Forensically Sound Cold System Analysis
As opposed to live system analysis, experts performing the cold analysis are not dealing with authenticated user sessions. Instead, cold analysis can be viewed as an intermediary measure with live system analysis on the one end and the examination of a forensic disk image on another. Why and when would you use cold system analysis, what can you do and what benefits does it bring compared to the traditional approach? Read along to find out.
👉 https://blog.elcomsoft.com/2020/12/forensically-sound-cold-system-analysis/
#dfir #datasecurity #encryption #windows #itsecurity
As opposed to live system analysis, experts performing the cold analysis are not dealing with authenticated user sessions. Instead, cold analysis can be viewed as an intermediary measure with live system analysis on the one end and the examination of a forensic disk image on another. Why and when would you use cold system analysis, what can you do and what benefits does it bring compared to the traditional approach? Read along to find out.
👉 https://blog.elcomsoft.com/2020/12/forensically-sound-cold-system-analysis/
#dfir #datasecurity #encryption #windows #itsecurity
Elcomsoft vs. Hashcat Part 3: Attacks, Costs, Performance and Extra Features
Elcomsoft Distributed Password Recovery and Hashcat support a number of different attacks ranging from brute-force all the way to scriptable, dictionary-based attacks. The costs and performance are extremely important factors. We charge several hundred dollars for what, in the end, can be done with a free tool. Which tool has better performance, and are the extra features worth the price premium? Let’s check it out.
👉 https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-3-attacks-costs-performance-and-extra-features/
#passwords #dfir #cybersecurity #datasecurity #passwordrecovery
Elcomsoft Distributed Password Recovery and Hashcat support a number of different attacks ranging from brute-force all the way to scriptable, dictionary-based attacks. The costs and performance are extremely important factors. We charge several hundred dollars for what, in the end, can be done with a free tool. Which tool has better performance, and are the extra features worth the price premium? Let’s check it out.
👉 https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-3-attacks-costs-performance-and-extra-features/
#passwords #dfir #cybersecurity #datasecurity #passwordrecovery
iOS Forensic Toolkit 6.60: jailbreak-free extraction for iOS 9.0 through 13.7
Elcomsoft iOS Forensic Toolkit 6.60 extends the coverage for jailbreak-free extraction from iOS 9.0 all the way through iOS 13.7, adding support to the last versions of iOS 13 ever released. The new release expands the availability of the extraction agent, adding full file system and keychain decryption support for previously unsupported versions of iOS 13.5.1 to 13.7 on all compatible iPhone and iPad devices.
📝 Release Notes (PDF)
👉 https://www.elcomsoft.com/news/774.html
#ios #iphone #mobileforensics #dfir #cybersecurity #EIFTagent #dataextraction
Elcomsoft iOS Forensic Toolkit 6.60 extends the coverage for jailbreak-free extraction from iOS 9.0 all the way through iOS 13.7, adding support to the last versions of iOS 13 ever released. The new release expands the availability of the extraction agent, adding full file system and keychain decryption support for previously unsupported versions of iOS 13.5.1 to 13.7 on all compatible iPhone and iPad devices.
📝 Release Notes (PDF)
👉 https://www.elcomsoft.com/news/774.html
#ios #iphone #mobileforensics #dfir #cybersecurity #EIFTagent #dataextraction
The Evolution of iOS Acquisition: Jailbreaks, Exploits and Extraction Agent
The past two years have become a turning point in iOS acquisition. The release of a bootrom-based exploit and the corresponding jailbreak made BFU acquisition possible on multiple devices regardless of security patches. Another exploit covers the entire iOS 13 range on all devices regardless of their hardware revision. ElcomSoft developed a jailbreak-free extraction method for the entire iOS 9.0-13.7 range. Let’s see what low-level acquisition options are available today, and when to use what.
