Digital Triage Forensics: Write-Blocking, Verifiable Disk Imaging
When accessing a locked system during an in-field investigation, speed is often the most important factor. However, maintaining digital chain of custody is just as if not more important in order to produce court admissible evidence. We are introducing new features in Elcomsoft System Recovery, our forensic triage tool, to help establish and maintain digital chain of custody throughout the investigation.
👉 https://blog.elcomsoft.com/2021/11/digital-triage-forensics-write-blocking-verifiable-disk-imaging/
#passwords #dfir #cybersecurity #datasecurity #passwordrecovery #digitalforensics
When accessing a locked system during an in-field investigation, speed is often the most important factor. However, maintaining digital chain of custody is just as if not more important in order to produce court admissible evidence. We are introducing new features in Elcomsoft System Recovery, our forensic triage tool, to help establish and maintain digital chain of custody throughout the investigation.
👉 https://blog.elcomsoft.com/2021/11/digital-triage-forensics-write-blocking-verifiable-disk-imaging/
#passwords #dfir #cybersecurity #datasecurity #passwordrecovery #digitalforensics
The Five Ways to Recover iPhone Deleted Data
iOS security model offers very are few possibilities to recover anything unless you have a backup, either local or one from the cloud. There are also tricks allowing to recover some bits and pieces even if you don’t. In this article we’ll talk about what you can and what you cannot recover in modern iOS devices.
Before we begin, I highly recommend reading our previous article aimed at demystifying bogus claims made by some unscrupulous vendors of data recovery tools: The iPhone Data Recovery Myth: What You Can and Cannot Recover. Below are the types of data you can actually recover.
👉 https://blog.elcomsoft.com/2021/11/the-five-ways-to-recover-iphone-deleted-data/
#ios #icloud #iphone #backup #syncedfiles #deletedrecords
iOS security model offers very are few possibilities to recover anything unless you have a backup, either local or one from the cloud. There are also tricks allowing to recover some bits and pieces even if you don’t. In this article we’ll talk about what you can and what you cannot recover in modern iOS devices.
Before we begin, I highly recommend reading our previous article aimed at demystifying bogus claims made by some unscrupulous vendors of data recovery tools: The iPhone Data Recovery Myth: What You Can and Cannot Recover. Below are the types of data you can actually recover.
👉 https://blog.elcomsoft.com/2021/11/the-five-ways-to-recover-iphone-deleted-data/
#ios #icloud #iphone #backup #syncedfiles #deletedrecords
Apple Watch Forensics: More on Adapters
If you are doing Apple Watch forensics, I’ve got some bad news for you. The latest model of Apple Watch, the Series 7, does not have a hidden diagnostics port anymore, which was replaced with a wireless 60.5GHz module (and the corresponding dock, which is nowhere to be found). What does that mean for the mobile forensics, and does it make the extraction more difficult? Let’s shed some light on it.
👉 https://blog.elcomsoft.com/2021/11/apple-watch-forensics-more-on-adapters/
#applewatch #ios #cloudsecurity #cloudforensics
If you are doing Apple Watch forensics, I’ve got some bad news for you. The latest model of Apple Watch, the Series 7, does not have a hidden diagnostics port anymore, which was replaced with a wireless 60.5GHz module (and the corresponding dock, which is nowhere to be found). What does that mean for the mobile forensics, and does it make the extraction more difficult? Let’s shed some light on it.
👉 https://blog.elcomsoft.com/2021/11/apple-watch-forensics-more-on-adapters/
#applewatch #ios #cloudsecurity #cloudforensics
iPhone Acquisition Methods Compared
Our mobile acquisition tools, Elcomsoft iOS Forensic Toolkit and Elcomsoft Phone Breaker, support a number of different extraction options. While many of our readers know the differences between logical and physical acquisition in general better than most, there are some things in our software making the logical/physical dilemma somewhat different. In this article, we laid out the differences between the extraction methods as implemented in our tools.
