Elcomsoft
547 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
checkm8 Extraction of Apple Watch Series 3

The fifth beta of iOS Forensic Toolkit 8 for Mac introduces forensically sound, checkm8-based extraction of Apple Watch Series 3. How to connect the watch to the computer, what data is available and how to apply the exploit? Check out this comprehensive guide!

👉 https://blog.elcomsoft.com/2022/02/checkm8-extraction-of-apple-watch-series-3/

#applewatch #watchOS #eift #mobileforensics #dfir
Apple Mobile Devices and iOS Acquisition Methods

Do you have to know which SoC a certain Apple device is based on? If you are working in mobile forensics, the answer is positive. Along with the version of iOS/watchOS/iPadOS, the SoC is one of the deciding factors that affects the data extraction paths available in each case. Read this article to better understand your options for each generation of Apple platforms.

👉 https://blog.elcomsoft.com/2022/02/apple-mobile-devices-and-ios-acquisition-methods/

#iphone #mobileforensics #dfir
Dude, Where Are My Messages?

Cloud backups are an invaluable source of information whether you download them from the user’s iCloud account or obtain directly from Apple. But why some iCloud backups miss essential bits and pieces of information such as text messages, particularly iMessages? The answer is “end-to-end encryption”, and there’s more to it than just backups.

👉 https://blog.elcomsoft.com/2022/02/dude-where-are-my-messages/

#sms #imessage #icloud #dfir #mobileforensics #phonebreaker
GPU Acceleration On The Cheap: Using Affordable Video Cards to Break Passwords Faster

Most password protection methods rely on multiple rounds of hash iterations to slow down brute-force attacks. Even the fastest processors choke when trying to break a reasonably strong password. Video cards can be used to speed up the recovery with GPU acceleration, yet the GPU market is currently overheated, and most high-end video cards are severely overpriced. Today, we’ll test a bunch of low-end video cards and compare their price/performance ratio.

👉 https://blog.elcomsoft.com/2022/02/gpu-acceleration-on-the-cheap-using-affordable-video-cards-to-break-passwords-faster/

#amd #cuda #edpr #gpu #intel #passwordcracking #passwordrecovery
https://www.forbes.com/sites/thomasbrewster/2022/03/04/russians-escaping-putins-repression-urged-to-wipe-their-phones/

Assistance from both inside and outside the country is being offered to Russians in fear of phone searches. Vladimir Katalov, the Moscow-based owner of phone forensics company Elcomsoft, which works with law enforcement to compile data on criminal suspects, says he doesn’t ask what nationality anyone is, but he has noted an increase in the number of people asking how to keep their data safe in an “emergency situation, whatever that is.”

His main advice, he said, is for people to not have their main device with them if they think there’s a chance it will be seized. “Get a spare phone with minimum data, probably just contacts,” he said. “Even better, get a spare SIM card, as your main one could be used to get an authentication code to log into your account.”
Elcomsoft Phone Viewer 5.33 updated with Windows 11, macOS 12 Monterey support

Elcomsoft Phone Viewer for Mac 5.33 is updated to support macOS 12 Monterey, while the Windows edition of the tool adds support for Windows 11. In addition, the tool fixes several reported issues related to data export.

👉 https://www.elcomsoft.com/news/808.html

#dfir #mobileforensics #epv #windows11 #macos12
Elcomsoft System Recovery 8.20 adds Windows 11 support, bootable triage tools

Elcomsoft System Recovery, a digital field triage tool, is updated to support Windows 11 and Windows Server 2022 installations and adds a host of bootable forensic triage tools to help experts analyze computer systems in the field.

👉 https://www.elcomsoft.com/news/809.html

📝 Release Notes

#esr #forensictriage #windows11 #dfir #digitalforensics
Simplifying Digital Triage with Bootable Forensic Tools

Elcomsoft System Recovery speeds up in-field investigations by providing experts with a forensic tool they can use by booting a PC from a dedicated USB media. The recent update extended the functionality of the tool by adding three new forensic tools.

👉 https://blog.elcomsoft.com/2022/03/simplifying-digital-triage-with-bootable-forensic-tools/

#esr #dfir #computerforensics #forensictriage
Windows 11 TPM Protection, Passwordless Sign-In and What You Can Do About Them

Windows 11 introduces increased account protection, passwordless sign-in and hardware-based security. What has been changed compared to Windows 10, how these changes affect forensic extraction and analysis, and to what extent can one overcome the TPM-based protection? Read along to find out!

👉 https://blog.elcomsoft.com/2022/03/windows-11-tpm-protection-passwordless-sign-in-and-what-you-can-do-about-them/

#esr #bitlocker #microsoftaccount #systemrecovery #tpm
Advanced Office Password Recovery: WordPerfect Office and Lotus SmartSuite support

Advanced Office Password Recovery 7.10 gains the ability to unlock protected WordPerfect Office and Lotus SmartSuite documents, offering instant unlock or fast guaranteed timeframe recovery depending on the format.

👉 https://www.elcomsoft.com/news/810.html

📝 Release notes (PDF)

#aopr #wordperfect #lotus #password #encryption
Unlock WordPerfect and Lotus Documents with Advanced Office Password Recovery

We are continuing the consolidation of our product line, now adding WordPerfect and Lotus office apps into Advanced Office Password Recovery. The tool can help experts unlock a host of digital document formats including Microsoft Office, OpenDocument, Hangul/Hancell, and many others without lengthy attacks.

