Elcomsoft Phone Viewer 5.31 update previews OneDrive deleted files metadata
Elcomsoft Phone Viewer gains the ability to preview metadata for files deleted from OneDrive prior to restoring the files. In addition, the update fixes the issue with Skype attachments.
👉 https://www.elcomsoft.com/news/790.html
#onedrive #phoneviewer #mobileforensics
Elcomsoft Phone Viewer gains the ability to preview metadata for files deleted from OneDrive prior to restoring the files. In addition, the update fixes the issue with Skype attachments.
👉 https://www.elcomsoft.com/news/790.html
#onedrive #phoneviewer #mobileforensics
iOS Forensic Toolkit 7.02 simplifies macOS installations, fixes corrupted file system extraction
Elcomsoft iOS Forensic Toolkit 7.02 is a minor update making it easier to install the tool on macOS computers and introducing a new agent extraction option to fix the extraction of corrupted file systems.
👉 https://www.elcomsoft.com/news/791.html
#ios #mobileforensics #macOS #filesystem
Elcomsoft iOS Forensic Toolkit 7.02 is a minor update making it easier to install the tool on macOS computers and introducing a new agent extraction option to fix the extraction of corrupted file systems.
👉 https://www.elcomsoft.com/news/791.html
#ios #mobileforensics #macOS #filesystem
Updated Elcomsoft iOS Forensic Toolkit Simplifies macOS Installs, Fixes Corrupted File System Extraction
While we are still working on the new version of Elcomsoft iOS Forensic Toolkit featuring forensically sound and nearly 100% compatible checkm8 extraction, an intermediate update is available with two minor yet important improvements. The update makes it easier to install the tool on macOS computers, and introduces a new agent extraction option.
👉 https://blog.elcomsoft.com/2021/07/updated-elcomsoft-ios-forensic-toolkit-simplifies-macos-installs-fixes-corrupted-file-system-extraction/
#ios #mobileforensics #macOS #filesystem
While we are still working on the new version of Elcomsoft iOS Forensic Toolkit featuring forensically sound and nearly 100% compatible checkm8 extraction, an intermediate update is available with two minor yet important improvements. The update makes it easier to install the tool on macOS computers, and introduces a new agent extraction option.
👉 https://blog.elcomsoft.com/2021/07/updated-elcomsoft-ios-forensic-toolkit-simplifies-macos-installs-fixes-corrupted-file-system-extraction/
#ios #mobileforensics #macOS #filesystem
iOS Privacy Protection Tools: Encrypted DNS, iOS 15 Private Relay, Proxy, VPN and TOR
Protecting one’s online privacy is becoming increasingly more important. With ISPs selling their customers’ usage data left and right, and various apps, mail and Web trackers contributing to the pool of “anonymized” data, de-anonimyzation becomes possible with big data analysis. This was clearly demonstrated with the recent event.
Apple did an attempt protecting their users’ location by introducing approximate locations in iOS 14. That change alone makes analyzing aggregate data from iPhone users more difficult but not impossible. In this publication, we compare the tools to protect one’s privacy online while using Apple iOS devices and desktop computers by making one’s browsing activities inaccessible to the middleman.
👉 https://blog.elcomsoft.com/2021/07/ios-privacy-protection-tools-encrypted-dns-ios-15-private-relay-proxy-vpn-and-tor/
#ios #vpn #privacy
Protecting one’s online privacy is becoming increasingly more important. With ISPs selling their customers’ usage data left and right, and various apps, mail and Web trackers contributing to the pool of “anonymized” data, de-anonimyzation becomes possible with big data analysis. This was clearly demonstrated with the recent event.
Apple did an attempt protecting their users’ location by introducing approximate locations in iOS 14. That change alone makes analyzing aggregate data from iPhone users more difficult but not impossible. In this publication, we compare the tools to protect one’s privacy online while using Apple iOS devices and desktop computers by making one’s browsing activities inaccessible to the middleman.
