Targeting Backup Encryption: Acronis, Macrium, and Veeam
Windows backups are rarely targeted during investigations, yet they can be the only available source of evidence if the suspect’s computer is locked and encrypted. There are multiple third-part backup tools for Windows, and most of them have password protection as an option. We are adding the ability to break password protection of popular backup tools: Acronis True Image, Macrium Reflect, and Veeam.
👉🏻 https://blog.elcomsoft.com/2022/01/targeting-backup-encryption-acronis-macrium-and-veeam/
#encryption
Windows backups are rarely targeted during investigations, yet they can be the only available source of evidence if the suspect’s computer is locked and encrypted. There are multiple third-part backup tools for Windows, and most of them have password protection as an option. We are adding the ability to break password protection of popular backup tools: Acronis True Image, Macrium Reflect, and Veeam.
👉🏻 https://blog.elcomsoft.com/2022/01/targeting-backup-encryption-acronis-macrium-and-veeam/
#encryption
iOS Forensic Toolkit 7.10 adds low-level extraction for iOS 14.4 through 14.8
Elcomsoft iOS Forensic Toolkit 7.10 brings the ability to perform low-level file system extraction for select iPhone models running iOS versions 14.4 through 14.8. The list of supported devices includes models of A11, A12, and A13 generations. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.
👉 https://www.elcomsoft.com/news/805.html
#iphone #ios14 #mobileforensics
Elcomsoft iOS Forensic Toolkit 7.10 brings the ability to perform low-level file system extraction for select iPhone models running iOS versions 14.4 through 14.8. The list of supported devices includes models of A11, A12, and A13 generations. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.
👉 https://www.elcomsoft.com/news/805.html
#iphone #ios14 #mobileforensics
Agent-based full file system and keychain extraction: now up to iOS 14.8 (incl.)
iOS Forensic Toolkit 7.10 brings low-level file system extraction support for a bunch of iOS versions. This includes the entire range of iPhone models based on the A11, A12, and A13 Bionic platforms running iOS 14.4 through 14.8.
Before this update, iOS Forensic Toolkit could perform low-level extraction of all iPhone models running iOS 9 through iOS 14.3 in a truly gapless fashion. With this update, we made it possible to perform full file system and keychain extraction of iOS 14.4-14.8 for select iPhone models.
👉 https://blog.elcomsoft.com/2022/01/agent-based-full-file-system-and-keychain-extraction-now-up-to-ios-14-8-incl/
#ios14 #iphone #dfir #eift
iOS Forensic Toolkit 7.10 brings low-level file system extraction support for a bunch of iOS versions. This includes the entire range of iPhone models based on the A11, A12, and A13 Bionic platforms running iOS 14.4 through 14.8.
Before this update, iOS Forensic Toolkit could perform low-level extraction of all iPhone models running iOS 9 through iOS 14.3 in a truly gapless fashion. With this update, we made it possible to perform full file system and keychain extraction of iOS 14.4-14.8 for select iPhone models.
👉 https://blog.elcomsoft.com/2022/01/agent-based-full-file-system-and-keychain-extraction-now-up-to-ios-14-8-incl/
#ios14 #iphone #dfir #eift
Elcomsoft iOS Forensic Toolkit 8.0 beta 4: forensically sound checkm8 extraction of iPhone 8, 8 Plus and iPhone X
The fourth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac introduces forensically sound checkm8 extraction of iPhone 8, 8 Plus, and iPhone X devices running iOS 11.0 through 15.3 (restrictions apply to iOS 14 and 15 extractions).
👉 https://www.elcomsoft.com/news/806.html
#iphone #eift #mobileforensics #dfir
The fourth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac introduces forensically sound checkm8 extraction of iPhone 8, 8 Plus, and iPhone X devices running iOS 11.0 through 15.3 (restrictions apply to iOS 14 and 15 extractions).
👉 https://www.elcomsoft.com/news/806.html
#iphone #eift #mobileforensics #dfir
iPhone X, DFU mode and checkm8
In order to use the checkm8-based acquisition, the device must be placed into DFU (Device Firmware Update) mode first, and this is the trickiest part of the process. There is no software way to enter DFU, so you have to do it manually. This article describes how to do it properly for the iPhone 8, iPhone 8 Plus and iPhone X that are now supported by Elcomsoft iOS Forensic Toolkit.
