Elcomsoft and The Case of the Apple iPad
For almost a decade, if not longer, I have collaborated with Vladimir Katalov on various digital forensics research topics. He has always been a great source of guidance, especially on iOS related challenges. When he offered me a standing invitation to post on the Elcomsoft Blog, I felt very humbled and honored to be given the opportunity to post on the ElcomSoft Blog, and I would like to thank the ElcomSoft team. This article has also been prepared together, with Vladimir Katalov.
π https://blog.elcomsoft.com/2020/11/elcomsoft-and-the-case-of-the-apple-ipad/
#ios #ipad #mobileforensics #dfir #elcomsoft_agent
For almost a decade, if not longer, I have collaborated with Vladimir Katalov on various digital forensics research topics. He has always been a great source of guidance, especially on iOS related challenges. When he offered me a standing invitation to post on the Elcomsoft Blog, I felt very humbled and honored to be given the opportunity to post on the ElcomSoft Blog, and I would like to thank the ElcomSoft team. This article has also been prepared together, with Vladimir Katalov.
π https://blog.elcomsoft.com/2020/11/elcomsoft-and-the-case-of-the-apple-ipad/
#ios #ipad #mobileforensics #dfir #elcomsoft_agent
Apple Watch Forensics Reloaded
Is it possible to extract any data from an Apple Watch? Itβs relatively easy if you have access to the iPhone the device is paired to, or if you have a backup of that iPhone. But what if the watch is all you have? If there is no paired iPhone, no backup and no iCloud credentials, how can you connect the Apple Watch to the computer, and can you backup the watch?
π https://blog.elcomsoft.com/2020/11/apple-watch-forensics-reloaded/
#ios #mobilesecurity #dfir #mobileforensics #applewatch
Is it possible to extract any data from an Apple Watch? Itβs relatively easy if you have access to the iPhone the device is paired to, or if you have a backup of that iPhone. But what if the watch is all you have? If there is no paired iPhone, no backup and no iCloud credentials, how can you connect the Apple Watch to the computer, and can you backup the watch?
π https://blog.elcomsoft.com/2020/11/apple-watch-forensics-reloaded/
#ios #mobilesecurity #dfir #mobileforensics #applewatch
Mobile Forensics β Advanced Investigative Strategies
Four years ago, we published our first book: Mobile Forensics β Advanced Investigative Strategies. We are really proud of this achievement. Do you want to know the story behind it and whatβs changed since then in mobile and cloud forensics? Here are some insides (but please do not tell anyone!)
π https://blog.elcomsoft.com/2020/11/mobile-forensics-advanced-investigative-strategies/
#dfir #mobileforensics #cybersecurity #book #digitalforensics
Four years ago, we published our first book: Mobile Forensics β Advanced Investigative Strategies. We are really proud of this achievement. Do you want to know the story behind it and whatβs changed since then in mobile and cloud forensics? Here are some insides (but please do not tell anyone!)
π https://blog.elcomsoft.com/2020/11/mobile-forensics-advanced-investigative-strategies/
#dfir #mobileforensics #cybersecurity #book #digitalforensics
Elcomsoft vs. Hashcat Part 1: Hardware Acceleration, Supported Formats and Initial Configuration
Hashcat is a great, free tool competing head to head with the tools we make. We charge several hundred dollars for what, in the end, can be done with a free tool. What are the reasons for our customers to choose ElcomSoft products instead of Hashcat, and is the expense justified? We did our best to compare the two tools to help you make the informed decision.
π https://blog.elcomsoft.com/2020/11/elcomsoft-vs-hashcat-part-1-hardware-acceleration-supported-formats-and-initial-configuration/
#encryption #passwords #gpucomputing #hashcat #bruteforce
Hashcat is a great, free tool competing head to head with the tools we make. We charge several hundred dollars for what, in the end, can be done with a free tool. What are the reasons for our customers to choose ElcomSoft products instead of Hashcat, and is the expense justified? We did our best to compare the two tools to help you make the informed decision.
π https://blog.elcomsoft.com/2020/11/elcomsoft-vs-hashcat-part-1-hardware-acceleration-supported-formats-and-initial-configuration/
#encryption #passwords #gpucomputing #hashcat #bruteforce
Extracting Evidence from iPhone Devices: Do I (Still) Need a Jailbreak?
by Vladimir Katalov
If you are familiar with iOS acquisition methods, you know that the best results can be obtained with a full file system acquisition. However, extracting the file system may require jailbreaking, which is a risky and not always permitted. Are there any reasons to use jailbreaks for extracting evidence from Apple devices?