👉 https://blog.elcomsoft.com/2021/11/iphone-acquisition-methods-compared/
#dfir #mobileforensics #checkm8
Our mobile acquisition tools, Elcomsoft iOS Forensic Toolkit and Elcomsoft Phone Breaker, support a number of different extraction options. While many of our readers know the differences between logical and physical acquisition in general better than most, there are some things in our software making the logical/physical dilemma somewhat different. In this article, we laid out the differences between the extraction methods as implemented in our tools.
👉 https://blog.elcomsoft.com/2021/11/iphone-acquisition-methods-compared/
#dfir #mobileforensics #checkm8
checkm8, checkra1n and USB hubs
If you ever used the checkra1n jailbreak or the checkm8 acquisition method available in some mobile forensic products like iOS Forensic Toolkit, you know that the trickiest parts of the process are the first two: entering DFU, and using the exploit itself. Even if you have the right cables and enough experience, sometimes you may still bump into a weird issue or two. The device may not enter DFU whatever you do, or the exploit fails. How can you increase your success rate?
👉 https://blog.elcomsoft.com/2021/11/checkm8-checkra1n-and-usb-hubs/
#checkm8 #checkra1n #mobileforensics
If you ever used the checkra1n jailbreak or the checkm8 acquisition method available in some mobile forensic products like iOS Forensic Toolkit, you know that the trickiest parts of the process are the first two: entering DFU, and using the exploit itself. Even if you have the right cables and enough experience, sometimes you may still bump into a weird issue or two. The device may not enter DFU whatever you do, or the exploit fails. How can you increase your success rate?
👉 https://blog.elcomsoft.com/2021/11/checkm8-checkra1n-and-usb-hubs/
#checkm8 #checkra1n #mobileforensics
iOS Forensic Toolkit 8.0 beta 2 brings forensically-sound checkm8 extraction and iOS 15 support
The second beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac is released, bringing forensically sound checkm8 extraction to iOS 15 devices and delivering a host of under-the-hood improvements and enhancements.
👉 https://www.elcomsoft.com/news/797.html
#checkm8 #ios15 #dfir #mobileforensics
The second beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac is released, bringing forensically sound checkm8 extraction to iOS 15 devices and delivering a host of under-the-hood improvements and enhancements.
👉 https://www.elcomsoft.com/news/797.html
#checkm8 #ios15 #dfir #mobileforensics
How to Use iOS Forensic Toolkit 8.0 b2 to Perform Forensically Sound Extraction of iPhone 5s, 6, 6s and SE
The second beta of iOS Forensic Toolkit 8.0 has arrived, offering repeatable, verifiable extraction for a limited range of iOS devices. The new release introduces a brand-new user interface, which differs significantly from the selection-driven console we’ve been using for the past several years. This article describes the new workflow for performing forensically sound extractions with iOS Forensic Toolkit 8.0 beta2.
👉 https://blog.elcomsoft.com/2021/11/how-to-use-ios-forensic-toolkit-8-0-b2-to-perform-forensically-sound-extraction-of-iphone-5s-6-6s-and-se/
#ios15 #checkm8 #dfir #mobileforensics
The second beta of iOS Forensic Toolkit 8.0 has arrived, offering repeatable, verifiable extraction for a limited range of iOS devices. The new release introduces a brand-new user interface, which differs significantly from the selection-driven console we’ve been using for the past several years. This article describes the new workflow for performing forensically sound extractions with iOS Forensic Toolkit 8.0 beta2.
👉 https://blog.elcomsoft.com/2021/11/how-to-use-ios-forensic-toolkit-8-0-b2-to-perform-forensically-sound-extraction-of-iphone-5s-6-6s-and-se/
#ios15 #checkm8 #dfir #mobileforensics
Forensically Sound Extraction for iPhone 5s, 6, 6s and SE
Half a year ago, we started a closed beta-testing of a revolutionary new build of iOS Forensic Toolkit. Using the checkm8 exploit, the first beta delivered forensically sound file system extraction for a large number of Apple devices. Today, we are rolling out the new, significantly improved second beta of the tool that delivers repeatable, forensically sound extractions based on the checkm8 exploit.