👉 https://blog.elcomsoft.com/2020/12/the-evolution-of-ios-acquisition-jailbreaks-exploits-and-extraction-agent/
#ios #iphone #mobileforensics #dfir #EIFTagent #dataextraction #jailbreak
The past two years have become a turning point in iOS acquisition. The release of a bootrom-based exploit and the corresponding jailbreak made BFU acquisition possible on multiple devices regardless of security patches. Another exploit covers the entire iOS 13 range on all devices regardless of their hardware revision. ElcomSoft developed a jailbreak-free extraction method for the entire iOS 9.0-13.7 range. Let’s see what low-level acquisition options are available today, and when to use what.
👉 https://blog.elcomsoft.com/2020/12/the-evolution-of-ios-acquisition-jailbreaks-exploits-and-extraction-agent/
#ios #iphone #mobileforensics #dfir #EIFTagent #dataextraction #jailbreak
iOS Extraction Without a Jailbreak: iOS 9 through iOS 13.7 on All Devices
After adding jailbreak-free extraction for iOS 13.5.1 through 13.7, we now support every Apple device running any version of iOS from 9.0 through 13.7 with no gaps or exclusions. For the first time, full file system extraction and keychain decryption are possible on all devices running these iOS versions.
👉 https://blog.elcomsoft.com/2020/12/ios-extraction-without-a-jailbreak-ios-9-through-ios-13-7-on-all-devices/
#ios #iphone #dfir #EIFTagent #mobileforensics #nojailbreak
After adding jailbreak-free extraction for iOS 13.5.1 through 13.7, we now support every Apple device running any version of iOS from 9.0 through 13.7 with no gaps or exclusions. For the first time, full file system extraction and keychain decryption are possible on all devices running these iOS versions.
👉 https://blog.elcomsoft.com/2020/12/ios-extraction-without-a-jailbreak-ios-9-through-ios-13-7-on-all-devices/
#ios #iphone #dfir #EIFTagent #mobileforensics #nojailbreak
How to Remove The iPhone Passcode You Cannot Remove
From time to time, we stumble upon a weird issue that interferes with the ability to install a jailbreak. One of such problems appearing literally out of the blue is the issue of being unable to remove the screen lock password on some iPhone devices. What could be the reason and how to work around the issue? Read along to find out!
👉 https://blog.elcomsoft.com/2020/12/how-to-remove-the-iphone-passcode-you-cannot-remove/
#iphone #passcode #screenlock #eift #jailbreak #mobileforensics
From time to time, we stumble upon a weird issue that interferes with the ability to install a jailbreak. One of such problems appearing literally out of the blue is the issue of being unable to remove the screen lock password on some iPhone devices. What could be the reason and how to work around the issue? Read along to find out!
👉 https://blog.elcomsoft.com/2020/12/how-to-remove-the-iphone-passcode-you-cannot-remove/
#iphone #passcode #screenlock #eift #jailbreak #mobileforensics
Elcomsoft vs. Hashcat Part 4: Case Studies
This is the final part of the series of articles comparing Elcomsoft Distributed Password Recovery with Hashcat. We’ve already compared the features, the price and performance of the two tools. In this study, we tried breaking passwords to several common formats, including Word document, an encrypted ZIP archive, and a VeraCrypt container. We summarized our experiences below.
👉 https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-4-case-studies/
#gpu #passwords #passwordrecovery #veracrypt #zip #hashcat
This is the final part of the series of articles comparing Elcomsoft Distributed Password Recovery with Hashcat. We’ve already compared the features, the price and performance of the two tools. In this study, we tried breaking passwords to several common formats, including Word document, an encrypted ZIP archive, and a VeraCrypt container. We summarized our experiences below.
👉 https://blog.elcomsoft.com/2020/12/elcomsoft-vs-hashcat-part-4-case-studies/
#gpu #passwords #passwordrecovery #veracrypt #zip #hashcat
Recovering Screen Time Passwords
The Screen Time password has been long recommended as an extra security layer. By setting a Screen Time password without any additional restrictions, Apple users could easily dodge attempts of changing or removing the screen lock passcode, resetting the iTunes backup password, or removing the activation lock. For a long time, removing the Screen Time password was not possible without either providing the original password or erasing the device. However, Apple had changed the way it works, making it possible to reset the Screen Time password with an iCloud/Apple ID password.