π https://blog.elcomsoft.com/2020/11/extracting-evidence-from-iphone-devices-do-i-still-need-a-jailbreak/
#jailbreak #ios #mobilesecurity #dfir #iphone #checkra1n
by Vladimir Katalov
If you are familiar with iOS acquisition methods, you know that the best results can be obtained with a full file system acquisition. However, extracting the file system may require jailbreaking, which is a risky and not always permitted. Are there any reasons to use jailbreaks for extracting evidence from Apple devices?
π https://blog.elcomsoft.com/2020/11/extracting-evidence-from-iphone-devices-do-i-still-need-a-jailbreak/
#jailbreak #ios #mobilesecurity #dfir #iphone #checkra1n
Elcomsoft vs. Hashcat: Addressing Feedback
After publishing the first article in the series, we received numerous comments challenging our claims. We carefully reviewed every comment, reread and reevaluated our original article. Elcomsoft vs. Hashcat Rev.1.1 is here.
π https://blog.elcomsoft.com/2020/11/elcomsoft-vs-hashcat-addressing-feedback/
#passwords #hashcat #cybersecurity #passwordcracking #dfir #gpu
After publishing the first article in the series, we received numerous comments challenging our claims. We carefully reviewed every comment, reread and reevaluated our original article. Elcomsoft vs. Hashcat Rev.1.1 is here.
π https://blog.elcomsoft.com/2020/11/elcomsoft-vs-hashcat-addressing-feedback/
#passwords #hashcat #cybersecurity #passwordcracking #dfir #gpu
Elcomsoft vs. Hashcat Part 2: Workflow, Distributed and Cloud Attacks
The user interface is a major advantage of Elcomsoft tools. Setting up attacks in Elcomsoft Distributed Password Recovery is simpler and more straightforward compared to the command-line tool. In this article, weβll talk about the general workflow, the use and configuration of distributed and cloud attacks in both products.
π https://blog.elcomsoft.com/2020/11/elcomsoft-vs-hashcat-part-2-workflow-distributed-and-cloud-attacks/
#dfir #edpr #hashcat #passwordrecovery #datadecryption
The user interface is a major advantage of Elcomsoft tools. Setting up attacks in Elcomsoft Distributed Password Recovery is simpler and more straightforward compared to the command-line tool. In this article, weβll talk about the general workflow, the use and configuration of distributed and cloud attacks in both products.
π https://blog.elcomsoft.com/2020/11/elcomsoft-vs-hashcat-part-2-workflow-distributed-and-cloud-attacks/
#dfir #edpr #hashcat #passwordrecovery #datadecryption
Elcomsoft System Recovery update: a Swiss army knife in desktop forensics
We updated Elcomsoft System Recovery, a Windows PE-based tool to recover or reset passwords to local Windows accounts and Microsoft accounts in all versions of Windows. In this release, we offer more options for recovering the original passwords as opposed to resetting while adding a multitude of other improvements.
π https://www.elcomsoft.com/news/772.html
π Release Notes (PDF)
#encryption #virtualmachines #diskimage #passwords #dataaccess #passwordrecovery
We updated Elcomsoft System Recovery, a Windows PE-based tool to recover or reset passwords to local Windows accounts and Microsoft accounts in all versions of Windows. In this release, we offer more options for recovering the original passwords as opposed to resetting while adding a multitude of other improvements.
π https://www.elcomsoft.com/news/772.html
π Release Notes (PDF)
#encryption #virtualmachines #diskimage #passwords #dataaccess #passwordrecovery
Elcomsoft System Recovery: a Swiss Army Knife of Desktop Forensics
Accessing a locked system is always a challenge. Encrypted disks and encrypted virtual machines, encrypted files and passwords are just a few things to mention. In this article we are proposing a straightforward workflow for investigating computers in the field.
Note: you may be able to perform live system analysis if the computer being investigated is turned on. Our scenario assumes that the computer is initially powered off, or powered on and locked/inaccessible.
π https://blog.elcomsoft.com/2020/11/elcomsoft-system-recovery-a-swiss-army-knife-of-desktop-forensics/
#encrypteddisks #virtualmachines #passwords #livesystemanalysis
Accessing a locked system is always a challenge. Encrypted disks and encrypted virtual machines, encrypted files and passwords are just a few things to mention. In this article we are proposing a straightforward workflow for investigating computers in the field.
Note: you may be able to perform live system analysis if the computer being investigated is turned on. Our scenario assumes that the computer is initially powered off, or powered on and locked/inaccessible.
