallmarks of the Apple ecosystem. Containing a plethora of sensitive information, the keychain is one of the best guarded parts of the walled garden. At the same time, the keychain is relatively underexplored by the forensic community. The common knowledge has it that the keychain contains the users’ logins and passwords, and possibly some payment card information. The common knowledge is missing the point: the keychain contains literally thousands of records belonging to various apps and the system that are required to access lots of other sensitive information. Let’s talk about the keychain, its content and its protection, and the methods used to extract, decrypt and analyze the various bits and pieces.
👉 https://blog.elcomsoft.com/2020/08/extracting-and-decrypting-ios-keychain-physical-logical-and-cloud-options-explored/
#ios #iphone #mobilesecurity #dfir #passwords #itsecurity #keychain
The keychain is one of the hallmarks of the Apple ecosystem. Containing a plethora of sensitive information, the keychain is one of the best guarded parts of the walled garden. At the same time, the keychain is relatively underexplored by the forensic community. The common knowledge has it that the keychain contains the users’ logins and passwords, and possibly some payment card information. The common knowledge is missing the point: the keychain contains literally thousands of records belonging to various apps and the system that are required to access lots of other sensitive information. Let’s talk about the keychain, its content and its protection, and the methods used to extract, decrypt and analyze the various bits and pieces.
👉 https://blog.elcomsoft.com/2020/08/extracting-and-decrypting-ios-keychain-physical-logical-and-cloud-options-explored/
#ios #iphone #mobilesecurity #dfir #passwords #itsecurity #keychain
iOS Forensic Toolkit 6.30: jailbreak-free iOS 9 support, user data extraction
Elcomsoft iOS Forensic Toolkit 6.30 expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9. In addition, the new release can now extract user data only, speeding up the acquisition process by skipping the static system files.
👉 https://www.elcomsoft.com/news/758.html
📝 Release Notes (PDF)
#ios9 #iphone #dataextraction #mobileforensics #dfir #agent #jailbreakfree
Elcomsoft iOS Forensic Toolkit 6.30 expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9. In addition, the new release can now extract user data only, speeding up the acquisition process by skipping the static system files.
👉 https://www.elcomsoft.com/news/758.html
📝 Release Notes (PDF)
#ios9 #iphone #dataextraction #mobileforensics #dfir #agent #jailbreakfree
iOS Extraction Without a Jailbreak: Full iOS 9 Support, Simplified File System Extraction
We updated iOS Forensic Toolkit to bring two notable improvements. The first one is the new acquisition option for jailbreak-free extractions. The new extraction mode helps experts save time and disk space by pulling only the content of the user partition while leaving the static system partition behind. The second update expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9.
👉 https://blog.elcomsoft.com/2020/08/ios-extraction-without-a-jailbreak-full-ios-9-support-simplified-file-system-extraction/
#ios #iphone #mobileforensics #dfir #ios9 #filesystem #dataextraction #agent
We updated iOS Forensic Toolkit to bring two notable improvements. The first one is the new acquisition option for jailbreak-free extractions. The new extraction mode helps experts save time and disk space by pulling only the content of the user partition while leaving the static system partition behind. The second update expands jailbreak-free extraction all the way back to iOS 9, now supporting all 64-bit devices running all builds of iOS 9.
👉 https://blog.elcomsoft.com/2020/08/ios-extraction-without-a-jailbreak-full-ios-9-support-simplified-file-system-extraction/
#ios #iphone #mobileforensics #dfir #ios9 #filesystem #dataextraction #agent
Elcomsoft Internet Password Breaker 3.30 extracts passwords from Tor and 360 Safe browsers
Elcomsoft Internet Password Breaker 3.30 adds the ability to extract stored passwords from Tor and 360 Safe Browser. 360 Safe Browser is among the top 5 most popular Web browsers in China, while Tor is designed to make Web browsing truly anonymous.
👉 https://www.elcomsoft.com/news/759.html
#internet #webbrowser #tor #360safebrowser #passwords #passwordbreaker
Elcomsoft Internet Password Breaker 3.30 adds the ability to extract stored passwords from Tor and 360 Safe Browser. 360 Safe Browser is among the top 5 most popular Web browsers in China, while Tor is designed to make Web browsing truly anonymous.
