Elcomsoft
547 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Elcomsoft Distributed Password Recovery 4.4 optimized for Intel Alder Lake

Elcomsoft Distributed Password Recovery 4.44 is updated with optimizations for Intelโ€™s 12th-generation hybrid architecture. The updated tool is now fully ready for the heterogeneous computing introduced in Intel Alder Lake CPUs.

๐Ÿ‘‰ https://www.elcomsoft.com/news/813.html

#edpr #intel #alderlake #passwordrecovery
Breaking Passwords on Alder Lake CPUs

In Alder Lake, Intel introduced hybrid architecture. Large, hyperthreading-enabled Performance cores are complemented with smaller, single-thread Efficiency cores. The host OS is responsible for assigning threads to one core or another. We discovered that Windows 10 scheduler is not doing a perfect job when it comes to password recovery, which requires a careful approach to thread scheduling.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/05/breaking-passwords-on-alder-lake-cpus/

#edpr #intel #alderlake #passwordrecovery
Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based full file system extraction

Elcomsoft iOS Forensic Toolkit 7.40 extends agent-based extraction support all the way up to iOS 15.1 on all supported devices. The new release fills the gap in iOS 14 support, adding agent-based extraction for devices running iOS 14.8.1 for all devices and iOS 14.3 through 14.8.1 for models based on Apple A14 Bionic. Using an Apple Developer account is required in Windows, optional but strongly recommended in macOS.

๐Ÿ‘‰ https://www.elcomsoft.com/news/814.html

#EIFT #dfir #ios14 #iphone #mobileforensics #agent
Filling the Gaps: iOS 14 Full File System Extracted

iOS Forensic Toolkit 7.40 brings gapless low-level extraction support for several iOS versions up to and including iOS 15.1 (15.1.1 on some devices), adding compatibility with previously unsupported versions of iOS 14.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/filling-the-gaps-ios-14-full-file-system-extracted/

#eift #ios14 #iphone #mobileforensics #dfir #agent
Elcomsoft iOS Forensic Toolkit 8.0 beta 9 adds checkm8 extraction of 14 iPad and iPod Touch devices

The ninth beta of Elcomsoft iOS Forensic Toolkit 8.0 for Mac brings forensically sound, checkm8-based extraction of ten iPad and four iPod Touch models, as well as two Apple TV models. The low-level extraction solution is available directly for most devices, with select models requiring a Raspberry Pi Pico board to apply the exploit.

๐Ÿ‘‰ https://www.elcomsoft.com/news/815.html

#iphone #ipad #ios #eift #dfir #mobileforensics
checkm8 Extraction: the iPads, iPods, and TVs

The ninth beta of iOS Forensic Toolkit 8.0 for Mac introduces forensically sound, checkm8-based extraction of sixteen iPad, iPod Touch and Apple TV models. The low-level extraction solution is now available for all iPad and all iPod Touch models susceptible to the checkm8 exploit.

checkm8 is applicable to all devices with bootloader vulnerability, yet there are technical differences when it comes to implementing the exploit on the various devices. In this update we are targeting non-iPhone devices, spending efforts to support the many iPads equipped with the corresponding SoCs. While other vendors have been offering their own implementations of checkm8 extraction for quite a while, we found their solutions to lack in device/iOS version coverage and miss the โ€œforensically soundโ€ mark.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/checkm8-extraction-the-ipads-ipods-and-tvs/

#ipad #ios #apple #dfir #eift #checkm8 #mobileforensics
Logical Acquisition: Not as Simple as It Sounds

Speaking of mobile devices, especially Appleโ€™s, โ€œlogical acquisitionโ€ is probably the most misused term. Are you sure you know what it is and how to properly use it, especially if you are working in mobile forensics? Let us shed some light on it.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/logical-acquisition-not-as-simple-as-it-sounds/

#ios #iphone #icloud #itunes #dfir #mobileforensics #logicalacquisition
GPU Acceleration: Attacking Passwords with NVIDIA RTX Series Boards

Todayโ€™s data protection methods utilize many thousands (sometimes millions) hash iterations to strengthen password protection, slowing down the attacks to a crawl. Consumer-grade video cards are commonly used for GPU acceleration. How do these video cards compare, and what about the price-performance ratio? We tested five reasonably priced NVIDIA boards ranging from the lowly GTX 1650 to RTX 3060 Ti.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/gpu-acceleration-attacking-passwords-with-nvidia-rtx-series/

#edpr #gpu #dfir #password #passwordrecovery #digitalforensics
Full File System and Keychain Acquisition: What, When, and How

We often write about full file system acquisition, yet we rarely explain what it is, when you can do it, and which methods you can use. We decided to clarify low-level extraction of Apple mobile devices (iPhones and iPads, and some other IoT devices such as Apple TVs and Apple Watches).

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/06/full-file-system-and-keychain-acquisition-what-when-and-how/

#filesystem #ios #eift #checkm8 #dfir #agent
iCloud backups: the Dark Territory

Apple ecosystem includes a comprehensive backup ecosystem that includes both local and cloud backups, and data synchronization with end-to-end encryption for some categories. Today weโ€™ll discuss the iCloud backups, particularly targeting issues that are not covered in the official documentation.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/icloud-backups-the-dark-territory/

#epb #e2ee #icloud #icloudbackup
Elcomsoft iOS Forensic Toolkit 7.50 closes the gap in keychain extraction

Elcomsoft iOS Forensic Toolkit 7.50 extends agent-based keychain extraction support all the way up to iOS 15.1.1 on all supported devices. The new release fills the remaining gaps in iOS 14 support, adding agent-based keychain extraction for iOS 14.5 โ€“ 14.8.1 and iOS 15.0 โ€“ 15.1.1 devices.