👉 https://blog.elcomsoft.com/2021/07/ios-privacy-protection-tools-encrypted-dns-ios-15-private-relay-proxy-vpn-and-tor/
#ios #vpn #privacy
Apple Watch Forensics: The Adapters
How do you extract an Apple Watch? While several methods are available, none of them will work if you want to access the device directly without an adapter. There are several different options available on the market, some of them costing north of $200. We tested a large number of such adapters. How do they stand to the marketing claims? In this article, I will share my experience with these adapters.
👉 https://blog.elcomsoft.com/2021/08/apple-watch-forensics-the-adapters/
#applewatch #mobileforensics #dfir #iosforensictoolkit
How do you extract an Apple Watch? While several methods are available, none of them will work if you want to access the device directly without an adapter. There are several different options available on the market, some of them costing north of $200. We tested a large number of such adapters. How do they stand to the marketing claims? In this article, I will share my experience with these adapters.
👉 https://blog.elcomsoft.com/2021/08/apple-watch-forensics-the-adapters/
#applewatch #mobileforensics #dfir #iosforensictoolkit
NAS Forensics: TrueNAS Encryption Overview
Established NAS manufacturers often offer some kind of encryption to their users. While anyone can use “military-grade AES-256 encryption”, the implementation details vary greatly. Synology, Asustor, and TerraMaster implement folder-based encryption, while QNAP, Thecus, and Asustor (MyAcrhive) employ full-disk encryption; the full comparison is available here. In this article, we’ll have a look at encryption methods used in TrueNAS, a system commonly used by computer enthusiasts for building custom NAS servers.
👉https://blog.elcomsoft.com/2021/08/nas-forensics-truenas-encryption-overview/
#nas #truenas #encryption
Established NAS manufacturers often offer some kind of encryption to their users. While anyone can use “military-grade AES-256 encryption”, the implementation details vary greatly. Synology, Asustor, and TerraMaster implement folder-based encryption, while QNAP, Thecus, and Asustor (MyAcrhive) employ full-disk encryption; the full comparison is available here. In this article, we’ll have a look at encryption methods used in TrueNAS, a system commonly used by computer enthusiasts for building custom NAS servers.
👉https://blog.elcomsoft.com/2021/08/nas-forensics-truenas-encryption-overview/
#nas #truenas #encryption
iOS 15 Forensic Implications: Temporary iCloud Backups
One of the main problems of iCloud forensics (unknown account passwords aside) is the sporadic nature of cloud backups. Experts often find out that a given user either does not have device backups in their iCloud account at all, or only has a very old backup. This happens primarily because of Apple’s policy of only granting 5GB of storage to the users of the free tier. While users can purchase additional storage for mere 99 cents a months, very few do so. iCloud Photos, downloads and other data quickly fill up the allotted storage space, leaving no space for a fresh cloud backup.
👉 https://blog.elcomsoft.com/2021/08/ios-15-forensic-implications-temporary-icloud-backups/
#ios #mobileforensics #icloud #cloudforensics #iphone
One of the main problems of iCloud forensics (unknown account passwords aside) is the sporadic nature of cloud backups. Experts often find out that a given user either does not have device backups in their iCloud account at all, or only has a very old backup. This happens primarily because of Apple’s policy of only granting 5GB of storage to the users of the free tier. While users can purchase additional storage for mere 99 cents a months, very few do so. iCloud Photos, downloads and other data quickly fill up the allotted storage space, leaving no space for a fresh cloud backup.
👉 https://blog.elcomsoft.com/2021/08/ios-15-forensic-implications-temporary-icloud-backups/
#ios #mobileforensics #icloud #cloudforensics #iphone
Instant Messengers: Authentication Methods and Instant Password Extraction
iMessage, Hangouts, Skype, Telegram, Signal, WhatsApp are familiar, while PalTalk, Pigin, Psi Jabber client, Gadu-Gadu, Gajim, Trillian, BigAnt or Brosix are relatively little known. The tools from the first group are not only more popular but infinitely more secure compared to the tools from the second group. In this publication we’ll review the authentication methods used by the various instant messengers, and attempt to extract a password to the user’s account.
