Keychain: the Gold Mine of Apple Mobile Devices
Keychain is an essential part of iOS and macOS that securely stores the most critical data: passwords of all kinds, encryption keys, certificates, credit card numbers, and more. Extracting and decrypting the keychain, when possible, is a must in mobile forensics. We seriously improved this part in the latest build of iOS Forensic Toolkit.
π https://blog.elcomsoft.com/2022/07/keychain-the-gold-mine-of-apple-mobile-devices/
#ios #apple #dfir #mobileforensics #keychain #agent
Keychain is an essential part of iOS and macOS that securely stores the most critical data: passwords of all kinds, encryption keys, certificates, credit card numbers, and more. Extracting and decrypting the keychain, when possible, is a must in mobile forensics. We seriously improved this part in the latest build of iOS Forensic Toolkit.
π https://blog.elcomsoft.com/2022/07/keychain-the-gold-mine-of-apple-mobile-devices/
#ios #apple #dfir #mobileforensics #keychain #agent
Building an Efficient Password Recovery Workstation: Power Savings and Waste Heat Management
This article continues the series of publications aimed to help experts specify and build economical and power-efficient workstations for password recovery workloads. Electricity costs, long-term reliability and warranty coverage must be considered when building a password recovery workstation. In this article we will review the most common cooling solutions found in todayβs GPUs, and compare consumer-grade video cards with their much lesser known professional counterparts.
π https://blog.elcomsoft.com/2022/07/building-an-efficient-password-recovery-workstation-power-savings-and-waste-heat-management/
#edpr #gpuacceleration #nvidia #rtx #passwordrecovery
This article continues the series of publications aimed to help experts specify and build economical and power-efficient workstations for password recovery workloads. Electricity costs, long-term reliability and warranty coverage must be considered when building a password recovery workstation. In this article we will review the most common cooling solutions found in todayβs GPUs, and compare consumer-grade video cards with their much lesser known professional counterparts.
π https://blog.elcomsoft.com/2022/07/building-an-efficient-password-recovery-workstation-power-savings-and-waste-heat-management/
#edpr #gpuacceleration #nvidia #rtx #passwordrecovery
Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds iOS 15.6 RC support
Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds forensically sound checkm8-based low-level extraction support for the latest iOS, iPadOS and tvOS 15.6 RC, while also supporting watchOS 8.7 RC. In addition, several fixes are made to the checkm8 extraction engine.
π https://www.elcomsoft.com/news/817.html
#eift #dfir #tvos #watchos #checkm8 #filesystem #keychain
Elcomsoft iOS Forensic Toolkit 8.0 beta 11 adds forensically sound checkm8-based low-level extraction support for the latest iOS, iPadOS and tvOS 15.6 RC, while also supporting watchOS 8.7 RC. In addition, several fixes are made to the checkm8 extraction engine.
π https://www.elcomsoft.com/news/817.html
#eift #dfir #tvos #watchos #checkm8 #filesystem #keychain
Apple TV 4K Keychain and Full File System Acquisition
Mobile forensics is not limited to phones and tablets. Many types of other gadgets, including IoT devices, contain tons of valuable data. Such devices include smart watches, media players, routers, smart home devices, and so on. In this article, we will cover the extraction of an Apple TV 4K, one of the most popular digital media players.
π https://blog.elcomsoft.com/2022/07/apple-tv-4k-keychain-and-full-file-system-acquisition/
#eift #checkm8 #tvos #appletv #dfir #mobileforensics
Mobile forensics is not limited to phones and tablets. Many types of other gadgets, including IoT devices, contain tons of valuable data. Such devices include smart watches, media players, routers, smart home devices, and so on. In this article, we will cover the extraction of an Apple TV 4K, one of the most popular digital media players.
π https://blog.elcomsoft.com/2022/07/apple-tv-4k-keychain-and-full-file-system-acquisition/
#eift #checkm8 #tvos #appletv #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves iPhone 7 extraction
Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves checkm8-based low-level extraction support for the iPhone 7 and iPhone 7 Plus devices running the latest versions of iOS. The new beta drops the requirement to remove the deviceβs screen lock passcode prior to extraction, enabling a clean, forensically sound extraction process.
π https://www.elcomsoft.com/news/818.html
#eift #checkm8 #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.0 beta 12 improves checkm8-based low-level extraction support for the iPhone 7 and iPhone 7 Plus devices running the latest versions of iOS. The new beta drops the requirement to remove the deviceβs screen lock passcode prior to extraction, enabling a clean, forensically sound extraction process.