👉 https://blog.elcomsoft.com/2022/04/unlock-wordperfect-and-lotus-documents-with-advanced-office-password-recovery/

#aopr #wordperfect #lotus #password #dfir
Decrypting Password-Protected DOC and XLS Files in Minutes

Accessing the content of password-protected and encrypted documents saved as DOC/XLS files (as opposed to the newer DOCX/XLSX files) is often possible without time-consuming attacks regardless of the length of the password. Advanced Office Password Recovery enables experts quickly breaking the encryption of password-protected DOC and XLS files, which are Microsoft Word and Excel documents saved by modern versions of the app in the “compatibility” format. Organizations are still using the “compatible” Office 97/2000 formats for their document workflow. More in the article:

👉 https://blog.elcomsoft.com/2022/04/decrypting-password-protected-doc-and-xls-files-in-minutes/

#aopr #microsoftoffice #word #excel #thundertables #encryption
Preventing BitLocker Lockout and Recovering Access to Encrypted System Drive

Encrypting a Windows system drive with BitLocker provides effective protection against unauthorized access, especially when paired with TPM. A hardware upgrade, firmware update or even a change in the computer’s UEFI BIOS may effectively lock you out, making your data inaccessible and the Windows system unbootable. How to prevent being locked out and how to restore access to the data if you are prompted to unlock the drive? Read along to find out.

👉 https://blog.elcomsoft.com/2022/04/preventing-bitlocker-lockout-and-recovering-access-to-encrypted-system-drive/

#BitLocker #edpr #efdd #tpm #encryption
iOS Low-Level Acquisition: How to Sideload the Extraction Agent

Regular or disposable Apple IDs can now be used to extract data from compatible iOS devices if you have a Mac. The use of a non-developer Apple ID carries certain risks and restrictions. In particular, one must “verify” the extraction agent on the target iPhone, which requires an active Internet connection. Learn how to verify the extraction agent signed with a regular or disposable Apple ID without the risk of receiving an accidental remote lock or remote erase command.

👉 https://blog.elcomsoft.com/2022/04/ios-low-level-acquisition-how-to-sideload-the-extraction-agent/

#ios #eift #mobileforensic #dfir #agent
iOS Forensic Toolkit Update supports iPhone 13

Elcomsoft iOS Forensic Toolkit 7.30 brings the ability to perform low-level file system extraction for iPhone models up to the iPhone 13 Pro Max running iOS 15.1.1. The still-in-beta iOS Forensic Toolkit 8.0 receives the same features, and adds checkm8 acquisition support for iPhone 6s, SE, 7, 8, and iPhone X devices running iOS 15.4 and iOS 15.4.1.

👉 https://www.elcomsoft.com/news/811.html

📝 EIFT 7.30 / 8.0 b6 Release Notes

#iphone13 #ios15 #eift #dfir #mobileforensics
Agent-Based Low-Level iOS File System Extraction

While we continue working on the major update to iOS Forensic Toolkit with forensically sound checkm8 extraction, we keep updating the current release branch. iOS Forensic Toolkit 7.30 brings low-level file system extraction support for iOS 15.1, expanding the ability to perform full file system extraction on iOS devices ranging from the iPhone 8 through iPhone 13 Pro Max.

👉 https://blog.elcomsoft.com/2022/04/agent-based-low-level-ios-file-system-extraction/

#iphone13 #ios15 #eift #dfir #mobileforensics
Identifying the iPhone Model

A pre-requisite to successful forensic analysis is accurate information about the device being investigated. Knowing the exact model number of the device helps identify the SoC used and the range of available iOS versions, which in turn pre-determines the available acquisition methods. Identifying the iPhone model may not be as obvious as it may seem. In this article, we’ll go through several methods for finding the iPhone model.

👉 https://blog.elcomsoft.com/2022/05/identifying-the-iphone-model/

#iphone #ios #dfir #mobileforensics #dfu #eift
Elcomsoft iOS Forensic Toolkit 8.0 beta 7 unlocks and extracts legacy iOS devices

The seventh beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings passcode unlock and forensically sound, checkm8-based extraction of iPhone 4s, iPad 2 and 3 devices. The low-level extraction solution employs a Raspberry Pi Pico board to apply the exploit.

👉 https://www.elcomsoft.com/news/812.html

#eift #checkm8 #raspberrypipico #iphone4s #dfir
checkm8: Unlocking and Imaging the iPhone 4s

The seventh beta of iOS Forensic Toolkit 8.0 for Mac introduces passcode unlock and forensically sound checkm8 extraction of iPhone 4s, iPad 2 and 3. The new solution employs a Raspberry Pi Pico board to apply the exploit. Learn how to configure and use the Pico microcontroller for extracting an iPhone 4s!

👉 https://blog.elcomsoft.com/2022/05/checkm8-unlocking-and-imaging-the-iphone-4s/

#iosforensictoolkit #iphone4s #checkm8 #raspberrypipico #forensicallysound
Elcomsoft Distributed Password Recovery 4.4 optimized for Intel Alder Lake

Elcomsoft Distributed Password Recovery 4.44 is updated with optimizations for Intel’s 12th-generation hybrid architecture. The updated tool is now fully ready for the heterogeneous computing introduced in Intel Alder Lake CPUs.

👉 https://www.elcomsoft.com/news/813.html

#edpr #intel #alderlake #passwordrecovery