👉 https://www.elcomsoft.com/news/759.html
#internet #webbrowser #tor #360safebrowser #passwords #passwordbreaker
Extracting Passwords from Qihoo 360 Safe Browser and Tor Browser
Tor Browser is a well-known tool for browsing the Web while renaming anonymous, while Qihoo 360 Safe Browser is one of China’s most popular desktop Web browsers. According to some sources, it might be the second most-popular desktop Web browser in China. Like many other Chromium-based browsers, 360 Safe Browser offers the ability to save and securely store website passwords, but the implementation is unexpectedly different from most other browsers. An update to Elcomsoft Internet Password Breaker enables the extraction of Qihoo 360 Safe Browser and Tor Browser passwords. Does the “360 Safe” moniker stand the trial, and is Tor really anonymous? Read along to find out!
👉 https://blog.elcomsoft.com/2020/08/extracting-passwords-from-qihoo-360-safe-browser-and-tor/
#tor #360safebrowser #browser #passwords #savedpasswords
Tor Browser is a well-known tool for browsing the Web while renaming anonymous, while Qihoo 360 Safe Browser is one of China’s most popular desktop Web browsers. According to some sources, it might be the second most-popular desktop Web browser in China. Like many other Chromium-based browsers, 360 Safe Browser offers the ability to save and securely store website passwords, but the implementation is unexpectedly different from most other browsers. An update to Elcomsoft Internet Password Breaker enables the extraction of Qihoo 360 Safe Browser and Tor Browser passwords. Does the “360 Safe” moniker stand the trial, and is Tor really anonymous? Read along to find out!
👉 https://blog.elcomsoft.com/2020/08/extracting-passwords-from-qihoo-360-safe-browser-and-tor/
#tor #360safebrowser #browser #passwords #savedpasswords
Elcomsoft adds LUKS encryption support
We updated Elcomsoft Forensic Disk Decryptor, Elcomsoft System Recovery and Elcomsoft Distributed Password Recovery with support for Linux partitions protected with LUKS encryption. The tools work together to identify encrypted partitions, extract encryption metadata and launch a full-scale, GPU-accelerated attack on the encryption password.
📝 Release Notes (PDF)
👉 https://www.elcomsoft.com/news/760.html
#LUKS #Linux #fde #diskencryption #cryptocontainer #forensictools #passwords #passwordrecovery
We updated Elcomsoft Forensic Disk Decryptor, Elcomsoft System Recovery and Elcomsoft Distributed Password Recovery with support for Linux partitions protected with LUKS encryption. The tools work together to identify encrypted partitions, extract encryption metadata and launch a full-scale, GPU-accelerated attack on the encryption password.
📝 Release Notes (PDF)
👉 https://www.elcomsoft.com/news/760.html
#LUKS #Linux #fde #diskencryption #cryptocontainer #forensictools #passwords #passwordrecovery
Breaking LUKS Encryption
LUKS encryption is widely used in various Linux distributions to protect disks and create encrypted containers. Being a platform-independent, open-source specification, LUKS can be viewed as an exemplary implementation of disk encryption. Offering the choice of multiple encryption algorithms, several modes of encryption and several hash functions to choose from, LUKS is one of the tougher disk encryption systems to break.
Learn how to deal with LUKS encryption in Windows and how to break in with distributed password attacks:
👉 https://blog.elcomsoft.com/2020/08/breaking-luks-encryption/
#LUKS #Linux #fde #passwords #passwordrecovery #encryption
LUKS encryption is widely used in various Linux distributions to protect disks and create encrypted containers. Being a platform-independent, open-source specification, LUKS can be viewed as an exemplary implementation of disk encryption. Offering the choice of multiple encryption algorithms, several modes of encryption and several hash functions to choose from, LUKS is one of the tougher disk encryption systems to break.
Learn how to deal with LUKS encryption in Windows and how to break in with distributed password attacks:
👉 https://blog.elcomsoft.com/2020/08/breaking-luks-encryption/
#LUKS #Linux #fde #passwords #passwordrecovery #encryption
iOS Forensic Toolkit 6.40: iPhone 5 and 5c passcode unlock
Elcomsoft iOS Forensic Toolkit 6.40 adds major functionality, enabling passcode unlock for iPhone 5 and iPhone 5c devices protected with an unknown screen lock passcode. The unlock method is decidedly software-only, no soldering, disassembly or extra hardware required. All you need is iOS Forensic Toolkit, a Mac computer, and a USB-A to Lightning cable. In this guide, we demonstrate how to unlock and image the iPhone 5 and 5c devices.