π https://www.elcomsoft.com/news/818.html
#eift #checkm8 #dfir #mobileforensics
checkm8 Extraction: iPhone 7
Elcomsoft iOS Forensic Toolkit supports checkm8 extraction from all compatible devices ranging from the iPhone 4s and all the way through the iPhone X (as well as the corresponding iPad, iPod Touch, Apple Watch and Apple TV models). The new update removes an important obstacle to the acquisition of the iPhone 7 and iPhone 7 Plus devices running recent versions of iOS.
π https://blog.elcomsoft.com/2022/07/checkm8-extraction-iphone-7/
#eift #iphone7 #checkm8 #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit supports checkm8 extraction from all compatible devices ranging from the iPhone 4s and all the way through the iPhone X (as well as the corresponding iPad, iPod Touch, Apple Watch and Apple TV models). The new update removes an important obstacle to the acquisition of the iPhone 7 and iPhone 7 Plus devices running recent versions of iOS.
π https://blog.elcomsoft.com/2022/07/checkm8-extraction-iphone-7/
#eift #iphone7 #checkm8 #dfir #mobileforensics
Elcomsoft System Recovery 8.30 recovers PIN-protected Windows accounts, supports LUKS2 encryption
Elcomsoft System Recovery, a digital field triage tool, is updated to support PIN-protected Windows 10 and Windows 11 accounts with in-place PIN recovery. The update adds LUKS2 support, detects Microsoft Azure accounts, and improves bootable forensic tools with custom filters.
π Release notes (PDF)
π https://www.elcomsoft.com/news/819.html
#ESR #Windows #MicrosoftAzure #LUKS2
Elcomsoft System Recovery, a digital field triage tool, is updated to support PIN-protected Windows 10 and Windows 11 accounts with in-place PIN recovery. The update adds LUKS2 support, detects Microsoft Azure accounts, and improves bootable forensic tools with custom filters.
π Release notes (PDF)
π https://www.elcomsoft.com/news/819.html
#ESR #Windows #MicrosoftAzure #LUKS2
New in Elcomsoft System Recovery: Microsoft Azure Accounts, LUKS2 and Forensic Tool Filters
Elcomsoft System Recovery 8.30 introduced the ability to break Windows Hello PIN codes on TPM-less computers. This, however, was just one of the many new features added to the updated release. Other features include the ability to detect Microsoft Azure accounts and LUKS2 encryption, as well as new filters for bootable forensic tools.
π https://blog.elcomsoft.com/2022/08/new-in-elcomsoft-system-recovery-microsoft-azure-accounts-luks2-and-forensic-tool-filters/
#ESR #Windows11 #Windows10 #MicrosoftAzure #LUKS2
Elcomsoft System Recovery 8.30 introduced the ability to break Windows Hello PIN codes on TPM-less computers. This, however, was just one of the many new features added to the updated release. Other features include the ability to detect Microsoft Azure accounts and LUKS2 encryption, as well as new filters for bootable forensic tools.
π https://blog.elcomsoft.com/2022/08/new-in-elcomsoft-system-recovery-microsoft-azure-accounts-luks2-and-forensic-tool-filters/
#ESR #Windows11 #Windows10 #MicrosoftAzure #LUKS2
Windows Hello: No TPM No Security
While Windows 11 requires a Trusted Platform Module (TPM), older versions of Windows can do without while still using PIN-based Windows Hello sign-in. We prove that all-digit PINs are a serious security risk on systems without a TPM, and can be broken in a matter of minutes.
π https://blog.elcomsoft.com/2022/08/windows-hello-no-tpm-no-security/
#esr #Windows10 #Windows11 #TPM #edpr #WindowsHello
While Windows 11 requires a Trusted Platform Module (TPM), older versions of Windows can do without while still using PIN-based Windows Hello sign-in. We prove that all-digit PINs are a serious security risk on systems without a TPM, and can be broken in a matter of minutes.
π https://blog.elcomsoft.com/2022/08/windows-hello-no-tpm-no-security/
#esr #Windows10 #Windows11 #TPM #edpr #WindowsHello
Elcomsoft Distributed Password Recovery 4.45 supports Windows Hello PIN codes and LUKS2 encryption
We updated Elcomsoft Distributed Password Recovery and Elcomsoft Forensic Disk Decryptor with support for LUKS2, an updated version of Linux disk encryption tool. The tools work together to extract encryption metadata and launch a password recovery attack. In addition, Elcomsoft Distributed Password Recovery can now break PIN codes protecting Windows accounts on TPM-less systems.
π Release notes (PDF)
π https://www.elcomsoft.com/news/820.html
#LUKS2 #Windows11 #EDPR #EFDD #diskencryption #pincode #dfir
We updated Elcomsoft Distributed Password Recovery and Elcomsoft Forensic Disk Decryptor with support for LUKS2, an updated version of Linux disk encryption tool. The tools work together to extract encryption metadata and launch a password recovery attack. In addition, Elcomsoft Distributed Password Recovery can now break PIN codes protecting Windows accounts on TPM-less systems.