๐Ÿ‘‰ https://www.elcomsoft.com/news/816.html

#ios #apple #iphone #agent #mobileforensics #dfir
Keychain: the Gold Mine of Apple Mobile Devices

Keychain is an essential part of iOS and macOS that securely stores the most critical data: passwords of all kinds, encryption keys, certificates, credit card numbers, and more. Extracting and decrypting the keychain, when possible, is a must in mobile forensics. We seriously improved this part in the latest build of iOS Forensic Toolkit.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/keychain-the-gold-mine-of-apple-mobile-devices/

#ios #apple #dfir #mobileforensics #keychain #agent
Building an Efficient Password Recovery Workstation: Power Savings and Waste Heat Management

This article continues the series of publications aimed to help experts specify and build economical and power-efficient workstations for password recovery workloads. Electricity costs, long-term reliability and warranty coverage must be considered when building a password recovery workstation. In this article we will review the most common cooling solutions found in todayโ€™s GPUs, and compare consumer-grade video cards with their much lesser known professional counterparts.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/building-an-efficient-password-recovery-workstation-power-savings-and-waste-heat-management/

#edpr #gpuacceleration #nvidia #rtx #passwordrecovery
Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds iOS 15.6 RC support

Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds forensically sound checkm8-based low-level extraction support for the latest iOS, iPadOS and tvOS 15.6 RC, while also supporting watchOS 8.7 RC. In addition, several fixes are made to the checkm8 extraction engine.

๐Ÿ‘‰ https://www.elcomsoft.com/news/817.html

#eift #dfir #tvos #watchos #checkm8 #filesystem #keychain
Apple TV 4K Keychain and Full File System Acquisition

Mobile forensics is not limited to phones and tablets. Many types of other gadgets, including IoT devices, contain tons of valuable data. Such devices include smart watches, media players, routers, smart home devices, and so on. In this article, we will cover the extraction of an Apple TV 4K, one of the most popular digital media players.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/apple-tv-4k-keychain-and-full-file-system-acquisition/

#eift #checkm8 #tvos #appletv #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves iPhone 7 extraction

Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves checkm8-based low-level extraction support for the iPhone 7 and iPhone 7 Plus devices running the latest versions of iOS. The new beta drops the requirement to remove the deviceโ€™s screen lock passcode prior to extraction, enabling a clean, forensically sound extraction process.

๐Ÿ‘‰ https://www.elcomsoft.com/news/818.html

#eift #checkm8 #dfir #mobileforensics
checkm8 Extraction: iPhone 7

Elcomsoft iOS Forensic Toolkit supports checkm8 extraction from all compatible devices ranging from the iPhone 4s and all the way through the iPhone X (as well as the corresponding iPad, iPod Touch, Apple Watch and Apple TV models). The new update removes an important obstacle to the acquisition of the iPhone 7 and iPhone 7 Plus devices running recent versions of iOS.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/07/checkm8-extraction-iphone-7/

#eift #iphone7 #checkm8 #dfir #mobileforensics
Elcomsoft System Recovery 8.30 recovers PIN-protected Windows accounts, supports LUKS2 encryption

Elcomsoft System Recovery, a digital field triage tool, is updated to support PIN-protected Windows 10 and Windows 11 accounts with in-place PIN recovery. The update adds LUKS2 support, detects Microsoft Azure accounts, and improves bootable forensic tools with custom filters.

๐Ÿ“ Release notes (PDF)

๐Ÿ‘‰ https://www.elcomsoft.com/news/819.html

#ESR #Windows #MicrosoftAzure #LUKS2
New in Elcomsoft System Recovery: Microsoft Azure Accounts, LUKS2 and Forensic Tool Filters

Elcomsoft System Recovery 8.30 introduced the ability to break Windows Hello PIN codes on TPM-less computers. This, however, was just one of the many new features added to the updated release. Other features include the ability to detect Microsoft Azure accounts and LUKS2 encryption, as well as new filters for bootable forensic tools.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/08/new-in-elcomsoft-system-recovery-microsoft-azure-accounts-luks2-and-forensic-tool-filters/

#ESR #Windows11 #Windows10 #MicrosoftAzure #LUKS2
Windows Hello: No TPM No Security

While Windows 11 requires a Trusted Platform Module (TPM), older versions of Windows can do without while still using PIN-based Windows Hello sign-in. We prove that all-digit PINs are a serious security risk on systems without a TPM, and can be broken in a matter of minutes.

๐Ÿ‘‰ https://blog.elcomsoft.com/2022/08/windows-hello-no-tpm-no-security/

#esr #Windows10 #Windows11 #TPM #edpr #WindowsHello
Elcomsoft Distributed Password Recovery 4.45 supports Windows Hello PIN codes and LUKS2 encryption

We updated Elcomsoft Distributed Password Recovery and Elcomsoft Forensic Disk Decryptor with support for LUKS2, an updated version of Linux disk encryption tool. The tools work together to extract encryption metadata and launch a password recovery attack. In addition, Elcomsoft Distributed Password Recovery can now break PIN codes protecting Windows accounts on TPM-less systems.

๐Ÿ“ Release notes (PDF)

๐Ÿ‘‰ https://www.elcomsoft.com/news/820.html

#LUKS2 #Windows11 #EDPR #EFDD #diskencryption #pincode #dfir
โค1