👉 https://blog.elcomsoft.com/2021/08/instant-messengers-authentication-methods-and-instant-password-extraction/
#mobileforensics #messengers
iMessage, Hangouts, Skype, Telegram, Signal, WhatsApp are familiar, while PalTalk, Pigin, Psi Jabber client, Gadu-Gadu, Gajim, Trillian, BigAnt or Brosix are relatively little known. The tools from the first group are not only more popular but infinitely more secure compared to the tools from the second group. In this publication we’ll review the authentication methods used by the various instant messengers, and attempt to extract a password to the user’s account.
👉 https://blog.elcomsoft.com/2021/08/instant-messengers-authentication-methods-and-instant-password-extraction/
#mobileforensics #messengers
The iPhone Upgrade: How to Back Up and Restore iOS Devices Without Losing Data
In just a few weeks, the new iPhone range will be released. Millions of users all over the world will upgrade, migrating their data from old devices. While Apple has an ingenious backup system in place, it has quite a few things behind the scenes that can make the migration not go as smooth as planned. How do you do the migration properly not to lose anything?
👉 https://blog.elcomsoft.com/2021/08/the-iphone-upgrade-how-to-back-up-and-restore-ios-devices-without-losing-data/
#iphone #mobileforensics #backup
In just a few weeks, the new iPhone range will be released. Millions of users all over the world will upgrade, migrating their data from old devices. While Apple has an ingenious backup system in place, it has quite a few things behind the scenes that can make the migration not go as smooth as planned. How do you do the migration properly not to lose anything?
👉 https://blog.elcomsoft.com/2021/08/the-iphone-upgrade-how-to-back-up-and-restore-ios-devices-without-losing-data/
#iphone #mobileforensics #backup
Elcomsoft iOS Forensic Toolkit 7.03 simplifies agent sideloading in macOS, improves support for legacy devices
In this build, we have made significant improvements to the handling of legacy (32-bit) iOS devices such as the iPhone 5 and 5c. Most importantly, we have nailed all the iPhone 5c physical acquisition issues. This model features a slightly different encryption method compared to that used in the iPhone 5. In addition, we’ve encountered some rare cases where the keychain header manifests a non-standard version number, and so iOS Forensic Toolkit would fail to decrypt the keychain. This has been fixed as well.
Next, we have improved jailbreak detection and handling for legacy models, which is particularly relevant for the iPhone 4s extraction. Since the iPhone 4s is still missing a working checkm8 implementation, the extraction options are currently limited to jailbreaking with subsequent file system and keychain extraction.
👉 https://www.elcomsoft.com/news/792.html
#ios #mobileforensics #macOS
In this build, we have made significant improvements to the handling of legacy (32-bit) iOS devices such as the iPhone 5 and 5c. Most importantly, we have nailed all the iPhone 5c physical acquisition issues. This model features a slightly different encryption method compared to that used in the iPhone 5. In addition, we’ve encountered some rare cases where the keychain header manifests a non-standard version number, and so iOS Forensic Toolkit would fail to decrypt the keychain. This has been fixed as well.
Next, we have improved jailbreak detection and handling for legacy models, which is particularly relevant for the iPhone 4s extraction. Since the iPhone 4s is still missing a working checkm8 implementation, the extraction options are currently limited to jailbreaking with subsequent file system and keychain extraction.
👉 https://www.elcomsoft.com/news/792.html
#ios #mobileforensics #macOS
Forensic Implications of Sleep, Hybrid Sleep, Hibernation, and Fast Startup in Windows 10
When analyzing connected computers, one may be tempted to pull the plug and bring the PC to the lab for in-depth research. This strategy carries risks that may overweigh the benefits. In this article we’ll discuss what exactly you may be losing when pulling the plug.