π https://blog.elcomsoft.com/2020/11/elcomsoft-system-recovery-a-swiss-army-knife-of-desktop-forensics/
#encrypteddisks #virtualmachines #passwords #livesystemanalysis
The ABCβs of Password Cracking: The True Meaning of Speed
When adding a new encryption format or comparing the performance of different password recovery tools, we routinely quote the recovery speed expressed in the number of passwords per second. But what is the true meaning of password recovery speeds? Do the speeds depend solely, or at all, on the encryption algorithm? Whatβs βmilitary gradeβ encryption, and does it guarantee the security of your data? And why on Earth breaking AES-256 encryption takes so vastly different effort in different file formats? Read along to find out.
π https://blog.elcomsoft.com/2020/11/the-abcs-of-password-cracking-the-true-meaning-of-speed/
#passwords #passwordrecovery #dfir #digitalforensics #datasecurity #dataaccess
When adding a new encryption format or comparing the performance of different password recovery tools, we routinely quote the recovery speed expressed in the number of passwords per second. But what is the true meaning of password recovery speeds? Do the speeds depend solely, or at all, on the encryption algorithm? Whatβs βmilitary gradeβ encryption, and does it guarantee the security of your data? And why on Earth breaking AES-256 encryption takes so vastly different effort in different file formats? Read along to find out.
π https://blog.elcomsoft.com/2020/11/the-abcs-of-password-cracking-the-true-meaning-of-speed/
#passwords #passwordrecovery #dfir #digitalforensics #datasecurity #dataaccess
Forensically Sound Cold System Analysis
As opposed to live system analysis, experts performing the cold analysis are not dealing with authenticated user sessions. Instead, cold analysis can be viewed as an intermediary measure with live system analysis on the one end and the examination of a forensic disk image on another. Why and when would you use cold system analysis, what can you do and what benefits does it bring compared to the traditional approach? Read along to find out.
π https://blog.elcomsoft.com/2020/12/forensically-sound-cold-system-analysis/
#dfir #datasecurity #encryption #windows #itsecurity
As opposed to live system analysis, experts performing the cold analysis are not dealing with authenticated user sessions. Instead, cold analysis can be viewed as an intermediary measure with live system analysis on the one end and the examination of a forensic disk image on another. Why and when would you use cold system analysis, what can you do and what benefits does it bring compared to the traditional approach? Read along to find out.
π https://blog.elcomsoft.com/2020/12/forensically-sound-cold-system-analysis/
#dfir #datasecurity #encryption #windows #itsecurity
Elcomsoft vs. Hashcat Part 3: Attacks, Costs, Performance and Extra Features
Elcomsoft Distributed Password Recovery and Hashcat support a number of different attacks ranging from brute-force all the way to scriptable, dictionary-based attacks. The costs and performance are extremely important factors. We charge several hundred dollars for what, in the end, can be done with a free tool. Which tool has better performance, and are the extra features worth the price premium? Letβs check it out.
π https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-3-attacks-costs-performance-and-extra-features/
#passwords #dfir #cybersecurity #datasecurity #passwordrecovery
Elcomsoft Distributed Password Recovery and Hashcat support a number of different attacks ranging from brute-force all the way to scriptable, dictionary-based attacks. The costs and performance are extremely important factors. We charge several hundred dollars for what, in the end, can be done with a free tool. Which tool has better performance, and are the extra features worth the price premium? Letβs check it out.
π https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-3-attacks-costs-performance-and-extra-features/
#passwords #dfir #cybersecurity #datasecurity #passwordrecovery
iOS Forensic Toolkit 6.60: jailbreak-free extraction for iOS 9.0 through 13.7
Elcomsoft iOS Forensic Toolkit 6.60 extends the coverage for jailbreak-free extraction from iOS 9.0 all the way through iOS 13.7, adding support to the last versions of iOS 13 ever released. The new release expands the availability of the extraction agent, adding full file system and keychain decryption support for previously unsupported versions of iOS 13.5.1 to 13.7 on all compatible iPhone and iPad devices.
π Release Notes (PDF)
π https://www.elcomsoft.com/news/774.html
#ios #iphone #mobileforensics #dfir #cybersecurity #EIFTagent #dataextraction
Elcomsoft iOS Forensic Toolkit 6.60 extends the coverage for jailbreak-free extraction from iOS 9.0 all the way through iOS 13.7, adding support to the last versions of iOS 13 ever released. The new release expands the availability of the extraction agent, adding full file system and keychain decryption support for previously unsupported versions of iOS 13.5.1 to 13.7 on all compatible iPhone and iPad devices.
