https://www.forbes.com/sites/thomasbrewster/2022/03/04/russians-escaping-putins-repression-urged-to-wipe-their-phones/
Assistance from both inside and outside the country is being offered to Russians in fear of phone searches. Vladimir Katalov, the Moscow-based owner of phone forensics company Elcomsoft, which works with law enforcement to compile data on criminal suspects, says he doesn’t ask what nationality anyone is, but he has noted an increase in the number of people asking how to keep their data safe in an “emergency situation, whatever that is.”
His main advice, he said, is for people to not have their main device with them if they think there’s a chance it will be seized. “Get a spare phone with minimum data, probably just contacts,” he said. “Even better, get a spare SIM card, as your main one could be used to get an authentication code to log into your account.”
Assistance from both inside and outside the country is being offered to Russians in fear of phone searches. Vladimir Katalov, the Moscow-based owner of phone forensics company Elcomsoft, which works with law enforcement to compile data on criminal suspects, says he doesn’t ask what nationality anyone is, but he has noted an increase in the number of people asking how to keep their data safe in an “emergency situation, whatever that is.”
His main advice, he said, is for people to not have their main device with them if they think there’s a chance it will be seized. “Get a spare phone with minimum data, probably just contacts,” he said. “Even better, get a spare SIM card, as your main one could be used to get an authentication code to log into your account.”
Forbes
Leaving Russia? Experts Say Wipe Your Phone Before You Go
Russians who are fleeing the country amid Putin’s war face border guards searching for hints of support for Ukraine.
Elcomsoft Phone Viewer 5.33 updated with Windows 11, macOS 12 Monterey support
Elcomsoft Phone Viewer for Mac 5.33 is updated to support macOS 12 Monterey, while the Windows edition of the tool adds support for Windows 11. In addition, the tool fixes several reported issues related to data export.
👉 https://www.elcomsoft.com/news/808.html
#dfir #mobileforensics #epv #windows11 #macos12
Elcomsoft Phone Viewer for Mac 5.33 is updated to support macOS 12 Monterey, while the Windows edition of the tool adds support for Windows 11. In addition, the tool fixes several reported issues related to data export.
👉 https://www.elcomsoft.com/news/808.html
#dfir #mobileforensics #epv #windows11 #macos12
Elcomsoft System Recovery 8.20 adds Windows 11 support, bootable triage tools
Elcomsoft System Recovery, a digital field triage tool, is updated to support Windows 11 and Windows Server 2022 installations and adds a host of bootable forensic triage tools to help experts analyze computer systems in the field.
👉 https://www.elcomsoft.com/news/809.html
📝 Release Notes
#esr #forensictriage #windows11 #dfir #digitalforensics
Elcomsoft System Recovery, a digital field triage tool, is updated to support Windows 11 and Windows Server 2022 installations and adds a host of bootable forensic triage tools to help experts analyze computer systems in the field.
👉 https://www.elcomsoft.com/news/809.html
📝 Release Notes
#esr #forensictriage #windows11 #dfir #digitalforensics
Simplifying Digital Triage with Bootable Forensic Tools
Elcomsoft System Recovery speeds up in-field investigations by providing experts with a forensic tool they can use by booting a PC from a dedicated USB media. The recent update extended the functionality of the tool by adding three new forensic tools.
👉 https://blog.elcomsoft.com/2022/03/simplifying-digital-triage-with-bootable-forensic-tools/
#esr #dfir #computerforensics #forensictriage
Elcomsoft System Recovery speeds up in-field investigations by providing experts with a forensic tool they can use by booting a PC from a dedicated USB media. The recent update extended the functionality of the tool by adding three new forensic tools.
👉 https://blog.elcomsoft.com/2022/03/simplifying-digital-triage-with-bootable-forensic-tools/
#esr #dfir #computerforensics #forensictriage
Windows 11 TPM Protection, Passwordless Sign-In and What You Can Do About Them
Windows 11 introduces increased account protection, passwordless sign-in and hardware-based security. What has been changed compared to Windows 10, how these changes affect forensic extraction and analysis, and to what extent can one overcome the TPM-based protection? Read along to find out!