👉 https://www.elcomsoft.com/news/761.html
📝 Release Notes (PDF)
#ios #iphone #mobileforensics #dfir #iphone5 #passcode #pin #screenlock #dataextraction #eift #unlock #passcodecracking
Elcomsoft iOS Forensic Toolkit 6.40 adds major functionality, enabling passcode unlock for iPhone 5 and iPhone 5c devices protected with an unknown screen lock passcode. The unlock method is decidedly software-only, no soldering, disassembly or extra hardware required. All you need is iOS Forensic Toolkit, a Mac computer, and a USB-A to Lightning cable. In this guide, we demonstrate how to unlock and image the iPhone 5 and 5c devices.
👉 https://www.elcomsoft.com/news/761.html
📝 Release Notes (PDF)
#ios #iphone #mobileforensics #dfir #iphone5 #passcode #pin #screenlock #dataextraction #eift #unlock #passcodecracking
iPhone 5 and 5c Passcode Unlock with iOS Forensic Toolkit
We have discovered a way to unlock encrypted iPhones protected with an unknown screen lock passcode. Our method supports two legacy iPhone models, the iPhone 5 and 5c, and requires a Mac to run the attack. Our solution is decidedly software-only; it does not require soldering, disassembling, or buying extra hardware. All you need is iOS Forensic Toolkit (new version), a Mac computer, and a USB-A to Lightning cable. In this guide, we’ll demonstrate how to unlock and image the iPhone 5 and 5c devices.
👉 https://blog.elcomsoft.com/2020/08/iphone-5-and-5c-passcode-unlock-with-ios-forensic-toolkit/
#ios #iphone #mobileforensics #dfir #iphone5 #passcode #pin #screenlock #dataextraction #eift #unlock #passcodecracking
We have discovered a way to unlock encrypted iPhones protected with an unknown screen lock passcode. Our method supports two legacy iPhone models, the iPhone 5 and 5c, and requires a Mac to run the attack. Our solution is decidedly software-only; it does not require soldering, disassembling, or buying extra hardware. All you need is iOS Forensic Toolkit (new version), a Mac computer, and a USB-A to Lightning cable. In this guide, we’ll demonstrate how to unlock and image the iPhone 5 and 5c devices.
👉 https://blog.elcomsoft.com/2020/08/iphone-5-and-5c-passcode-unlock-with-ios-forensic-toolkit/
#ios #iphone #mobileforensics #dfir #iphone5 #passcode #pin #screenlock #dataextraction #eift #unlock #passcodecracking
Behind the iPhone 5 and 5c Passcode Cracking
Smartphones are used for everything from placing calls and taking photos to navigating, tracking health and making payments. Smartphones contain massive amounts of sensitive information which becomes essential evidence. Accessing this evidence can be problematic or expensive, as was clearly demonstrated during the FBI-Apple encryption dispute, which was about the iPhone 5c used by the San Bernardino shooter in December 2015. With modern technological advances, iPhone 5c unlocks are no longer an issue.
👉 https://blog.elcomsoft.com/2020/08/behind-the-iphone-5-and-5c-passcode-cracking/
#ios #iphone #mobileforensics #dfir #iphone5 #passcode #pin #screenlock #dataextraction #eift #unlock #passcodecracking #decryption #dataextraction
Smartphones are used for everything from placing calls and taking photos to navigating, tracking health and making payments. Smartphones contain massive amounts of sensitive information which becomes essential evidence. Accessing this evidence can be problematic or expensive, as was clearly demonstrated during the FBI-Apple encryption dispute, which was about the iPhone 5c used by the San Bernardino shooter in December 2015. With modern technological advances, iPhone 5c unlocks are no longer an issue.
👉 https://blog.elcomsoft.com/2020/08/behind-the-iphone-5-and-5c-passcode-cracking/
#ios #iphone #mobileforensics #dfir #iphone5 #passcode #pin #screenlock #dataextraction #eift #unlock #passcodecracking #decryption #dataextraction
New Elcomsoft iOS Forensic Toolkit 6.50: jailbreak-free extraction without an Apple Developer Account
The macOS edition of Elcomsoft iOS Forensic Toolkit 6.50 drops the requirement for using a paid Apple Developer account when extracting the file system and decrypting the keychain from a compatible iPhone or iPad device. The new release also adds jailbreak-free agent-based extraction for iOS versions up to and including iOS 13.5.
