Elcomsoft
547 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Unlock WordPerfect and Lotus Documents with Advanced Office Password Recovery

We are continuing the consolidation of our product line, now adding WordPerfect and Lotus office apps into Advanced Office Password Recovery. The tool can help experts unlock a host of digital document formats including Microsoft Office, OpenDocument, Hangul/Hancell, and many others without lengthy attacks.

👉 https://blog.elcomsoft.com/2022/04/unlock-wordperfect-and-lotus-documents-with-advanced-office-password-recovery/

#aopr #wordperfect #lotus #password #dfir
Decrypting Password-Protected DOC and XLS Files in Minutes

Accessing the content of password-protected and encrypted documents saved as DOC/XLS files (as opposed to the newer DOCX/XLSX files) is often possible without time-consuming attacks regardless of the length of the password. Advanced Office Password Recovery enables experts quickly breaking the encryption of password-protected DOC and XLS files, which are Microsoft Word and Excel documents saved by modern versions of the app in the “compatibility” format. Organizations are still using the “compatible” Office 97/2000 formats for their document workflow. More in the article:

👉 https://blog.elcomsoft.com/2022/04/decrypting-password-protected-doc-and-xls-files-in-minutes/

#aopr #microsoftoffice #word #excel #thundertables #encryption
Preventing BitLocker Lockout and Recovering Access to Encrypted System Drive

Encrypting a Windows system drive with BitLocker provides effective protection against unauthorized access, especially when paired with TPM. A hardware upgrade, firmware update or even a change in the computer’s UEFI BIOS may effectively lock you out, making your data inaccessible and the Windows system unbootable. How to prevent being locked out and how to restore access to the data if you are prompted to unlock the drive? Read along to find out.

👉 https://blog.elcomsoft.com/2022/04/preventing-bitlocker-lockout-and-recovering-access-to-encrypted-system-drive/

#BitLocker #edpr #efdd #tpm #encryption
iOS Low-Level Acquisition: How to Sideload the Extraction Agent

Regular or disposable Apple IDs can now be used to extract data from compatible iOS devices if you have a Mac. The use of a non-developer Apple ID carries certain risks and restrictions. In particular, one must “verify” the extraction agent on the target iPhone, which requires an active Internet connection. Learn how to verify the extraction agent signed with a regular or disposable Apple ID without the risk of receiving an accidental remote lock or remote erase command.

👉 https://blog.elcomsoft.com/2022/04/ios-low-level-acquisition-how-to-sideload-the-extraction-agent/

#ios #eift #mobileforensic #dfir #agent
iOS Forensic Toolkit Update supports iPhone 13

Elcomsoft iOS Forensic Toolkit 7.30 brings the ability to perform low-level file system extraction for iPhone models up to the iPhone 13 Pro Max running iOS 15.1.1. The still-in-beta iOS Forensic Toolkit 8.0 receives the same features, and adds checkm8 acquisition support for iPhone 6s, SE, 7, 8, and iPhone X devices running iOS 15.4 and iOS 15.4.1.

👉 https://www.elcomsoft.com/news/811.html

📝 EIFT 7.30 / 8.0 b6 Release Notes

#iphone13 #ios15 #eift #dfir #mobileforensics
Agent-Based Low-Level iOS File System Extraction

While we continue working on the major update to iOS Forensic Toolkit with forensically sound checkm8 extraction, we keep updating the current release branch. iOS Forensic Toolkit 7.30 brings low-level file system extraction support for iOS 15.1, expanding the ability to perform full file system extraction on iOS devices ranging from the iPhone 8 through iPhone 13 Pro Max.

👉 https://blog.elcomsoft.com/2022/04/agent-based-low-level-ios-file-system-extraction/

#iphone13 #ios15 #eift #dfir #mobileforensics
Identifying the iPhone Model

A pre-requisite to successful forensic analysis is accurate information about the device being investigated. Knowing the exact model number of the device helps identify the SoC used and the range of available iOS versions, which in turn pre-determines the available acquisition methods. Identifying the iPhone model may not be as obvious as it may seem. In this article, we’ll go through several methods for finding the iPhone model.

