Elcomsoft
547 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Worthless Security Practices

Many security practices still widely accepted today are things of the past. Many of them made sense at the time of short passwords and unrestricted access to workplaces, while some were learned from TV shows with “Russian hackers” breaking Pentagon. In this article we’ll sort it out.

👉 https://blog.elcomsoft.com/2021/12/worthless-security-practices/
#passwords #itsecurity
Elcomsoft Explorer for WhatsApp 2.80 improves compatibility and fixes bugs

Elcomsoft Explorer for WhatsApp 2.80 fixes the ability to download and decrypt WhatsApp backups created by the latest versions of the app and stored in the user’s Google Account. In addition, the new server-based authentication and crypt14 encrypted backups are now supported.

👉 https://www.elcomsoft.com/news/798.html

#exwa #whatsapp #crypt14
WhatsApp Explorer: End-to-End Encrypted Backups and Compatibility Improvements

WhatsApp is the fastest growing instant messenger app. With over 2 billion monthly users, WhatsApp keeps the crown of the most popular instant messaging tool in the Western hemisphere. The recent introduction of end-to-end encrypted backups and the change of Google’s authentication protocol broke things temporarily for EXWA users, but now everything is back to normal. Learn how Elcomsoft Explorer for WhatsApp can download and decrypt encrypted WhatsApp communication histories from Google Drive and Apple iCloud!

👉 https://blog.elcomsoft.com/2021/12/whatsapp-explorer-end-to-end-encrypted-backups-and-compatibility-improvements/

#exwa #whatsapp #crypt14
Advanced Office Password Recovery: guaranteed recovery of legacy DOC/XLS documents

We updated Advanced Office Password Recovery (AOPR) with guaranteed recovery of encrypted .doc and .xls files saved by legacy and modern Microsoft Office tools in Office 97/2000 compatibility mode. For these documents, we target the 40-bit encryption key instead of the password.

👉 https://www.elcomsoft.com/news/799.html

Microsoft Office 40-bit Encryption and Thunder Tables in Advanced Office Password Recovery

Before the end of this year, we are releasing one last update. Advanced Office Password Recovery can now break 40-bit encryption in Microsoft Office documents, and gains support for Thunder Tables. What are Thunder Tables exactly, and is 40-bit encryption still relevant? Read along to find out.

📖 https://blog.elcomsoft.com/2021/12/microsoft-office-40-bit-encryption-and-thunder-tables-in-advanced-office-password-recovery/

#officefiles #microsoft #excel #word #password #aopr #thundertables
iOS Forensic Toolkit 8.0 beta 3: forensically sound checkm8 extraction of iPhone 7, iOS 15.2 support

The third beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac is released, bringing forensically sound checkm8 extraction to iPhone 7 and 7 Plus devices running iOS 10 through 13, with limited support for iOS 14 and 15. For older devices, iOS 15.2 support is added. Finally, we implemented keychain decryption for supported devices running iOS 15.x.

👉 https://www.elcomsoft.com/news/800.html

#iphone #checkm8 #eift #mobileforensics #ios15
Checkm8 Based Extraction of iPhone 7 and iPhone 7 Plus

Today, we are adding forensically sound low-level checkm8 extraction of the iPhone 7 and 7 Plus to previously supported range of iPhone devices.

What is “forensically sound” extraction and how our extraction process differs from competing implementations?

Our solution delivers true forensically sound extraction of the iPhone file system, incl. the keychain. Since all occurs entirely in the device’s RAM, we never boot (and don’t even need) the operating system installed on the device. The result is reliable, verifiable and repeatable extraction. If you use iOS Forensic Toolkit to image the iPhone file system and repeat the extractions, you are guaranteed to get exactly the same result; the checksums of the two images will match.

Learn more about supported phone models, DFU mode and the keychain in our blog:

👉 https://blog.elcomsoft.com/2021/12/checkm8-based-extraction-of-iphone-7-and-iphone-7-plus/

#mobileforensics #forensicallysound #dfir
Elcomsoft Phone Breaker 10.1: bugfix and maintenance release

Elcomsoft Phone Breaker 10.1 fixes bugs and improves compatibility, adding support for macOS 12 Monterey and the ability to extract Apple Maps data from end-to-end encrypted containers.

👉 https://www.elcomsoft.com/news/801.html

#icloud #applemaps #monterey #cloudforensics #dfir #epb
Digital Evidence in Encrypted Backups

Backups are the primary way to preserve data. On smartphones, backups are handled automatically by the OS. Windows lacks a convincing backup app; numerous third-party tools are available, some of which feature strong encryption. Computer backups may contain valuable evidence that can be useful during an investigation – if you can do something about the password.