👉 https://blog.elcomsoft.com/2020/12/recovering-screen-time-passwords/
#dfir #passwords #mobileforensics #ios #iphone
The Screen Time password has been long recommended as an extra security layer. By setting a Screen Time password without any additional restrictions, Apple users could easily dodge attempts of changing or removing the screen lock passcode, resetting the iTunes backup password, or removing the activation lock. For a long time, removing the Screen Time password was not possible without either providing the original password or erasing the device. However, Apple had changed the way it works, making it possible to reset the Screen Time password with an iCloud/Apple ID password.
👉 https://blog.elcomsoft.com/2020/12/recovering-screen-time-passwords/
#dfir #passwords #mobileforensics #ios #iphone
Elcomsoft breaks BestCrypt containers, supports NVIDIA Ampere cards
We updated Elcomsoft Forensic Disk Decryptor, Advanced Office Password Recovery and Elcomsoft Distributed Password Recovery with support for additional data formats and GPU accelerators. The updated tools break Jetico BestCrypt 9 containers, accelerate ZIP and RAR recovery on AMD and Intel GPUs, and add support for NVIDIA’s latest RTX 3000-series boards based on the Ampere architecture.
📝 Release Notes (PDF)
👉 https://www.elcomsoft.com/news/775.html
#gpu #passwords #passwordrecovery #zip #rar #archives #nvidia #myoffice #bestcrypt
We updated Elcomsoft Forensic Disk Decryptor, Advanced Office Password Recovery and Elcomsoft Distributed Password Recovery with support for additional data formats and GPU accelerators. The updated tools break Jetico BestCrypt 9 containers, accelerate ZIP and RAR recovery on AMD and Intel GPUs, and add support for NVIDIA’s latest RTX 3000-series boards based on the Ampere architecture.
📝 Release Notes (PDF)
👉 https://www.elcomsoft.com/news/775.html
#gpu #passwords #passwordrecovery #zip #rar #archives #nvidia #myoffice #bestcrypt
Breaking Passwords with NVIDIA RTX 3080 and 3090
Today we have an important date. Advanced Office Password Recovery turned 16. What started as an instant recovery tool for legacy versions of Microsoft Word had now become a GPU-accelerated toolkit for breaking the many Microsoft formats. Today we’re releasing a major update, giving Advanced Office Password Recovery and Distributed Password Recovery tools the ability to crunch passwords faster with the newest and latest NVIDIA 3000-series graphic boards. Powered by Ampere, the new generation of GPUs delivers unprecedented performance in modern video games. How do the new cards fare when it comes to accelerating the password recovery, and is an upgrade worth it for the forensic experts? Let’s find out.
👉 https://blog.elcomsoft.com/2020/12/breaking-passwords-with-nvidia-rtx-3080-and-3090/
#gpu #nvidia #rtx3090 #passwordcracking #bruteforce #videocards
Today we have an important date. Advanced Office Password Recovery turned 16. What started as an instant recovery tool for legacy versions of Microsoft Word had now become a GPU-accelerated toolkit for breaking the many Microsoft formats. Today we’re releasing a major update, giving Advanced Office Password Recovery and Distributed Password Recovery tools the ability to crunch passwords faster with the newest and latest NVIDIA 3000-series graphic boards. Powered by Ampere, the new generation of GPUs delivers unprecedented performance in modern video games. How do the new cards fare when it comes to accelerating the password recovery, and is an upgrade worth it for the forensic experts? Let’s find out.
👉 https://blog.elcomsoft.com/2020/12/breaking-passwords-with-nvidia-rtx-3080-and-3090/
#gpu #nvidia #rtx3090 #passwordcracking #bruteforce #videocards
New Privacy Features: iOS 14.0 through 14.3
Apple has long provided its users the tools to control how apps and Web sites use their personal data. The release of iOS 14 brought a number of new privacy features, while iOS 14.3 adds an important extra. At the same time, one of the most interesting privacy features is facing tough opposition from a group of digital advertising associations, making Apple postpone its implementation.