👉 https://blog.elcomsoft.com/2021/11/forensically-sound-extraction-for-iphone-5s-6-6s-and-se/
#ios15 #checkm8 #mobileforensics #dfi
Half a year ago, we started a closed beta-testing of a revolutionary new build of iOS Forensic Toolkit. Using the checkm8 exploit, the first beta delivered forensically sound file system extraction for a large number of Apple devices. Today, we are rolling out the new, significantly improved second beta of the tool that delivers repeatable, forensically sound extractions based on the checkm8 exploit.
👉 https://blog.elcomsoft.com/2021/11/forensically-sound-extraction-for-iphone-5s-6-6s-and-se/
#ios15 #checkm8 #mobileforensics #dfi
Worthless Security Practices
Many security practices still widely accepted today are things of the past. Many of them made sense at the time of short passwords and unrestricted access to workplaces, while some were learned from TV shows with “Russian hackers” breaking Pentagon. In this article we’ll sort it out.
👉 https://blog.elcomsoft.com/2021/12/worthless-security-practices/
#passwords #itsecurity
Many security practices still widely accepted today are things of the past. Many of them made sense at the time of short passwords and unrestricted access to workplaces, while some were learned from TV shows with “Russian hackers” breaking Pentagon. In this article we’ll sort it out.
👉 https://blog.elcomsoft.com/2021/12/worthless-security-practices/
#passwords #itsecurity
Elcomsoft Explorer for WhatsApp 2.80 improves compatibility and fixes bugs
Elcomsoft Explorer for WhatsApp 2.80 fixes the ability to download and decrypt WhatsApp backups created by the latest versions of the app and stored in the user’s Google Account. In addition, the new server-based authentication and crypt14 encrypted backups are now supported.
👉 https://www.elcomsoft.com/news/798.html
#exwa #whatsapp #crypt14
Elcomsoft Explorer for WhatsApp 2.80 fixes the ability to download and decrypt WhatsApp backups created by the latest versions of the app and stored in the user’s Google Account. In addition, the new server-based authentication and crypt14 encrypted backups are now supported.
👉 https://www.elcomsoft.com/news/798.html
#exwa #whatsapp #crypt14
WhatsApp Explorer: End-to-End Encrypted Backups and Compatibility Improvements
WhatsApp is the fastest growing instant messenger app. With over 2 billion monthly users, WhatsApp keeps the crown of the most popular instant messaging tool in the Western hemisphere. The recent introduction of end-to-end encrypted backups and the change of Google’s authentication protocol broke things temporarily for EXWA users, but now everything is back to normal. Learn how Elcomsoft Explorer for WhatsApp can download and decrypt encrypted WhatsApp communication histories from Google Drive and Apple iCloud!
👉 https://blog.elcomsoft.com/2021/12/whatsapp-explorer-end-to-end-encrypted-backups-and-compatibility-improvements/
#exwa #whatsapp #crypt14
WhatsApp is the fastest growing instant messenger app. With over 2 billion monthly users, WhatsApp keeps the crown of the most popular instant messaging tool in the Western hemisphere. The recent introduction of end-to-end encrypted backups and the change of Google’s authentication protocol broke things temporarily for EXWA users, but now everything is back to normal. Learn how Elcomsoft Explorer for WhatsApp can download and decrypt encrypted WhatsApp communication histories from Google Drive and Apple iCloud!
👉 https://blog.elcomsoft.com/2021/12/whatsapp-explorer-end-to-end-encrypted-backups-and-compatibility-improvements/
#exwa #whatsapp #crypt14
Advanced Office Password Recovery: guaranteed recovery of legacy DOC/XLS documents
We updated Advanced Office Password Recovery (AOPR) with guaranteed recovery of encrypted .doc and .xls files saved by legacy and modern Microsoft Office tools in Office 97/2000 compatibility mode. For these documents, we target the 40-bit encryption key instead of the password.