👉 https://blog.elcomsoft.com/2021/09/forensic-implications-of-sleep-hybrid-sleep-hibernation-and-fast-startup-in-windows-10/
#windows10 #bitlocker #diskencryption #truecrypt
When analyzing connected computers, one may be tempted to pull the plug and bring the PC to the lab for in-depth research. This strategy carries risks that may overweigh the benefits. In this article we’ll discuss what exactly you may be losing when pulling the plug.
👉 https://blog.elcomsoft.com/2021/09/forensic-implications-of-sleep-hybrid-sleep-hibernation-and-fast-startup-in-windows-10/
#windows10 #bitlocker #diskencryption #truecrypt
How to Put an iOS Device with Broken Buttons in DFU Mode
Switching the iPhone into DFU mode is frequently required during the investigation, especially for older devices that are susceptible to checkm8 exploit. For newer devices that are locked with an unknown passcode or disabled one can still learn something about the device through DFU (in particular, the bootloader version, which points to the version of iOS installed on the device). However, switching to DFU requires a sequence of key presses on the device with precise timings. If the device is damaged and one or more keys are not working correctly, entering DFU may be difficult or impossible. In this guide, we offer an alternative.
👉 https://blog.elcomsoft.com/2021/09/how-to-put-an-ios-device-with-broken-buttons-in-dfu-mode/
#apple #dfir #iphone
Switching the iPhone into DFU mode is frequently required during the investigation, especially for older devices that are susceptible to checkm8 exploit. For newer devices that are locked with an unknown passcode or disabled one can still learn something about the device through DFU (in particular, the bootloader version, which points to the version of iOS installed on the device). However, switching to DFU requires a sequence of key presses on the device with precise timings. If the device is damaged and one or more keys are not working correctly, entering DFU may be difficult or impossible. In this guide, we offer an alternative.
👉 https://blog.elcomsoft.com/2021/09/how-to-put-an-ios-device-with-broken-buttons-in-dfu-mode/
#apple #dfir #iphone
Cloud Forensics: the New Reality
The majority of mobile devices today are encrypted throughout, making extractions difficult or even impossible for major platforms. Traditional attack vectors are becoming a thing of the past with encryption being moved into dedicated security chips, and encryption keys generated on first unlock based on the user’s screen lock passwords. Cloud forensics is a great alternative, often returning as much or even more data compared to what is stored on the device itself.
👉 https://blog.elcomsoft.com/2021/09/cloud-forensics-the-new-reality/
#icloud #iphone #cloudforensics #iossecurity #mobileforensics
The majority of mobile devices today are encrypted throughout, making extractions difficult or even impossible for major platforms. Traditional attack vectors are becoming a thing of the past with encryption being moved into dedicated security chips, and encryption keys generated on first unlock based on the user’s screen lock passwords. Cloud forensics is a great alternative, often returning as much or even more data compared to what is stored on the device itself.
👉 https://blog.elcomsoft.com/2021/09/cloud-forensics-the-new-reality/
#icloud #iphone #cloudforensics #iossecurity #mobileforensics
ElcomSoft Phone Breaker 10 adds device-based iCloud authentication
Elcomsoft Phone Breaker 10 adds the ability to use a trusted iOS device to authenticate iCloud extraction. Every type of data becomes extractable including end-to-end encrypted data, and no password is required.
👉 https://www.elcomsoft.com/news/795.html
#ios #dfir #cloudforensics #2fa #cloudsecurity
Elcomsoft Phone Breaker 10 adds the ability to use a trusted iOS device to authenticate iCloud extraction. Every type of data becomes extractable including end-to-end encrypted data, and no password is required.
