Elcomsoft
547 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Agent-Based Low-Level iOS File System Extraction

While we continue working on the major update to iOS Forensic Toolkit with forensically sound checkm8 extraction, we keep updating the current release branch. iOS Forensic Toolkit 7.30 brings low-level file system extraction support for iOS 15.1, expanding the ability to perform full file system extraction on iOS devices ranging from the iPhone 8 through iPhone 13 Pro Max.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/04/agent-based-low-level-ios-file-system-extraction/

#iphone13 #ios15 #eift #dfir #mobileforensics
Identifying the iPhone Model

A pre-requisite to successful forensic analysis is accurate information about the device being investigated. Knowing the exact model number of the device helps identify the SoC used and the range of available iOS versions, which in turn pre-determines the available acquisition methods. Identifying the iPhone model may not be as obvious as it may seem. In this article, weโ€™ll go through several methods for finding the iPhone model.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/05/identifying-the-iphone-model/

#iphone #ios #dfir #mobileforensics #dfu #eift
Elcomsoft iOS Forensic Toolkit 8.0 beta 7 unlocks and extracts legacy iOS devices

The seventh beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings passcode unlock and forensically sound, checkm8-based extraction of iPhone 4s, iPad 2 and 3 devices. The low-level extraction solution employs a Raspberry Pi Pico board to apply the exploit.

๐Ÿ‘‰ https://www.elcomsoft.com/news/812.html

#eift #checkm8 #raspberrypipico #iphone4s #dfir
checkm8: Unlocking and Imaging the iPhone 4s

The seventh beta of iOS Forensic Toolkit 8.0 for Mac introduces passcode unlock and forensically sound checkm8 extraction of iPhone 4s, iPad 2 and 3. The new solution employs a Raspberry Pi Pico board to apply the exploit. Learn how to configure and use the Pico microcontroller for extracting an iPhone 4s!

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/05/checkm8-unlocking-and-imaging-the-iphone-4s/

#iosforensictoolkit #iphone4s #checkm8 #raspberrypipico #forensicallysound
Elcomsoft Distributed Password Recovery 4.4 optimized for Intel Alder Lake

Elcomsoft Distributed Password Recovery 4.44 is updated with optimizations for Intelโ€™s 12th-generation hybrid architecture. The updated tool is now fully ready for the heterogeneous computing introduced in Intel Alder Lake CPUs.

๐Ÿ‘‰ https://www.elcomsoft.com/news/813.html

#edpr #intel #alderlake #passwordrecovery
Breaking Passwords on Alder Lake CPUs

In Alder Lake, Intel introduced hybrid architecture. Large, hyperthreading-enabled Performance cores are complemented with smaller, single-thread Efficiency cores. The host OS is responsible for assigning threads to one core or another. We discovered that Windows 10 scheduler is not doing a perfect job when it comes to password recovery, which requires a careful approach to thread scheduling.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/05/breaking-passwords-on-alder-lake-cpus/

#edpr #intel #alderlake #passwordrecovery
Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based full file system extraction

Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based extraction support all the way up to iOS 15.1 on all supported devices. The new release fills the gap in iOS 14 support, adding agent-based extraction for devices running iOS 14.8.1 for all devices and iOS 14.3 through 14.8.1 for models based on Apple A14 Bionic. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.

๐Ÿ‘‰ https://www.elcomsoft.com/news/814.html

#EIFT #dfir #ios14 #iphone #mobileforensics #agent
Filling the Gaps: iOS 14 Full File System Extracted

iOS Forensic Toolkit 7.40 brings gapless low-level extraction support for several iOS versions up to and including iOS 15.1 (15.1.1 on some devices), adding compatibility with previously unsupported versions of iOS 14.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/filling-the-gaps-ios-14-full-file-system-extracted/

#eift #ios14 #iphone #mobileforensics #dfir #agent
Elcomsoft iOS Forensic Toolkit 8.0 beta 9 adds checkm8 extraction of 14 iPad and iPod Touch devices

The ninth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of ten iPad and four iPod Touch models, as well as two Apple TV models. The low-level extraction solution is available directly for most devices, with select models requiring a Raspberry Pi Pico board to apply the exploit.

๐Ÿ‘‰ https://www.elcomsoft.com/news/815.html

#iphone #ipad #ios #eift #dfir #mobileforensics
checkm8 Extraction: the iPads, iPods, and TVs

The ninth beta of iOS Forensic Toolkit 8.0 for Mac introduces forensically sound, checkm8-based extraction of sixteen iPad, iPod Touch and Apple TV models. The low-level extraction solution is now available for all iPad and all iPod Touch models susceptible to the checkm8 exploit.

checkm8 is applicable to all devices with bootloader vulnerability, yet there are technical differences when it comes to implementing the exploit on the various devices. In this update we are targeting non-iPhone devices, spending efforts to support the many iPads equipped with the corresponding SoCs. While other vendors have been offering their own implementations of checkm8 extraction for quite a while, we found their solutions to lack in device/iOS version coverage and miss the โ€œforensically soundโ€ mark.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/checkm8-extraction-the-ipads-ipods-and-tvs/

#ipad #ios #apple #dfir #eift #checkm8 #mobileforensics
Logical Acquisition: Not as Simple as It Sounds