👉 https://www.elcomsoft.com/news/799.html
Microsoft Office 40-bit Encryption and Thunder Tables in Advanced Office Password Recovery
Before the end of this year, we are releasing one last update. Advanced Office Password Recovery can now break 40-bit encryption in Microsoft Office documents, and gains support for Thunder Tables. What are Thunder Tables exactly, and is 40-bit encryption still relevant? Read along to find out.
📖 https://blog.elcomsoft.com/2021/12/microsoft-office-40-bit-encryption-and-thunder-tables-in-advanced-office-password-recovery/
#officefiles #microsoft #excel #word #password #aopr #thundertables
We updated Advanced Office Password Recovery (AOPR) with guaranteed recovery of encrypted .doc and .xls files saved by legacy and modern Microsoft Office tools in Office 97/2000 compatibility mode. For these documents, we target the 40-bit encryption key instead of the password.
👉 https://www.elcomsoft.com/news/799.html
Microsoft Office 40-bit Encryption and Thunder Tables in Advanced Office Password Recovery
Before the end of this year, we are releasing one last update. Advanced Office Password Recovery can now break 40-bit encryption in Microsoft Office documents, and gains support for Thunder Tables. What are Thunder Tables exactly, and is 40-bit encryption still relevant? Read along to find out.
📖 https://blog.elcomsoft.com/2021/12/microsoft-office-40-bit-encryption-and-thunder-tables-in-advanced-office-password-recovery/
#officefiles #microsoft #excel #word #password #aopr #thundertables
iOS Forensic Toolkit 8.0 beta 3: forensically sound checkm8 extraction of iPhone 7, iOS 15.2 support
The third beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac is released, bringing forensically sound checkm8 extraction to iPhone 7 and 7 Plus devices running iOS 10 through 13, with limited support for iOS 14 and 15. For older devices, iOS 15.2 support is added. Finally, we implemented keychain decryption for supported devices running iOS 15.x.
👉 https://www.elcomsoft.com/news/800.html
#iphone #checkm8 #eift #mobileforensics #ios15
The third beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac is released, bringing forensically sound checkm8 extraction to iPhone 7 and 7 Plus devices running iOS 10 through 13, with limited support for iOS 14 and 15. For older devices, iOS 15.2 support is added. Finally, we implemented keychain decryption for supported devices running iOS 15.x.
👉 https://www.elcomsoft.com/news/800.html
#iphone #checkm8 #eift #mobileforensics #ios15
Checkm8 Based Extraction of iPhone 7 and iPhone 7 Plus
Today, we are adding forensically sound low-level checkm8 extraction of the iPhone 7 and 7 Plus to previously supported range of iPhone devices.
What is “forensically sound” extraction and how our extraction process differs from competing implementations?
Our solution delivers true forensically sound extraction of the iPhone file system, incl. the keychain. Since all occurs entirely in the device’s RAM, we never boot (and don’t even need) the operating system installed on the device. The result is reliable, verifiable and repeatable extraction. If you use iOS Forensic Toolkit to image the iPhone file system and repeat the extractions, you are guaranteed to get exactly the same result; the checksums of the two images will match.
Learn more about supported phone models, DFU mode and the keychain in our blog:
👉 https://blog.elcomsoft.com/2021/12/checkm8-based-extraction-of-iphone-7-and-iphone-7-plus/
#mobileforensics #forensicallysound #dfir
Today, we are adding forensically sound low-level checkm8 extraction of the iPhone 7 and 7 Plus to previously supported range of iPhone devices.
What is “forensically sound” extraction and how our extraction process differs from competing implementations?
Our solution delivers true forensically sound extraction of the iPhone file system, incl. the keychain. Since all occurs entirely in the device’s RAM, we never boot (and don’t even need) the operating system installed on the device. The result is reliable, verifiable and repeatable extraction. If you use iOS Forensic Toolkit to image the iPhone file system and repeat the extractions, you are guaranteed to get exactly the same result; the checksums of the two images will match.