👉 https://blog.elcomsoft.com/2022/05/identifying-the-iphone-model/

#iphone #ios #dfir #mobileforensics #dfu #eift
Elcomsoft iOS Forensic Toolkit 8.0 beta 7 unlocks and extracts legacy iOS devices

The seventh beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings passcode unlock and forensically sound, checkm8-based extraction of iPhone 4s, iPad 2 and 3 devices. The low-level extraction solution employs a Raspberry Pi Pico board to apply the exploit.

👉 https://www.elcomsoft.com/news/812.html

#eift #checkm8 #raspberrypipico #iphone4s #dfir
checkm8: Unlocking and Imaging the iPhone 4s

The seventh beta of iOS Forensic Toolkit 8.0 for Mac introduces passcode unlock and forensically sound checkm8 extraction of iPhone 4s, iPad 2 and 3. The new solution employs a Raspberry Pi Pico board to apply the exploit. Learn how to configure and use the Pico microcontroller for extracting an iPhone 4s!

👉 https://blog.elcomsoft.com/2022/05/checkm8-unlocking-and-imaging-the-iphone-4s/

#iosforensictoolkit #iphone4s #checkm8 #raspberrypipico #forensicallysound
Elcomsoft Distributed Password Recovery 4.4 optimized for Intel Alder Lake

Elcomsoft Distributed Password Recovery 4.44 is updated with optimizations for Intel’s 12th-generation hybrid architecture. The updated tool is now fully ready for the heterogeneous computing introduced in Intel Alder Lake CPUs.

👉 https://www.elcomsoft.com/news/813.html

#edpr #intel #alderlake #passwordrecovery
Breaking Passwords on Alder Lake CPUs

In Alder Lake, Intel introduced hybrid architecture. Large, hyperthreading-enabled Performance cores are complemented with smaller, single-thread Efficiency cores. The host OS is responsible for assigning threads to one core or another. We discovered that Windows 10 scheduler is not doing a perfect job when it comes to password recovery, which requires a careful approach to thread scheduling.

👉 https://blog.elcomsoft.com/2022/05/breaking-passwords-on-alder-lake-cpus/

#edpr #intel #alderlake #passwordrecovery
Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based full file system extraction

Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based extraction support all the way up to iOS 15.1 on all supported devices. The new release fills the gap in iOS 14 support, adding agent-based extraction for devices running iOS 14.8.1 for all devices and iOS 14.3 through 14.8.1 for models based on Apple A14 Bionic. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.

👉 https://www.elcomsoft.com/news/814.html

#EIFT #dfir #ios14 #iphone #mobileforensics #agent
Filling the Gaps: iOS 14 Full File System Extracted

iOS Forensic Toolkit 7.40 brings gapless low-level extraction support for several iOS versions up to and including iOS 15.1 (15.1.1 on some devices), adding compatibility with previously unsupported versions of iOS 14.

👉 https://blog.elcomsoft.com/2022/06/filling-the-gaps-ios-14-full-file-system-extracted/

#eift #ios14 #iphone #mobileforensics #dfir #agent
Elcomsoft iOS Forensic Toolkit 8.0 beta 9 adds checkm8 extraction of 14 iPad and iPod Touch devices

The ninth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of ten iPad and four iPod Touch models, as well as two Apple TV models. The low-level extraction solution is available directly for most devices, with select models requiring a Raspberry Pi Pico board to apply the exploit.