👉 https://www.elcomsoft.com/news/762.html
##dfir #iphone #ios #itsecurity #iossecurity #mobileforensics
The macOS edition of Elcomsoft iOS Forensic Toolkit 6.50 drops the requirement for using a paid Apple Developer account when extracting the file system and decrypting the keychain from a compatible iPhone or iPad device. The new release also adds jailbreak-free agent-based extraction for iOS versions up to and including iOS 13.5.
👉 https://www.elcomsoft.com/news/762.html
##dfir #iphone #ios #itsecurity #iossecurity #mobileforensics
Extracting iPhone File System and Keychain Without an Apple Developer Account
Last year, we have developed an innovative way to extract iPhone data without a jailbreak. The method’s numerous advantages were outweighed with a major drawback: an Apple ID enrolled in the paid Apple’s Developer program was required to sign the extraction binary. This is no longer an issue on Mac computers with the improved sideloading technique.
👉 https://blog.elcomsoft.com/2020/09/extracting-iphone-file-system-and-keychain-without-an-apple-developer-account/
#iphone #ios #iossecurity #mobileforensics #dfir #mobilesecurity #mac #nojailbreak
Last year, we have developed an innovative way to extract iPhone data without a jailbreak. The method’s numerous advantages were outweighed with a major drawback: an Apple ID enrolled in the paid Apple’s Developer program was required to sign the extraction binary. This is no longer an issue on Mac computers with the improved sideloading technique.
👉 https://blog.elcomsoft.com/2020/09/extracting-iphone-file-system-and-keychain-without-an-apple-developer-account/
#iphone #ios #iossecurity #mobileforensics #dfir #mobilesecurity #mac #nojailbreak
Setting Up Restricted Internet Connection for iPhone Extraction
Regular or disposable Apple IDs can now be used to extract data from compatible iOS devices if you have a Mac. The use of a non-developer Apple ID carries certain risks and restrictions. In particular, one must “verify” the extraction agent on the target iPhone, which requires an active Internet connection. Learn how to verify the extraction agent signed with a regular or disposable Apple ID without the risk of receiving an accidental remote lock or remote erase command.
👉 https://blog.elcomsoft.com/2020/09/setting-up-restricted-internet-connection-for-iphone-extraction/
#ios #iphone #mobileforensics #dataextraction #iossecurity #jbfree #mac
Regular or disposable Apple IDs can now be used to extract data from compatible iOS devices if you have a Mac. The use of a non-developer Apple ID carries certain risks and restrictions. In particular, one must “verify” the extraction agent on the target iPhone, which requires an active Internet connection. Learn how to verify the extraction agent signed with a regular or disposable Apple ID without the risk of receiving an accidental remote lock or remote erase command.
👉 https://blog.elcomsoft.com/2020/09/setting-up-restricted-internet-connection-for-iphone-extraction/
#ios #iphone #mobileforensics #dataextraction #iossecurity #jbfree #mac
It’s Hashed, Not Encrypted
How many times have you seen the phrase: “Your password is securely encrypted”? More often than not, taking it at face value has little sense. Encryption means the data (such as the password) can be decrypted if you have the right key. Most passwords, however, cannot be decrypted since they weren’t encrypted in the first place. Instead, one might be able to recover them by running a lengthy attack. Let’s talk about the differences between encryption and hashing and discuss why some passwords are so much tougher to break.
👉 https://blog.elcomsoft.com/2020/09/its-hashed-not-encrypted/
#passwords #passwordsecurity #itsecurity #encryption #hashingpasswords #saltedhash
How many times have you seen the phrase: “Your password is securely encrypted”? More often than not, taking it at face value has little sense. Encryption means the data (such as the password) can be decrypted if you have the right key. Most passwords, however, cannot be decrypted since they weren’t encrypted in the first place. Instead, one might be able to recover them by running a lengthy attack. Let’s talk about the differences between encryption and hashing and discuss why some passwords are so much tougher to break.
👉 https://blog.elcomsoft.com/2020/09/its-hashed-not-encrypted/
#passwords #passwordsecurity #itsecurity #encryption #hashingpasswords #saltedhash
iOS 14 Forensics: What Has Changed Since iOS 13.7?
iOS 14 is officially out. It’s a big release from the privacy protection standpoint, but little had changed for the forensic expert. In this article, we’ll review what has changed in iOS 14 in the ways relevant for the forensic crowd.
👉 https://blog.elcomsoft.com/2020/09/ios-14-forensics-what-has-changed-since-ios-13-7/
#ios14 #iphone #mobilesecurity #dfir #mobileforensics #eift
iOS 14 is officially out. It’s a big release from the privacy protection standpoint, but little had changed for the forensic expert. In this article, we’ll review what has changed in iOS 14 in the ways relevant for the forensic crowd.