👉 https://blog.elcomsoft.com/2020/12/new-privacy-features-ios-14-0-through-14-3/
#iphone #ios14 #mobilesecurity #dfir #privacy
Apple has long provided its users the tools to control how apps and Web sites use their personal data. The release of iOS 14 brought a number of new privacy features, while iOS 14.3 adds an important extra. At the same time, one of the most interesting privacy features is facing tough opposition from a group of digital advertising associations, making Apple postpone its implementation.
👉 https://blog.elcomsoft.com/2020/12/new-privacy-features-ios-14-0-through-14-3/
#iphone #ios14 #mobilesecurity #dfir #privacy
iPhone Backups: Top 5 Default Passwords
The iPhone backup is one of the hottest topics in iOS forensics. iTunes-style backups are the core of logical acquisition used by forensic specialists, containing overwhelming amounts of evidence that is is unrivaled on other platforms. The backups, as simple as they seem, have many “ifs” and “buts”, especially when it comes to password protection. We wrote a thousand and one articles about iOS backup passwords, but there is always something fresh that comes out. Today we have some new tips for you.
👉 https://blog.elcomsoft.com/2020/12/iphone-backups-top-5-default-passwords/
#iphone #ios #passwords #dfir #mobilesecurity #cybersecurity
The iPhone backup is one of the hottest topics in iOS forensics. iTunes-style backups are the core of logical acquisition used by forensic specialists, containing overwhelming amounts of evidence that is is unrivaled on other platforms. The backups, as simple as they seem, have many “ifs” and “buts”, especially when it comes to password protection. We wrote a thousand and one articles about iOS backup passwords, but there is always something fresh that comes out. Today we have some new tips for you.
👉 https://blog.elcomsoft.com/2020/12/iphone-backups-top-5-default-passwords/
#iphone #ios #passwords #dfir #mobilesecurity #cybersecurity
NAS Forensics: QNAP Encryption Analysis
A year ago, we analyzed the encryption used in Synology NAS devices. We were somewhat disappointed by the company’s choice to rely on a single encryption layer with multiple functional restrictions and security reservations. Today we are publishing the results of our analysis of data encryption used in QNAP devices. Spoiler: it’s very, very different.
👉 https://blog.elcomsoft.com/2020/12/nas-forensics-qnap-encryption-analysis/
#nas #encryption #datasecurity #dataprotection #sedencryption
A year ago, we analyzed the encryption used in Synology NAS devices. We were somewhat disappointed by the company’s choice to rely on a single encryption layer with multiple functional restrictions and security reservations. Today we are publishing the results of our analysis of data encryption used in QNAP devices. Spoiler: it’s very, very different.
👉 https://blog.elcomsoft.com/2020/12/nas-forensics-qnap-encryption-analysis/
#nas #encryption #datasecurity #dataprotection #sedencryption
2020 in Review: What Was New in Desktop and Mobile Forensics
This year is different from many before. The Corona pandemic, the lack of travel and canceled events had changed the business landscape for many forensic companies. Yet, even this year, we made a number of achievements we’d love to share.
👉 https://blog.elcomsoft.com/2020/12/2020-in-review-what-was-new-in-desktop-and-mobile-forensics/
#digitalforensics #mobilesecurtiy #dfir #iosacquisition #cybersecurity
This year is different from many before. The Corona pandemic, the lack of travel and canceled events had changed the business landscape for many forensic companies. Yet, even this year, we made a number of achievements we’d love to share.
👉 https://blog.elcomsoft.com/2020/12/2020-in-review-what-was-new-in-desktop-and-mobile-forensics/
#digitalforensics #mobilesecurtiy #dfir #iosacquisition #cybersecurity
Understanding BitLocker TPM Protection
Investigating a BitLocker-encrypted hard drive can be challenging, especially if the encryption keys are protected by the computer’s hardware protection, the TPM. In this article, we’ll talk about the protection that TPM chips provide to BitLocker volumes, and discuss vulnerabilities found in today’s TPM modules.