👉 https://blog.elcomsoft.com/2022/02/iphone-x-dfu-mode-and-checkm8/
#dfir #DFU #mobileforensics #iphoneX #checkm8
In order to use the checkm8-based acquisition, the device must be placed into DFU (Device Firmware Update) mode first, and this is the trickiest part of the process. There is no software way to enter DFU, so you have to do it manually. This article describes how to do it properly for the iPhone 8, iPhone 8 Plus and iPhone X that are now supported by Elcomsoft iOS Forensic Toolkit.
👉 https://blog.elcomsoft.com/2022/02/iphone-x-dfu-mode-and-checkm8/
#dfir #DFU #mobileforensics #iphoneX #checkm8
checkm8 Extraction of iPhone 8, 8 Plus and iPhone X
Last month, we released the tool and published the guide on forensically sound extraction of the iPhone 7 generation of devices. Today, we have added support for the iPhone 8, 8 Plus, and iPhone X, making iOS Forensic Toolkit the first and only forensically sound iPhone extraction tool delivering repeatable and verifiable results for all 64-bit iPhone devices that can be exploited with checkm8. While the previous publication talks about the details on acquiring the iPhone 7, there are some things different when it comes to the last generation of checkm8-supported devices.
👉 https://blog.elcomsoft.com/2022/02/checkm8-extraction-of-iphone-8-8-plus-and-iphone-x/
#dfir #mobileforensics #checkm8 #eift #iphone8 #iphoneX
Last month, we released the tool and published the guide on forensically sound extraction of the iPhone 7 generation of devices. Today, we have added support for the iPhone 8, 8 Plus, and iPhone X, making iOS Forensic Toolkit the first and only forensically sound iPhone extraction tool delivering repeatable and verifiable results for all 64-bit iPhone devices that can be exploited with checkm8. While the previous publication talks about the details on acquiring the iPhone 7, there are some things different when it comes to the last generation of checkm8-supported devices.
👉 https://blog.elcomsoft.com/2022/02/checkm8-extraction-of-iphone-8-8-plus-and-iphone-x/
#dfir #mobileforensics #checkm8 #eift #iphone8 #iphoneX
Elcomsoft iOS Forensic Toolkit 8.0 beta 5: forensically sound checkm8 extraction of Apple Watch 3
The fifth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of Apple Watch Series 3. The low-level extraction helps access crucial evidence stored on the Watch without altering any of the data.
👉 https://www.elcomsoft.com/news/807.html
#eift #watchOS #ios15 #mobileforensics #dfir
The fifth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of Apple Watch Series 3. The low-level extraction helps access crucial evidence stored on the Watch without altering any of the data.
👉 https://www.elcomsoft.com/news/807.html
#eift #watchOS #ios15 #mobileforensics #dfir
checkm8 Extraction of Apple Watch Series 3
The fifth beta of iOS Forensic Toolkit 8 for Mac introduces forensically sound, checkm8-based extraction of Apple Watch Series 3. How to connect the watch to the computer, what data is available and how to apply the exploit? Check out this comprehensive guide!
👉 https://blog.elcomsoft.com/2022/02/checkm8-extraction-of-apple-watch-series-3/
#applewatch #watchOS #eift #mobileforensics #dfir
The fifth beta of iOS Forensic Toolkit 8 for Mac introduces forensically sound, checkm8-based extraction of Apple Watch Series 3. How to connect the watch to the computer, what data is available and how to apply the exploit? Check out this comprehensive guide!
👉 https://blog.elcomsoft.com/2022/02/checkm8-extraction-of-apple-watch-series-3/
#applewatch #watchOS #eift #mobileforensics #dfir
Apple Mobile Devices and iOS Acquisition Methods
Do you have to know which SoC a certain Apple device is based on? If you are working in mobile forensics, the answer is positive. Along with the version of iOS/watchOS/iPadOS, the SoC is one of the deciding factors that affects the data extraction paths available in each case. Read this article to better understand your options for each generation of Apple platforms.
👉 https://blog.elcomsoft.com/2022/02/apple-mobile-devices-and-ios-acquisition-methods/
#iphone #mobileforensics #dfir
Do you have to know which SoC a certain Apple device is based on? If you are working in mobile forensics, the answer is positive. Along with the version of iOS/watchOS/iPadOS, the SoC is one of the deciding factors that affects the data extraction paths available in each case. Read this article to better understand your options for each generation of Apple platforms.
👉 https://blog.elcomsoft.com/2022/02/apple-mobile-devices-and-ios-acquisition-methods/
#iphone #mobileforensics #dfir
Dude, Where Are My Messages?