π Release Notes (PDF)
π https://www.elcomsoft.com/news/774.html
#ios #iphone #mobileforensics #dfir #cybersecurity #EIFTagent #dataextraction
The Evolution of iOS Acquisition: Jailbreaks, Exploits and Extraction Agent
The past two years have become a turning point in iOS acquisition. The release of a bootrom-based exploit and the corresponding jailbreak made BFU acquisition possible on multiple devices regardless of security patches. Another exploit covers the entire iOS 13 range on all devices regardless of their hardware revision. ElcomSoft developed a jailbreak-free extraction method for the entire iOS 9.0-13.7 range. Letβs see what low-level acquisition options are available today, and when to use what.
π https://blog.elcomsoft.com/2020/12/the-evolution-of-ios-acquisition-jailbreaks-exploits-and-extraction-agent/
#ios #iphone #mobileforensics #dfir #EIFTagent #dataextraction #jailbreak
The past two years have become a turning point in iOS acquisition. The release of a bootrom-based exploit and the corresponding jailbreak made BFU acquisition possible on multiple devices regardless of security patches. Another exploit covers the entire iOS 13 range on all devices regardless of their hardware revision. ElcomSoft developed a jailbreak-free extraction method for the entire iOS 9.0-13.7 range. Letβs see what low-level acquisition options are available today, and when to use what.
π https://blog.elcomsoft.com/2020/12/the-evolution-of-ios-acquisition-jailbreaks-exploits-and-extraction-agent/
#ios #iphone #mobileforensics #dfir #EIFTagent #dataextraction #jailbreak
iOS Extraction Without a Jailbreak: iOS 9 through iOS 13.7 on All Devices
After adding jailbreak-free extraction for iOS 13.5.1 through 13.7, we now support every Apple device running any version of iOS from 9.0 through 13.7 with no gaps or exclusions. For the first time, full file system extraction and keychain decryption are possible on all devices running these iOS versions.
π https://blog.elcomsoft.com/2020/12/ios-extraction-without-a-jailbreak-ios-9-through-ios-13-7-on-all-devices/
#ios #iphone #dfir #EIFTagent #mobileforensics #nojailbreak
After adding jailbreak-free extraction for iOS 13.5.1 through 13.7, we now support every Apple device running any version of iOS from 9.0 through 13.7 with no gaps or exclusions. For the first time, full file system extraction and keychain decryption are possible on all devices running these iOS versions.
π https://blog.elcomsoft.com/2020/12/ios-extraction-without-a-jailbreak-ios-9-through-ios-13-7-on-all-devices/
#ios #iphone #dfir #EIFTagent #mobileforensics #nojailbreak
How to Remove The iPhone Passcode You Cannot Remove
From time to time, we stumble upon a weird issue that interferes with the ability to install a jailbreak. One of such problems appearing literally out of the blue is the issue of being unable to remove the screen lock password on some iPhone devices. What could be the reason and how to work around the issue? Read along to find out!
π https://blog.elcomsoft.com/2020/12/how-to-remove-the-iphone-passcode-you-cannot-remove/
#iphone #passcode #screenlock #eift #jailbreak #mobileforensics
From time to time, we stumble upon a weird issue that interferes with the ability to install a jailbreak. One of such problems appearing literally out of the blue is the issue of being unable to remove the screen lock password on some iPhone devices. What could be the reason and how to work around the issue? Read along to find out!
π https://blog.elcomsoft.com/2020/12/how-to-remove-the-iphone-passcode-you-cannot-remove/
#iphone #passcode #screenlock #eift #jailbreak #mobileforensics
Elcomsoft vs. Hashcat Part 4: Case Studies
This is the final part of the series of articles comparing Elcomsoft Distributed Password Recovery with Hashcat. Weβve already compared the features, the price and performance of the two tools. In this study, we tried breaking passwords to several common formats, including Word document, an encrypted ZIP archive, and a VeraCrypt container. We summarized our experiences below.
π https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-4-case-studies/
#gpu #passwords #passwordrecovery #veracrypt #zip #hashcat
This is the final part of the series of articles comparing Elcomsoft Distributed Password Recovery with Hashcat. Weβve already compared the features, the price and performance of the two tools. In this study, we tried breaking passwords to several common formats, including Word document, an encrypted ZIP archive, and a VeraCrypt container. We summarized our experiences below.
π https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-4-case-studies/
#gpu #passwords #passwordrecovery #veracrypt #zip #hashcat
Recovering Screen Time Passwords
The Screen Time password has been long recommended as an extra security layer. By setting a Screen Time password without any additional restrictions, Apple users could easily dodge attempts of changing or removing the screen lock passcode, resetting the iTunes backup password, or removing the activation lock. For a long time, removing the Screen Time password was not possible without either providing the original password or erasing the device. However, Apple had changed the way it works, making it possible to reset the Screen Time password with an iCloud/Apple ID password.