👉 https://blog.elcomsoft.com/2022/03/windows-11-tpm-protection-passwordless-sign-in-and-what-you-can-do-about-them/
#esr #bitlocker #microsoftaccount #systemrecovery #tpm
Windows 11 introduces increased account protection, passwordless sign-in and hardware-based security. What has been changed compared to Windows 10, how these changes affect forensic extraction and analysis, and to what extent can one overcome the TPM-based protection? Read along to find out!
👉 https://blog.elcomsoft.com/2022/03/windows-11-tpm-protection-passwordless-sign-in-and-what-you-can-do-about-them/
#esr #bitlocker #microsoftaccount #systemrecovery #tpm
Advanced Office Password Recovery: WordPerfect Office and Lotus SmartSuite support
Advanced Office Password Recovery 7.10 gains the ability to unlock protected WordPerfect Office and Lotus SmartSuite documents, offering instant unlock or fast guaranteed timeframe recovery depending on the format.
👉 https://www.elcomsoft.com/news/810.html
📝 Release notes (PDF)
#aopr #wordperfect #lotus #password #encryption
Advanced Office Password Recovery 7.10 gains the ability to unlock protected WordPerfect Office and Lotus SmartSuite documents, offering instant unlock or fast guaranteed timeframe recovery depending on the format.
👉 https://www.elcomsoft.com/news/810.html
📝 Release notes (PDF)
#aopr #wordperfect #lotus #password #encryption
Unlock WordPerfect and Lotus Documents with Advanced Office Password Recovery
We are continuing the consolidation of our product line, now adding WordPerfect and Lotus office apps into Advanced Office Password Recovery. The tool can help experts unlock a host of digital document formats including Microsoft Office, OpenDocument, Hangul/Hancell, and many others without lengthy attacks.
👉 https://blog.elcomsoft.com/2022/04/unlock-wordperfect-and-lotus-documents-with-advanced-office-password-recovery/
#aopr #wordperfect #lotus #password #dfir
We are continuing the consolidation of our product line, now adding WordPerfect and Lotus office apps into Advanced Office Password Recovery. The tool can help experts unlock a host of digital document formats including Microsoft Office, OpenDocument, Hangul/Hancell, and many others without lengthy attacks.
👉 https://blog.elcomsoft.com/2022/04/unlock-wordperfect-and-lotus-documents-with-advanced-office-password-recovery/
#aopr #wordperfect #lotus #password #dfir
Decrypting Password-Protected DOC and XLS Files in Minutes
Accessing the content of password-protected and encrypted documents saved as DOC/XLS files (as opposed to the newer DOCX/XLSX files) is often possible without time-consuming attacks regardless of the length of the password. Advanced Office Password Recovery enables experts quickly breaking the encryption of password-protected DOC and XLS files, which are Microsoft Word and Excel documents saved by modern versions of the app in the “compatibility” format. Organizations are still using the “compatible” Office 97/2000 formats for their document workflow. More in the article:
👉 https://blog.elcomsoft.com/2022/04/decrypting-password-protected-doc-and-xls-files-in-minutes/
#aopr #microsoftoffice #word #excel #thundertables #encryption
Accessing the content of password-protected and encrypted documents saved as DOC/XLS files (as opposed to the newer DOCX/XLSX files) is often possible without time-consuming attacks regardless of the length of the password. Advanced Office Password Recovery enables experts quickly breaking the encryption of password-protected DOC and XLS files, which are Microsoft Word and Excel documents saved by modern versions of the app in the “compatibility” format. Organizations are still using the “compatible” Office 97/2000 formats for their document workflow. More in the article:
👉 https://blog.elcomsoft.com/2022/04/decrypting-password-protected-doc-and-xls-files-in-minutes/
#aopr #microsoftoffice #word #excel #thundertables #encryption
Preventing BitLocker Lockout and Recovering Access to Encrypted System Drive
Encrypting a Windows system drive with BitLocker provides effective protection against unauthorized access, especially when paired with TPM. A hardware upgrade, firmware update or even a change in the computer’s UEFI BIOS may effectively lock you out, making your data inaccessible and the Windows system unbootable. How to prevent being locked out and how to restore access to the data if you are prompted to unlock the drive? Read along to find out.