👉 https://www.elcomsoft.com/news/795.html
#ios #dfir #cloudforensics #2fa #cloudsecurity
iCloud Extractions Without Passwords and Tokens: When a Trusted Device is Enough
A lot of folks (and even some law enforcement experts) are looking for a one-click solution for mobile extractions and data decryption. Unfortunately, in today’s day and age there are no ‘silver bullet’ solutions. In the days of high-tech mobile devices and end-to-end encryption one must clearly understand the available options, and plan their actions accordingly. The time of ‘snake oil’ exploits is long gone. The modern world of mobile forensics is complex, and your actions will depend on a lot of factors. Today, we’re going to make your life a notch more complex by introducing a new iCloud authentication option you’ve never heard of before.
👉 https://blog.elcomsoft.com/2021/10/icloud-extractions-without-passwords-and-tokens-when-a-trusted-device-is-enough/
#ios #icloud #2fa #dfir #cloudsecurity #cloudforensics
A lot of folks (and even some law enforcement experts) are looking for a one-click solution for mobile extractions and data decryption. Unfortunately, in today’s day and age there are no ‘silver bullet’ solutions. In the days of high-tech mobile devices and end-to-end encryption one must clearly understand the available options, and plan their actions accordingly. The time of ‘snake oil’ exploits is long gone. The modern world of mobile forensics is complex, and your actions will depend on a lot of factors. Today, we’re going to make your life a notch more complex by introducing a new iCloud authentication option you’ve never heard of before.
👉 https://blog.elcomsoft.com/2021/10/icloud-extractions-without-passwords-and-tokens-when-a-trusted-device-is-enough/
#ios #icloud #2fa #dfir #cloudsecurity #cloudforensics
Using a Trusted Device for iCloud Authentication
To perform an iCloud extraction, a valid password is generally required, followed by solving the two-factor authentication challenge. If the user’s iPhone is everything that you have, the iCloud password may not be available. By using a trusted device, one can gain unrestricted access to everything that is stored in the user’s iCloud account. This article gives a comprehensive walkthrough on this alternative authentication method.
👉 https://blog.elcomsoft.com/2021/10/using-a-trusted-device-for-icloud-authentication/
#dfir #ios #cloudsecurity #cloudforensics
To perform an iCloud extraction, a valid password is generally required, followed by solving the two-factor authentication challenge. If the user’s iPhone is everything that you have, the iCloud password may not be available. By using a trusted device, one can gain unrestricted access to everything that is stored in the user’s iCloud account. This article gives a comprehensive walkthrough on this alternative authentication method.
👉 https://blog.elcomsoft.com/2021/10/using-a-trusted-device-for-icloud-authentication/
#dfir #ios #cloudsecurity #cloudforensics
Protecting Linux and NAS Devices: LUKS, eCryptFS and Native ZFS Encryption Compared
Many Linux distributions including those used in off the shelf Network Attached Storage (NAS) devices have the ability to protect users’ data with one or more types of encryption. Full-disk and folder-based encryption options are commonly available, each with its own set of pros and contras. The new native ZFS encryption made available in OpenZFS 2.0 is designed to combine the benefits of full-disk and folder-based encryption without the associated drawbacks. In this article, we’ll compare the strengths and weaknesses of LUKS, eCryptFS and ZFS encryption.
👉 https://blog.elcomsoft.com/2021/11/protecting-linux-and-nas-devices-luks-ecryptfs-and-native-zfs-encryption-compared/
#encryption #linux #luks #ecryptfs #nas #zfs
Many Linux distributions including those used in off the shelf Network Attached Storage (NAS) devices have the ability to protect users’ data with one or more types of encryption. Full-disk and folder-based encryption options are commonly available, each with its own set of pros and contras. The new native ZFS encryption made available in OpenZFS 2.0 is designed to combine the benefits of full-disk and folder-based encryption without the associated drawbacks. In this article, we’ll compare the strengths and weaknesses of LUKS, eCryptFS and ZFS encryption.
👉 https://blog.elcomsoft.com/2021/11/protecting-linux-and-nas-devices-luks-ecryptfs-and-native-zfs-encryption-compared/
#encryption #linux #luks #ecryptfs #nas #zfs