π https://blog.elcomsoft.com/2020/12/recovering-screen-time-passwords/
#dfir #passwords #mobileforensics #ios #iphone
The Screen Time password has been long recommended as an extra security layer. By setting a Screen Time password without any additional restrictions, Apple users could easily dodge attempts of changing or removing the screen lock passcode, resetting the iTunes backup password, or removing the activation lock. For a long time, removing the Screen Time password was not possible without either providing the original password or erasing the device. However, Apple had changed the way it works, making it possible to reset the Screen Time password with an iCloud/Apple ID password.
π https://blog.elcomsoft.com/2020/12/recovering-screen-time-passwords/
#dfir #passwords #mobileforensics #ios #iphone
Elcomsoft breaks BestCrypt containers, supports NVIDIA Ampere cards
We updated Elcomsoft Forensic Disk Decryptor, Advanced Office Password Recovery and Elcomsoft Distributed Password Recovery with support for additional data formats and GPU accelerators. The updated tools break Jetico BestCrypt 9 containers, accelerate ZIP and RAR recovery on AMD and Intel GPUs, and add support for NVIDIAβs latest RTX 3000-series boards based on the Ampere architecture.
π Release Notes (PDF)
π https://www.elcomsoft.com/news/775.html
#gpu #passwords #passwordrecovery #zip #rar #archives #nvidia #myoffice #bestcrypt
We updated Elcomsoft Forensic Disk Decryptor, Advanced Office Password Recovery and Elcomsoft Distributed Password Recovery with support for additional data formats and GPU accelerators. The updated tools break Jetico BestCrypt 9 containers, accelerate ZIP and RAR recovery on AMD and Intel GPUs, and add support for NVIDIAβs latest RTX 3000-series boards based on the Ampere architecture.
π Release Notes (PDF)
π https://www.elcomsoft.com/news/775.html
#gpu #passwords #passwordrecovery #zip #rar #archives #nvidia #myoffice #bestcrypt
Breaking Passwords with NVIDIA RTX 3080 and 3090
Today we have an important date. Advanced Office Password Recovery turned 16. What started as an instant recovery tool for legacy versions of Microsoft Word had now become a GPU-accelerated toolkit for breaking the many Microsoft formats. Today weβre releasing a major update, giving Advanced Office Password Recovery and Distributed Password Recovery tools the ability to crunch passwords faster with the newest and latest NVIDIA 3000-series graphic boards. Powered by Ampere, the new generation of GPUs delivers unprecedented performance in modern video games. How do the new cards fare when it comes to accelerating the password recovery, and is an upgrade worth it for the forensic experts? Letβs find out.
π https://blog.elcomsoft.com/2020/12/breaking-passwords-with-nvidia-rtx-3080-and-3090/
#gpu #nvidia #rtx3090 #passwordcracking #bruteforce #videocards
Today we have an important date. Advanced Office Password Recovery turned 16. What started as an instant recovery tool for legacy versions of Microsoft Word had now become a GPU-accelerated toolkit for breaking the many Microsoft formats. Today weβre releasing a major update, giving Advanced Office Password Recovery and Distributed Password Recovery tools the ability to crunch passwords faster with the newest and latest NVIDIA 3000-series graphic boards. Powered by Ampere, the new generation of GPUs delivers unprecedented performance in modern video games. How do the new cards fare when it comes to accelerating the password recovery, and is an upgrade worth it for the forensic experts? Letβs find out.
π https://blog.elcomsoft.com/2020/12/breaking-passwords-with-nvidia-rtx-3080-and-3090/
#gpu #nvidia #rtx3090 #passwordcracking #bruteforce #videocards
New Privacy Features: iOS 14.0 through 14.3
Apple has long provided its users the tools to control how apps and Web sites use their personal data. The release of iOS 14 brought a number of new privacy features, while iOS 14.3 adds an important extra. At the same time, one of the most interesting privacy features is facing tough opposition from a group of digital advertising associations, making Apple postpone its implementation.
π https://blog.elcomsoft.com/2020/12/new-privacy-features-ios-14-0-through-14-3/
#iphone #ios14 #mobilesecurity #dfir #privacy
Apple has long provided its users the tools to control how apps and Web sites use their personal data. The release of iOS 14 brought a number of new privacy features, while iOS 14.3 adds an important extra. At the same time, one of the most interesting privacy features is facing tough opposition from a group of digital advertising associations, making Apple postpone its implementation.
π https://blog.elcomsoft.com/2020/12/new-privacy-features-ios-14-0-through-14-3/
#iphone #ios14 #mobilesecurity #dfir #privacy