👉 https://blog.elcomsoft.com/2021/12/digital-evidence-in-encrypted-backups/

#backup #password #encrypted
Elcomsoft adds support for BestCrypt Volume Encryption 5

Elcomsoft updates its range of solutions for distributed, hardware-accelerated password recovery and data decryption, adding support for yet another popular full disk encryption product: BestCrypt Volume Encryption.

👉 https://www.elcomsoft.com/news/802.html

#bestcrypt #encryption #edpr #efdd #esr
Season’s Greetings and 2021 in Review

The new year is just around the corner, and so it’s the right time to review our achievements in 2021. We’ve done plenty of researching, developing and updating, and posted a great deal of content in our blog. Let’s run through the most exciting developments of the year!

🎄☃️ Here's a quick summary of our achievements and product updates over the course of the year: https://blog.elcomsoft.com/2021/12/seasons-greetings-and-2021-in-review/

#happynewyear #review
Targeting Backup Encryption: Acronis, Macrium, and Veeam

Windows backups are rarely targeted during investigations, yet they can be the only available source of evidence if the suspect’s computer is locked and encrypted. There are multiple third-part backup tools for Windows, and most of them have password protection as an option. We are adding the ability to break password protection of popular backup tools: Acronis True Image, Macrium Reflect, and Veeam.

👉🏻 https://blog.elcomsoft.com/2022/01/targeting-backup-encryption-acronis-macrium-and-veeam/

#encryption
iOS Forensic Toolkit 7.10 adds low-level extraction for iOS 14.4 through 14.8

Elcomsoft iOS Forensic Toolkit 7.10 brings the ability to perform low-level file system extraction for select iPhone models running iOS versions 14.4 through 14.8. The list of supported devices includes models of A11, A12, and A13 generations. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.

👉 https://www.elcomsoft.com/news/805.html

#iphone #ios14 #mobileforensics
Agent-based full file system and keychain extraction: now up to iOS 14.8 (incl.)

iOS Forensic Toolkit 7.10 brings low-level file system extraction support for a bunch of iOS versions. This includes the entire range of iPhone models based on the A11, A12, and A13 Bionic platforms running iOS 14.4 through 14.8.

Before this update, iOS Forensic Toolkit could perform low-level extraction of all iPhone models running iOS 9 through iOS 14.3 in a truly gapless fashion. With this update, we made it possible to perform full file system and keychain extraction of iOS 14.4-14.8 for select iPhone models.

👉 https://blog.elcomsoft.com/2022/01/agent-based-full-file-system-and-keychain-extraction-now-up-to-ios-14-8-incl/

#ios14 #iphone #dfir #eift
Elcomsoft iOS Forensic Toolkit 8.0 beta 4: forensically sound checkm8 extraction of iPhone 8, 8 Plus and iPhone X

The fourth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac introduces forensically sound checkm8 extraction of iPhone 8, 8 Plus, and iPhone X devices running iOS 11.0 through 15.3 (restrictions apply to iOS 14 and 15 extractions).

👉 https://www.elcomsoft.com/news/806.html

#iphone #eift #mobileforensics #dfir
iPhone X, DFU mode and checkm8

In order to use the checkm8-based acquisition, the device must be placed into DFU (Device Firmware Update) mode first, and this is the trickiest part of the process. There is no software way to enter DFU, so you have to do it manually. This article describes how to do it properly for the iPhone 8, iPhone 8 Plus and iPhone X that are now supported by Elcomsoft iOS Forensic Toolkit.

👉 https://blog.elcomsoft.com/2022/02/iphone-x-dfu-mode-and-checkm8/

#dfir #DFU #mobileforensics #iphoneX #checkm8
checkm8 Extraction of iPhone 8, 8 Plus and iPhone X

Last month, we released the tool and published the guide on forensically sound extraction of the iPhone 7 generation of devices. Today, we have added support for the iPhone 8, 8 Plus, and iPhone X, making iOS Forensic Toolkit the first and only forensically sound iPhone extraction tool delivering repeatable and verifiable results for all 64-bit iPhone devices that can be exploited with checkm8. While the previous publication talks about the details on acquiring the iPhone 7, there are some things different when it comes to the last generation of checkm8-supported devices.

👉 https://blog.elcomsoft.com/2022/02/checkm8-extraction-of-iphone-8-8-plus-and-iphone-x/

#dfir #mobileforensics #checkm8 #eift #iphone8 #iphoneX