👉 https://blog.elcomsoft.com/2021/01/understanding-bitlocker-tpm-protection/
#tpm #encryption #datasecurity #bitlocker
Investigating a BitLocker-encrypted hard drive can be challenging, especially if the encryption keys are protected by the computer’s hardware protection, the TPM. In this article, we’ll talk about the protection that TPM chips provide to BitLocker volumes, and discuss vulnerabilities found in today’s TPM modules.
👉 https://blog.elcomsoft.com/2021/01/understanding-bitlocker-tpm-protection/
#tpm #encryption #datasecurity #bitlocker
Apple Scraps End-to-End Encryption of iCloud Backups
Reportedly, Apple dropped plan for encrypting backups after FBI complained. Apple’s decision will undoubtedly cause turmoil and will have a number of consequences. In this article, I want to talk about the technical reasons for encrypting or not encrypting cloud backup, and compare Apple’s approach with the data encryption strategies used by Google, who have been encrypting Android backups for several years.
👉 https://blog.elcomsoft.com/2021/01/apple-scraps-end-to-end-encryption-of-icloud-backups/
#dfir #cybersecurity #mobileforensics #e2ee #icloud
Reportedly, Apple dropped plan for encrypting backups after FBI complained. Apple’s decision will undoubtedly cause turmoil and will have a number of consequences. In this article, I want to talk about the technical reasons for encrypting or not encrypting cloud backup, and compare Apple’s approach with the data encryption strategies used by Google, who have been encrypting Android backups for several years.
👉 https://blog.elcomsoft.com/2021/01/apple-scraps-end-to-end-encryption-of-icloud-backups/
#dfir #cybersecurity #mobileforensics #e2ee #icloud
Apple, FBI and iPhone Backup Encryption: Everything You Wanted to Know
Shame on us, we somehow missed the whole issue about Apple dropping plan for encrypting backups after FBI complained, even mentioned in The Cybersecurity Stories We Were Jealous of in 2020 (and many reprints). In the meantime, the article is full of rumors, guesses, and unverified and technically dubious information. “Fake news”, so to say. Is there truth to the rumors, and what does Apple do and does not do when it comes to encrypting your personal information?
👉 https://blog.elcomsoft.com/2021/01/apple-fbi-and-iphone-backup-encryption-everything-you-wanted-to-know/
#ios #iphone #fbi #mobilesecurity #dfir #cybersecurity
Shame on us, we somehow missed the whole issue about Apple dropping plan for encrypting backups after FBI complained, even mentioned in The Cybersecurity Stories We Were Jealous of in 2020 (and many reprints). In the meantime, the article is full of rumors, guesses, and unverified and technically dubious information. “Fake news”, so to say. Is there truth to the rumors, and what does Apple do and does not do when it comes to encrypting your personal information?
👉 https://blog.elcomsoft.com/2021/01/apple-fbi-and-iphone-backup-encryption-everything-you-wanted-to-know/
#ios #iphone #fbi #mobilesecurity #dfir #cybersecurity
DFU Mode Cheat Sheet
The Device Firmware Upgrade mode, or simply DFU, just got a second breath. The ability to image the file system, decrypt the keychain and even do passcode unlocks on some older iPhone models has been made possible thanks to the checkm8 exploit and the checkra1n jailbreak, both of which require switching the phone into DFU. The procedure is undocumented, and the steps are different for the various devices.
👉 https://blog.elcomsoft.com/2021/01/dfu-mode-cheat-sheet/
#dfumode #iphone #ios #mobileforensics
The Device Firmware Upgrade mode, or simply DFU, just got a second breath. The ability to image the file system, decrypt the keychain and even do passcode unlocks on some older iPhone models has been made possible thanks to the checkm8 exploit and the checkra1n jailbreak, both of which require switching the phone into DFU. The procedure is undocumented, and the steps are different for the various devices.