👉 https://www.elcomsoft.com/news/815.html

#iphone #ipad #ios #eift #dfir #mobileforensics
checkm8 Extraction: the iPads, iPods, and TVs

The ninth beta of iOS Forensic Toolkit 8.0 for Mac introduces forensically sound, checkm8-based extraction of sixteen iPad, iPod Touch and Apple TV models. The low-level extraction solution is now available for all iPad and all iPod Touch models susceptible to the checkm8 exploit.

checkm8 is applicable to all devices with bootloader vulnerability, yet there are technical differences when it comes to implementing the exploit on the various devices. In this update we are targeting non-iPhone devices, spending efforts to support the many iPads equipped with the corresponding SoCs. While other vendors have been offering their own implementations of checkm8 extraction for quite a while, we found their solutions to lack in device/iOS version coverage and miss the “forensically sound” mark.

👉 https://blog.elcomsoft.com/2022/06/checkm8-extraction-the-ipads-ipods-and-tvs/

#ipad #ios #apple #dfir #eift #checkm8 #mobileforensics
Logical Acquisition: Not as Simple as It Sounds

Speaking of mobile devices, especially Apple’s, “logical acquisition” is probably the most misused term. Are you sure you know what it is and how to properly use it, especially if you are working in mobile forensics? Let us shed some light on it.

👉 https://blog.elcomsoft.com/2022/06/logical-acquisition-not-as-simple-as-it-sounds/

#ios #iphone #icloud #itunes #dfir #mobileforensics #logicalacquisition
GPU Acceleration: Attacking Passwords with NVIDIA RTX Series Boards

Today’s data protection methods utilize many thousands (sometimes millions) hash iterations to strengthen password protection, slowing down the attacks to a crawl. Consumer-grade video cards are commonly used for GPU acceleration. How do these video cards compare, and what about the price-performance ratio? We tested five reasonably priced NVIDIA boards ranging from the lowly GTX 1650 to RTX 3060 Ti.

👉 https://blog.elcomsoft.com/2022/06/gpu-acceleration-attacking-passwords-with-nvidia-rtx-series/

#edpr #gpu #dfir #password #passwordrecovery #digitalforensics
Full File System and Keychain Acquisition: What, When, and How

We often write about full file system acquisition, yet we rarely explain what it is, when you can do it, and which methods you can use. We decided to clarify low-level extraction of Apple mobile devices (iPhones and iPads, and some other IoT devices such as Apple TVs and Apple Watches).

👉 https://blog.elcomsoft.com/2022/06/full-file-system-and-keychain-acquisition-what-when-and-how/

#filesystem #ios #eift #checkm8 #dfir #agent
iCloud backups: the Dark Territory

Apple ecosystem includes a comprehensive backup ecosystem that includes both local and cloud backups, and data synchronization with end-to-end encryption for some categories. Today we’ll discuss the iCloud backups, particularly targeting issues that are not covered in the official documentation.

👉 https://blog.elcomsoft.com/2022/07/icloud-backups-the-dark-territory/

#epb #e2ee #icloud #icloudbackup
Elcomsoft iOS Forensic Toolkit 7.50 closes the gap in keychain extraction

Elcomsoft iOS Forensic Toolkit 7.50 extends agent-based keychain extraction support all the way up to iOS 15.1.1 on all supported devices. The new release fills the remaining gaps in iOS 14 support, adding agent-based keychain extraction for iOS 14.5 – 14.8.1 and iOS 15.0 – 15.1.1 devices.

👉 https://www.elcomsoft.com/news/816.html

#ios #apple #iphone #agent #mobileforensics #dfir
Keychain: the Gold Mine of Apple Mobile Devices

Keychain is an essential part of iOS and macOS that securely stores the most critical data: passwords of all kinds, encryption keys, certificates, credit card numbers, and more. Extracting and decrypting the keychain, when possible, is a must in mobile forensics. We seriously improved this part in the latest build of iOS Forensic Toolkit.

👉 https://blog.elcomsoft.com/2022/07/keychain-the-gold-mine-of-apple-mobile-devices/

#ios #apple #dfir #mobileforensics #keychain #agent