Cloud backups are an invaluable source of information whether you download them from the user’s iCloud account or obtain directly from Apple. But why some iCloud backups miss essential bits and pieces of information such as text messages, particularly iMessages? The answer is “end-to-end encryption”, and there’s more to it than just backups.
👉 https://blog.elcomsoft.com/2022/02/dude-where-are-my-messages/
#sms #imessage #icloud #dfir #mobileforensics #phonebreaker
Cloud backups are an invaluable source of information whether you download them from the user’s iCloud account or obtain directly from Apple. But why some iCloud backups miss essential bits and pieces of information such as text messages, particularly iMessages? The answer is “end-to-end encryption”, and there’s more to it than just backups.
👉 https://blog.elcomsoft.com/2022/02/dude-where-are-my-messages/
#sms #imessage #icloud #dfir #mobileforensics #phonebreaker
GPU Acceleration On The Cheap: Using Affordable Video Cards to Break Passwords Faster
Most password protection methods rely on multiple rounds of hash iterations to slow down brute-force attacks. Even the fastest processors choke when trying to break a reasonably strong password. Video cards can be used to speed up the recovery with GPU acceleration, yet the GPU market is currently overheated, and most high-end video cards are severely overpriced. Today, we’ll test a bunch of low-end video cards and compare their price/performance ratio.
👉 https://blog.elcomsoft.com/2022/02/gpu-acceleration-on-the-cheap-using-affordable-video-cards-to-break-passwords-faster/
#amd #cuda #edpr #gpu #intel #passwordcracking #passwordrecovery
Most password protection methods rely on multiple rounds of hash iterations to slow down brute-force attacks. Even the fastest processors choke when trying to break a reasonably strong password. Video cards can be used to speed up the recovery with GPU acceleration, yet the GPU market is currently overheated, and most high-end video cards are severely overpriced. Today, we’ll test a bunch of low-end video cards and compare their price/performance ratio.
👉 https://blog.elcomsoft.com/2022/02/gpu-acceleration-on-the-cheap-using-affordable-video-cards-to-break-passwords-faster/
#amd #cuda #edpr #gpu #intel #passwordcracking #passwordrecovery
https://www.forbes.com/sites/thomasbrewster/2022/03/04/russians-escaping-putins-repression-urged-to-wipe-their-phones/
Assistance from both inside and outside the country is being offered to Russians in fear of phone searches. Vladimir Katalov, the Moscow-based owner of phone forensics company Elcomsoft, which works with law enforcement to compile data on criminal suspects, says he doesn’t ask what nationality anyone is, but he has noted an increase in the number of people asking how to keep their data safe in an “emergency situation, whatever that is.”
His main advice, he said, is for people to not have their main device with them if they think there’s a chance it will be seized. “Get a spare phone with minimum data, probably just contacts,” he said. “Even better, get a spare SIM card, as your main one could be used to get an authentication code to log into your account.”
Assistance from both inside and outside the country is being offered to Russians in fear of phone searches. Vladimir Katalov, the Moscow-based owner of phone forensics company Elcomsoft, which works with law enforcement to compile data on criminal suspects, says he doesn’t ask what nationality anyone is, but he has noted an increase in the number of people asking how to keep their data safe in an “emergency situation, whatever that is.”
His main advice, he said, is for people to not have their main device with them if they think there’s a chance it will be seized. “Get a spare phone with minimum data, probably just contacts,” he said. “Even better, get a spare SIM card, as your main one could be used to get an authentication code to log into your account.”
Forbes
Leaving Russia? Experts Say Wipe Your Phone Before You Go
Russians who are fleeing the country amid Putin’s war face border guards searching for hints of support for Ukraine.
Elcomsoft Phone Viewer 5.33 updated with Windows 11, macOS 12 Monterey support
Elcomsoft Phone Viewer for Mac 5.33 is updated to support macOS 12 Monterey, while the Windows edition of the tool adds support for Windows 11. In addition, the tool fixes several reported issues related to data export.
👉 https://www.elcomsoft.com/news/808.html
#dfir #mobileforensics #epv #windows11 #macos12
Elcomsoft Phone Viewer for Mac 5.33 is updated to support macOS 12 Monterey, while the Windows edition of the tool adds support for Windows 11. In addition, the tool fixes several reported issues related to data export.
👉 https://www.elcomsoft.com/news/808.html
#dfir #mobileforensics #epv #windows11 #macos12