👉 https://blog.elcomsoft.com/2021/01/dfu-mode-cheat-sheet/
#dfumode #iphone #ios #mobileforensics
Secure Instant Messengers
In today’s world of everyone wanting a slice of one’s personal information, users become more and more concerned about the privacy. The WhatsApp/Facebook integration raised an additional concern, considering that Facebook-owned Messenger requests the largest number of invasive permissions among all commonly used messengers. Data privacy and security concerns are mounting like a snowball. 2020 brought multiple data breach incidents from popular blogging resources from LiveJournal whose users’ data was breached and leaked to the darknet to financial institutions like Postbank with 12M exposed credit cards, hospitality giants as Mariott with 383 million records compromised or even Microsoft customers who also suffered from privacy-related issues.
👉 https://blog.elcomsoft.com/2021/01/secure-instant-messengers/
#instantmessengers #telegram #signal #whatsapp #privacy
In today’s world of everyone wanting a slice of one’s personal information, users become more and more concerned about the privacy. The WhatsApp/Facebook integration raised an additional concern, considering that Facebook-owned Messenger requests the largest number of invasive permissions among all commonly used messengers. Data privacy and security concerns are mounting like a snowball. 2020 brought multiple data breach incidents from popular blogging resources from LiveJournal whose users’ data was breached and leaked to the darknet to financial institutions like Postbank with 12M exposed credit cards, hospitality giants as Mariott with 383 million records compromised or even Microsoft customers who also suffered from privacy-related issues.
👉 https://blog.elcomsoft.com/2021/01/secure-instant-messengers/
#instantmessengers #telegram #signal #whatsapp #privacy
End-to-End Encryption in Apple iCloud, Google and Microsoft Accounts
The proliferation of always connected, increasingly smart devices had led to a dramatic increase in the amount of highly sensitive information stored in manufacturers’ cloud accounts. Apple, Google, and Microsoft are the three major cloud providers who also develop their own hardware and OS ecosystems. In this report, we’ll see how these companies protect their users’ highly sensitive information compared to each other.
👉 https://blog.elcomsoft.com/2021/01/end-to-end-encryption-in-apple-icloud-google-and-microsoft-accounts/
#e2ee #icloud #google #microsoftaccount #apple #cloudsecurity #datasecurity
The proliferation of always connected, increasingly smart devices had led to a dramatic increase in the amount of highly sensitive information stored in manufacturers’ cloud accounts. Apple, Google, and Microsoft are the three major cloud providers who also develop their own hardware and OS ecosystems. In this report, we’ll see how these companies protect their users’ highly sensitive information compared to each other.
👉 https://blog.elcomsoft.com/2021/01/end-to-end-encryption-in-apple-icloud-google-and-microsoft-accounts/
#e2ee #icloud #google #microsoftaccount #apple #cloudsecurity #datasecurity
NAS Forensics: Synology, ASUSTOR, QNAP, TerraMaster and Thecus Encryption Compared
More than a year ago, we started researching the available encryption options in off the shelf network attached storage devices. We started with Synology devices, followed by Asustor, TerraMaster, Thecus, and finally Qnap. The manufacturers exhibit vastly different approaches to data protection, with different limitations, security implications and vulnerabilities. Today we are publishing the aggregate results of our analysis.
👉 https://blog.elcomsoft.com/2021/02/nas-forensics-synology-asustor-qnap-terramaster-and-thecus-encryption-compared/
#asustor #nas #digitalforensics #qnap #synology #terramaster #thecus #encryption
More than a year ago, we started researching the available encryption options in off the shelf network attached storage devices. We started with Synology devices, followed by Asustor, TerraMaster, Thecus, and finally Qnap. The manufacturers exhibit vastly different approaches to data protection, with different limitations, security implications and vulnerabilities. Today we are publishing the aggregate results of our analysis.
👉 https://blog.elcomsoft.com/2021/02/nas-forensics-synology-asustor-qnap-terramaster-and-thecus-encryption-compared/
#asustor #nas #digitalforensics #qnap #synology #terramaster #thecus #encryption