👉 https://blog.elcomsoft.com/2020/09/ios-14-forensics-what-has-changed-since-ios-13-7/
#ios14 #iphone #mobilesecurity #dfir #mobileforensics #eift
Using Screen Time Password to Protect iPhone Local Backups
The iOS backup system is truly unrivalled. The highly comprehensive, versatile and secure backups can be created with Apple iTunes. For the user, local backups are a convenient and easy way to transfer data to a new device or restore an existing one. In malicious hands, the backup becomes a dangerous weapon. Logins and passwords from the Keychain allow hackers accessing the user’s social accounts, messages, and financial information. A backup password can be set to protect local backups, but it can be removed just as easily shall the hacker have access to the physical iPhone and know its passcode. Let's discuss how the Screen Time password can be used to further strengthen the protection of local backups.
👉 https://blog.elcomsoft.com/2020/09/using-screen-time-password-to-protect-iphone-local-backups/
#iphone #ios #itsecurity #backups #mobilesecurity
The iOS backup system is truly unrivalled. The highly comprehensive, versatile and secure backups can be created with Apple iTunes. For the user, local backups are a convenient and easy way to transfer data to a new device or restore an existing one. In malicious hands, the backup becomes a dangerous weapon. Logins and passwords from the Keychain allow hackers accessing the user’s social accounts, messages, and financial information. A backup password can be set to protect local backups, but it can be removed just as easily shall the hacker have access to the physical iPhone and know its passcode. Let's discuss how the Screen Time password can be used to further strengthen the protection of local backups.
👉 https://blog.elcomsoft.com/2020/09/using-screen-time-password-to-protect-iphone-local-backups/
#iphone #ios #itsecurity #backups #mobilesecurity
The Issue of Trust: Untrusting Connected Devices from Your iPhone
When connecting an iPhone to a computer for the first time, you’ll see the prompt asking you whether to trust the computer. Trusting a computer enables your phone and computer to exchange information. However, should the trusted computer fall into the wrong hands, the pairing record from that computer could be used to pull information from your iPhone. Learn about the risks associated with pairing records and how to block unwanted connections by untrusting connected computers from your iPhone.
👉 https://blog.elcomsoft.com/2020/09/the-issue-of-trust-untrusting-connected-devices-from-your-iphone/
#ios #iphone #iossecurity #dfir #mobileforensics
When connecting an iPhone to a computer for the first time, you’ll see the prompt asking you whether to trust the computer. Trusting a computer enables your phone and computer to exchange information. However, should the trusted computer fall into the wrong hands, the pairing record from that computer could be used to pull information from your iPhone. Learn about the risks associated with pairing records and how to block unwanted connections by untrusting connected computers from your iPhone.
👉 https://blog.elcomsoft.com/2020/09/the-issue-of-trust-untrusting-connected-devices-from-your-iphone/
#ios #iphone #iossecurity #dfir #mobileforensics
Playing devil’s advocate: iPhone anti-forensics
Everyone’s iPhones contain overwhelming amounts of highly sensitive personal information. Even if some of that data is not stored on the device, the iPhone itself or the data inside can work as a key to other many things from bank accounts to private family life. While there are many possible vectors of attack, the attacker will always try exploiting the weakest link. Learn to think like one, find the weakest link and eliminate the potential vulnerabilities before they are exploited. This guide comes from the forensic guys making tools for the law enforcement, helping the good guys break into the bad guys’ iPhones.
👉 https://blog.elcomsoft.com/2020/09/playing-devils-advocate-iphone-anti-forensics/
#dfir #mobilesecurity #iossecurity #antiforensics #icloud #password #iphone
Everyone’s iPhones contain overwhelming amounts of highly sensitive personal information. Even if some of that data is not stored on the device, the iPhone itself or the data inside can work as a key to other many things from bank accounts to private family life. While there are many possible vectors of attack, the attacker will always try exploiting the weakest link. Learn to think like one, find the weakest link and eliminate the potential vulnerabilities before they are exploited. This guide comes from the forensic guys making tools for the law enforcement, helping the good guys break into the bad guys’ iPhones.
👉 https://blog.elcomsoft.com/2020/09/playing-devils-advocate-iphone-anti-forensics/
#dfir #mobilesecurity #iossecurity #antiforensics #icloud #password #iphone