Speaking of mobile devices, especially Appleโ€™s, โ€œlogical acquisitionโ€ is probably the most misused term. Are you sure you know what it is and how to properly use it, especially if you are working in mobile forensics? Let us shed some light on it.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/logical-acquisition-not-as-simple-as-it-sounds/

#ios #iphone #icloud #itunes #dfir #mobileforensics #logicalacquisition
GPU Acceleration: Attacking Passwords with NVIDIA RTX Series Boards

Todayโ€™s data protection methods utilize many thousands (sometimes millions) hash iterations to strengthen password protection, slowing down the attacks to a crawl. Consumer-grade video cards are commonly used for GPU acceleration. How do these video cards compare, and what about the price-performance ratio? We tested five reasonably priced NVIDIA boards ranging from the lowly GTX 1650 to RTX 3060 Ti.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/gpu-acceleration-attacking-passwords-with-nvidia-rtx-series/

#edpr #gpu #dfir #password #passwordrecovery #digitalforensics
Full File System and Keychain Acquisition: What, When, and How

We often write about full file system acquisition, yet we rarely explain what it is, when you can do it, and which methods you can use. We decided to clarify low-level extraction of Apple mobile devices (iPhones and iPads, and some other IoT devices such as Apple TVs and Apple Watches).

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/full-file-system-and-keychain-acquisition-what-when-and-how/

#filesystem #ios #eift #checkm8 #dfir #agent
iCloud backups: the Dark Territory

Apple ecosystem includes a comprehensive backup ecosystem that includes both local and cloud backups, and data synchronization with end-to-end encryption for some categories. Today weโ€™ll discuss the iCloud backups, particularly targeting issues that are not covered in the official documentation.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/icloud-backups-the-dark-territory/

#epb #e2ee #icloud #icloudbackup
Elcomsoft iOS Forensic Toolkit 7.50 closes the gap in keychain extraction

Elcomsoft iOS Forensic Toolkit 7.50 extends agent-based keychain extraction support all the way up to iOS 15.1.1 on all supported devices. The new release fills the remaining gaps in iOS 14 support, adding agent-based keychain extraction for iOS 14.5 โ€“ 14.8.1 and iOS 15.0 โ€“ 15.1.1 devices.

๐Ÿ‘‰ https://www.elcomsoft.com/news/816.html

#ios #apple #iphone #agent #mobileforensics #dfir
Keychain: the Gold Mine of Apple Mobile Devices

Keychain is an essential part of iOS and macOS that securely stores the most critical data: passwords of all kinds, encryption keys, certificates, credit card numbers, and more. Extracting and decrypting the keychain, when possible, is a must in mobile forensics. We seriously improved this part in the latest build of iOS Forensic Toolkit.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/keychain-the-gold-mine-of-apple-mobile-devices/

#ios #apple #dfir #mobileforensics #keychain #agent
Building an Efficient Password Recovery Workstation: Power Savings and Waste Heat Management

This article continues the series of publications aimed to help experts specify and build economical and power-efficient workstations for password recovery workloads. Electricity costs, long-term reliability and warranty coverage must be considered when building a password recovery workstation. In this article we will review the most common cooling solutions found in todayโ€™s GPUs, and compare consumer-grade video cards with their much lesser known professional counterparts.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/building-an-efficient-password-recovery-workstation-power-savings-and-waste-heat-management/

#edpr #gpuacceleration #nvidia #rtx #passwordrecovery
Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds iOS 15.6 RC support

Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds forensically sound checkm8-based low-level extraction support for the latest iOS, iPadOS and tvOS 15.6 RC, while also supporting watchOS 8.7 RC. In addition, several fixes are made to the checkm8 extraction engine.

๐Ÿ‘‰ https://www.elcomsoft.com/news/817.html

#eift #dfir #tvos #watchos #checkm8 #filesystem #keychain
Apple TV 4K Keychain and Full File System Acquisition

Mobile forensics is not limited to phones and tablets. Many types of other gadgets, including IoT devices, contain tons of valuable data. Such devices include smart watches, media players, routers, smart home devices, and so on. In this article, we will cover the extraction of an Apple TV 4K, one of the most popular digital media players.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/apple-tv-4k-keychain-and-full-file-system-acquisition/

#eift #checkm8 #tvos #appletv #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves iPhone 7 extraction

Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves checkm8-based low-level extraction support for the iPhone 7 and iPhone 7 Plus devices running the latest versions of iOS. The new beta drops the requirement to remove the deviceโ€™s screen lock passcode prior to extraction, enabling a clean, forensically sound extraction process.

๐Ÿ‘‰ https://www.elcomsoft.com/news/818.html

#eift #checkm8 #dfir #mobileforensics
checkm8 Extraction: iPhone 7

Elcomsoft iOS Forensic Toolkit supports checkm8 extraction from all compatible devices ranging from the iPhone 4s and all the way through the iPhone X (as well as the corresponding iPad, iPod Touch, Apple Watch and Apple TV models). The new update removes an important obstacle to the acquisition of the iPhone 7 and iPhone 7 Plus devices running recent versions of iOS.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/checkm8-extraction-iphone-7/

#eift #iphone7 #checkm8 #dfir #mobileforensics