👉 https://blog.elcomsoft.com/2022/04/preventing-bitlocker-lockout-and-recovering-access-to-encrypted-system-drive/
#BitLocker #edpr #efdd #tpm #encryption
Encrypting a Windows system drive with BitLocker provides effective protection against unauthorized access, especially when paired with TPM. A hardware upgrade, firmware update or even a change in the computer’s UEFI BIOS may effectively lock you out, making your data inaccessible and the Windows system unbootable. How to prevent being locked out and how to restore access to the data if you are prompted to unlock the drive? Read along to find out.
👉 https://blog.elcomsoft.com/2022/04/preventing-bitlocker-lockout-and-recovering-access-to-encrypted-system-drive/
#BitLocker #edpr #efdd #tpm #encryption
iOS Low-Level Acquisition: How to Sideload the Extraction Agent
Regular or disposable Apple IDs can now be used to extract data from compatible iOS devices if you have a Mac. The use of a non-developer Apple ID carries certain risks and restrictions. In particular, one must “verify” the extraction agent on the target iPhone, which requires an active Internet connection. Learn how to verify the extraction agent signed with a regular or disposable Apple ID without the risk of receiving an accidental remote lock or remote erase command.
👉 https://blog.elcomsoft.com/2022/04/ios-low-level-acquisition-how-to-sideload-the-extraction-agent/
#ios #eift #mobileforensic #dfir #agent
Regular or disposable Apple IDs can now be used to extract data from compatible iOS devices if you have a Mac. The use of a non-developer Apple ID carries certain risks and restrictions. In particular, one must “verify” the extraction agent on the target iPhone, which requires an active Internet connection. Learn how to verify the extraction agent signed with a regular or disposable Apple ID without the risk of receiving an accidental remote lock or remote erase command.
👉 https://blog.elcomsoft.com/2022/04/ios-low-level-acquisition-how-to-sideload-the-extraction-agent/
#ios #eift #mobileforensic #dfir #agent
iOS Forensic Toolkit Update supports iPhone 13
Elcomsoft iOS Forensic Toolkit 7.30 brings the ability to perform low-level file system extraction for iPhone models up to the iPhone 13 Pro Max running iOS 15.1.1. The still-in-beta iOS Forensic Toolkit 8.0 receives the same features, and adds checkm8 acquisition support for iPhone 6s, SE, 7, 8, and iPhone X devices running iOS 15.4 and iOS 15.4.1.
👉 https://www.elcomsoft.com/news/811.html
📝 EIFT 7.30 / 8.0 b6 Release Notes
#iphone13 #ios15 #eift #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 7.30 brings the ability to perform low-level file system extraction for iPhone models up to the iPhone 13 Pro Max running iOS 15.1.1. The still-in-beta iOS Forensic Toolkit 8.0 receives the same features, and adds checkm8 acquisition support for iPhone 6s, SE, 7, 8, and iPhone X devices running iOS 15.4 and iOS 15.4.1.
👉 https://www.elcomsoft.com/news/811.html
📝 EIFT 7.30 / 8.0 b6 Release Notes
#iphone13 #ios15 #eift #dfir #mobileforensics
Agent-Based Low-Level iOS File System Extraction
While we continue working on the major update to iOS Forensic Toolkit with forensically sound checkm8 extraction, we keep updating the current release branch. iOS Forensic Toolkit 7.30 brings low-level file system extraction support for iOS 15.1, expanding the ability to perform full file system extraction on iOS devices ranging from the iPhone 8 through iPhone 13 Pro Max.
👉 https://blog.elcomsoft.com/2022/04/agent-based-low-level-ios-file-system-extraction/
#iphone13 #ios15 #eift #dfir #mobileforensics
While we continue working on the major update to iOS Forensic Toolkit with forensically sound checkm8 extraction, we keep updating the current release branch. iOS Forensic Toolkit 7.30 brings low-level file system extraction support for iOS 15.1, expanding the ability to perform full file system extraction on iOS devices ranging from the iPhone 8 through iPhone 13 Pro Max.
👉 https://blog.elcomsoft.com/2022/04/agent-based-low-level-ios-file-system-extraction/
#iphone13 #ios15 #eift #dfir #mobileforensics
Identifying the iPhone Model
A pre-requisite to successful forensic analysis is accurate information about the device being investigated. Knowing the exact model number of the device helps identify the SoC used and the range of available iOS versions, which in turn pre-determines the available acquisition methods. Identifying the iPhone model may not be as obvious as it may seem. In this article, we’ll go through several methods for finding the iPhone model.