Learn more about supported phone models, DFU mode and the keychain in our blog:
👉 https://blog.elcomsoft.com/2021/12/checkm8-based-extraction-of-iphone-7-and-iphone-7-plus/
#mobileforensics #forensicallysound #dfir
Elcomsoft Phone Breaker 10.1: bugfix and maintenance release
Elcomsoft Phone Breaker 10.1 fixes bugs and improves compatibility, adding support for macOS 12 Monterey and the ability to extract Apple Maps data from end-to-end encrypted containers.
👉 https://www.elcomsoft.com/news/801.html
#icloud #applemaps #monterey #cloudforensics #dfir #epb
Elcomsoft Phone Breaker 10.1 fixes bugs and improves compatibility, adding support for macOS 12 Monterey and the ability to extract Apple Maps data from end-to-end encrypted containers.
👉 https://www.elcomsoft.com/news/801.html
#icloud #applemaps #monterey #cloudforensics #dfir #epb
Digital Evidence in Encrypted Backups
Backups are the primary way to preserve data. On smartphones, backups are handled automatically by the OS. Windows lacks a convincing backup app; numerous third-party tools are available, some of which feature strong encryption. Computer backups may contain valuable evidence that can be useful during an investigation – if you can do something about the password.
👉 https://blog.elcomsoft.com/2021/12/digital-evidence-in-encrypted-backups/
#backup #password #encrypted
Backups are the primary way to preserve data. On smartphones, backups are handled automatically by the OS. Windows lacks a convincing backup app; numerous third-party tools are available, some of which feature strong encryption. Computer backups may contain valuable evidence that can be useful during an investigation – if you can do something about the password.
👉 https://blog.elcomsoft.com/2021/12/digital-evidence-in-encrypted-backups/
#backup #password #encrypted
Elcomsoft adds support for BestCrypt Volume Encryption 5
Elcomsoft updates its range of solutions for distributed, hardware-accelerated password recovery and data decryption, adding support for yet another popular full disk encryption product: BestCrypt Volume Encryption.
👉 https://www.elcomsoft.com/news/802.html
#bestcrypt #encryption #edpr #efdd #esr
Elcomsoft updates its range of solutions for distributed, hardware-accelerated password recovery and data decryption, adding support for yet another popular full disk encryption product: BestCrypt Volume Encryption.
👉 https://www.elcomsoft.com/news/802.html
#bestcrypt #encryption #edpr #efdd #esr
Season’s Greetings and 2021 in Review
The new year is just around the corner, and so it’s the right time to review our achievements in 2021. We’ve done plenty of researching, developing and updating, and posted a great deal of content in our blog. Let’s run through the most exciting developments of the year!
🎄☃️ Here's a quick summary of our achievements and product updates over the course of the year: https://blog.elcomsoft.com/2021/12/seasons-greetings-and-2021-in-review/
#happynewyear #review
The new year is just around the corner, and so it’s the right time to review our achievements in 2021. We’ve done plenty of researching, developing and updating, and posted a great deal of content in our blog. Let’s run through the most exciting developments of the year!
🎄☃️ Here's a quick summary of our achievements and product updates over the course of the year: https://blog.elcomsoft.com/2021/12/seasons-greetings-and-2021-in-review/
#happynewyear #review
Targeting Backup Encryption: Acronis, Macrium, and Veeam
Windows backups are rarely targeted during investigations, yet they can be the only available source of evidence if the suspect’s computer is locked and encrypted. There are multiple third-part backup tools for Windows, and most of them have password protection as an option. We are adding the ability to break password protection of popular backup tools: Acronis True Image, Macrium Reflect, and Veeam.
👉🏻 https://blog.elcomsoft.com/2022/01/targeting-backup-encryption-acronis-macrium-and-veeam/
#encryption
Windows backups are rarely targeted during investigations, yet they can be the only available source of evidence if the suspect’s computer is locked and encrypted. There are multiple third-part backup tools for Windows, and most of them have password protection as an option. We are adding the ability to break password protection of popular backup tools: Acronis True Image, Macrium Reflect, and Veeam.
👉🏻 https://blog.elcomsoft.com/2022/01/targeting-backup-encryption-acronis-macrium-and-veeam/
#encryption