👉 https://blog.elcomsoft.com/2022/05/identifying-the-iphone-model/
#iphone #ios #dfir #mobileforensics #dfu #eift
A pre-requisite to successful forensic analysis is accurate information about the device being investigated. Knowing the exact model number of the device helps identify the SoC used and the range of available iOS versions, which in turn pre-determines the available acquisition methods. Identifying the iPhone model may not be as obvious as it may seem. In this article, we’ll go through several methods for finding the iPhone model.
👉 https://blog.elcomsoft.com/2022/05/identifying-the-iphone-model/
#iphone #ios #dfir #mobileforensics #dfu #eift
Elcomsoft iOS Forensic Toolkit 8.0 beta 7 unlocks and extracts legacy iOS devices
The seventh beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings passcode unlock and forensically sound, checkm8-based extraction of iPhone 4s, iPad 2 and 3 devices. The low-level extraction solution employs a Raspberry Pi Pico board to apply the exploit.
👉 https://www.elcomsoft.com/news/812.html
#eift #checkm8 #raspberrypipico #iphone4s #dfir
The seventh beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings passcode unlock and forensically sound, checkm8-based extraction of iPhone 4s, iPad 2 and 3 devices. The low-level extraction solution employs a Raspberry Pi Pico board to apply the exploit.
👉 https://www.elcomsoft.com/news/812.html
#eift #checkm8 #raspberrypipico #iphone4s #dfir
checkm8: Unlocking and Imaging the iPhone 4s
The seventh beta of iOS Forensic Toolkit 8.0 for Mac introduces passcode unlock and forensically sound checkm8 extraction of iPhone 4s, iPad 2 and 3. The new solution employs a Raspberry Pi Pico board to apply the exploit. Learn how to configure and use the Pico microcontroller for extracting an iPhone 4s!
👉 https://blog.elcomsoft.com/2022/05/checkm8-unlocking-and-imaging-the-iphone-4s/
#iosforensictoolkit #iphone4s #checkm8 #raspberrypipico #forensicallysound
The seventh beta of iOS Forensic Toolkit 8.0 for Mac introduces passcode unlock and forensically sound checkm8 extraction of iPhone 4s, iPad 2 and 3. The new solution employs a Raspberry Pi Pico board to apply the exploit. Learn how to configure and use the Pico microcontroller for extracting an iPhone 4s!
👉 https://blog.elcomsoft.com/2022/05/checkm8-unlocking-and-imaging-the-iphone-4s/
#iosforensictoolkit #iphone4s #checkm8 #raspberrypipico #forensicallysound
Elcomsoft Distributed Password Recovery 4.4 optimized for Intel Alder Lake
Elcomsoft Distributed Password Recovery 4.44 is updated with optimizations for Intel’s 12th-generation hybrid architecture. The updated tool is now fully ready for the heterogeneous computing introduced in Intel Alder Lake CPUs.
👉 https://www.elcomsoft.com/news/813.html
#edpr #intel #alderlake #passwordrecovery
Elcomsoft Distributed Password Recovery 4.44 is updated with optimizations for Intel’s 12th-generation hybrid architecture. The updated tool is now fully ready for the heterogeneous computing introduced in Intel Alder Lake CPUs.
👉 https://www.elcomsoft.com/news/813.html
#edpr #intel #alderlake #passwordrecovery
Breaking Passwords on Alder Lake CPUs
In Alder Lake, Intel introduced hybrid architecture. Large, hyperthreading-enabled Performance cores are complemented with smaller, single-thread Efficiency cores. The host OS is responsible for assigning threads to one core or another. We discovered that Windows 10 scheduler is not doing a perfect job when it comes to password recovery, which requires a careful approach to thread scheduling.
👉 https://blog.elcomsoft.com/2022/05/breaking-passwords-on-alder-lake-cpus/
#edpr #intel #alderlake #passwordrecovery
In Alder Lake, Intel introduced hybrid architecture. Large, hyperthreading-enabled Performance cores are complemented with smaller, single-thread Efficiency cores. The host OS is responsible for assigning threads to one core or another. We discovered that Windows 10 scheduler is not doing a perfect job when it comes to password recovery, which requires a careful approach to thread scheduling.
👉 https://blog.elcomsoft.com/2022/05/breaking-passwords-on-alder-lake-cpus/
#edpr #intel #alderlake #passwordrecovery
Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based full file system extraction
Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based extraction support all the way up to iOS 15.1 on all supported devices. The new release fills the gap in iOS 14 support, adding agent-based extraction for devices running iOS 14.8.1 for all devices and iOS 14.3 through 14.8.1 for models based on Apple A14 Bionic. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.
👉 https://www.elcomsoft.com/news/814.html
#EIFT #dfir #ios14 #iphone #mobileforensics #agent
Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based extraction support all the way up to iOS 15.1 on all supported devices. The new release fills the gap in iOS 14 support, adding agent-based extraction for devices running iOS 14.8.1 for all devices and iOS 14.3 through 14.8.1 for models based on Apple A14 Bionic. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.
👉 https://www.elcomsoft.com/news/814.html
#EIFT #dfir #ios14 #iphone #mobileforensics #agent
Filling the Gaps: iOS 14 Full File System Extracted
iOS Forensic Toolkit 7.40 brings gapless low-level extraction support for several iOS versions up to and including iOS 15.1 (15.1.1 on some devices), adding compatibility with previously unsupported versions of iOS 14.
👉 https://blog.elcomsoft.com/2022/06/filling-the-gaps-ios-14-full-file-system-extracted/
#eift #ios14 #iphone #mobileforensics #dfir #agent
iOS Forensic Toolkit 7.40 brings gapless low-level extraction support for several iOS versions up to and including iOS 15.1 (15.1.1 on some devices), adding compatibility with previously unsupported versions of iOS 14.
👉 https://blog.elcomsoft.com/2022/06/filling-the-gaps-ios-14-full-file-system-extracted/
#eift #ios14 #iphone #mobileforensics #dfir #agent
Elcomsoft iOS Forensic Toolkit 8.0 beta 9 adds checkm8 extraction of 14 iPad and iPod Touch devices
The ninth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of ten iPad and four iPod Touch models, as well as two Apple TV models. The low-level extraction solution is available directly for most devices, with select models requiring a Raspberry Pi Pico board to apply the exploit.
👉 https://www.elcomsoft.com/news/815.html
#iphone #ipad #ios #eift #dfir #mobileforensics
The ninth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of ten iPad and four iPod Touch models, as well as two Apple TV models. The low-level extraction solution is available directly for most devices, with select models requiring a Raspberry Pi Pico board to apply the exploit.
👉 https://www.elcomsoft.com/news/815.html
#iphone #ipad #ios #eift #dfir #mobileforensics
checkm8 Extraction: the iPads, iPods, and TVs
The ninth beta of iOS Forensic Toolkit 8.0 for Mac introduces forensically sound, checkm8-based extraction of sixteen iPad, iPod Touch and Apple TV models. The low-level extraction solution is now available for all iPad and all iPod Touch models susceptible to the checkm8 exploit.
checkm8 is applicable to all devices with bootloader vulnerability, yet there are technical differences when it comes to implementing the exploit on the various devices. In this update we are targeting non-iPhone devices, spending efforts to support the many iPads equipped with the corresponding SoCs. While other vendors have been offering their own implementations of checkm8 extraction for quite a while, we found their solutions to lack in device/iOS version coverage and miss the “forensically sound” mark.
👉 https://blog.elcomsoft.com/2022/06/checkm8-extraction-the-ipads-ipods-and-tvs/
#ipad #ios #apple #dfir #eift #checkm8 #mobileforensics
The ninth beta of iOS Forensic Toolkit 8.0 for Mac introduces forensically sound, checkm8-based extraction of sixteen iPad, iPod Touch and Apple TV models. The low-level extraction solution is now available for all iPad and all iPod Touch models susceptible to the checkm8 exploit.
checkm8 is applicable to all devices with bootloader vulnerability, yet there are technical differences when it comes to implementing the exploit on the various devices. In this update we are targeting non-iPhone devices, spending efforts to support the many iPads equipped with the corresponding SoCs. While other vendors have been offering their own implementations of checkm8 extraction for quite a while, we found their solutions to lack in device/iOS version coverage and miss the “forensically sound” mark.
👉 https://blog.elcomsoft.com/2022/06/checkm8-extraction-the-ipads-ipods-and-tvs/
#ipad #ios #apple #dfir #eift #checkm8 #mobileforensics