π Release notes (PDF)
π https://www.elcomsoft.com/news/820.html
#LUKS2 #Windows11 #EDPR #EFDD #diskencryption #pincode #dfir
β€1
Breaking Windows Passwords: LM, NTLM, DCC and Windows Hello PIN Compared
Modern versions of Windows have many different types of accounts. Local Windows accounts, Microsoft accounts, and domain accounts feature different types of protection. There is also Windows Hello with PIN codes, which are protected differently from everything else. How secure are these types of passwords, and how can you break them? Read along to find out!
π https://blog.elcomsoft.com/2022/08/breaking-windows-passwords-lm-ntlm-dcc-and-windows-hello-pin-compared/
#edpr #Windows11 #pincode #dfir #windowshello #password
Modern versions of Windows have many different types of accounts. Local Windows accounts, Microsoft accounts, and domain accounts feature different types of protection. There is also Windows Hello with PIN codes, which are protected differently from everything else. How secure are these types of passwords, and how can you break them? Read along to find out!
π https://blog.elcomsoft.com/2022/08/breaking-windows-passwords-lm-ntlm-dcc-and-windows-hello-pin-compared/
#edpr #Windows11 #pincode #dfir #windowshello #password
Probing Linux Disk Encryption: LUKS2, Argon 2 and GPU Acceleration
Disk encryption is widely used desktop and laptop computers. Many non-ZFS Linux distributions rely on LUKS for data protection. LUKS is a classic implementation of disk encryption offering the choice of encryption algorithms, encryption modes and hash functions. LUKS2 further improves the already tough disk encryption. Learn how to deal with LUKS2 encryption in Windows and how to break in with distributed password attacks.
π https://blog.elcomsoft.com/2022/08/probing-linux-disk-encryption-luks2-argon-2-and-gpu-acceleration/
#LUKS2 #EDPR #EFDD #diskencryption #dfir
Disk encryption is widely used desktop and laptop computers. Many non-ZFS Linux distributions rely on LUKS for data protection. LUKS is a classic implementation of disk encryption offering the choice of encryption algorithms, encryption modes and hash functions. LUKS2 further improves the already tough disk encryption. Learn how to deal with LUKS2 encryption in Windows and how to break in with distributed password attacks.
π https://blog.elcomsoft.com/2022/08/probing-linux-disk-encryption-luks2-argon-2-and-gpu-acceleration/
#LUKS2 #EDPR #EFDD #diskencryption #dfir
Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based full file system extraction
Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based extraction support all the way up to iOS 15.3.1 on Apple A11-A15 and M1 devices. The new release delivers full file system extraction for iOS 15.2 through 15.3.1, while still offering file system and keychain extraction support for all earlier versions of iOS.
π https://www.elcomsoft.com/news/821.html
#eift #ios #agent #mobileforensics #dfir
Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based extraction support all the way up to iOS 15.3.1 on Apple A11-A15 and M1 devices. The new release delivers full file system extraction for iOS 15.2 through 15.3.1, while still offering file system and keychain extraction support for all earlier versions of iOS.
π https://www.elcomsoft.com/news/821.html
#eift #ios #agent #mobileforensics #dfir
Low-Level Extraction of iOS 15.2-15.3.1
iOS Forensic Toolkit 7.60 brings gapless low-level extraction support for several iOS versions from iOS 15.2 up to and including iOS 15.3.1, adding full file system extraction support for Apple devices based on Apple A11-A15 and M1 chips.
Read more in our blog π https://blog.elcomsoft.com/2022/08/low-level-extraction-of-ios-15-2-15-3-1/
#eift #ios #apple #dfir #mobileforensics
iOS Forensic Toolkit 7.60 brings gapless low-level extraction support for several iOS versions from iOS 15.2 up to and including iOS 15.3.1, adding full file system extraction support for Apple devices based on Apple A11-A15 and M1 chips.
Read more in our blog π https://blog.elcomsoft.com/2022/08/low-level-extraction-of-ios-15-2-15-3-1/
#eift #ios #apple #dfir #mobileforensics
Entering DFU: iPhone 8, 8 Plus, and iPhone X
DFU (Device Firmware Update) is a special service mode available in many Apple devices for recovering corrupted devices by uploading a clean copy of the firmware. Forensic specialists use DFU during checkm8 extractions (Elcomsoft iOS Forensic Toolkit). Unlike Recovery, which serves a similar purpose, DFU operates on a lower level and is undocumented. Surprisingly, there might be more than one DFU mode, one being more reliable than the others when it comes to forensic extractions. The method described in this article works for the iPhone 8, 8 Plus and iPhone X.
π https://blog.elcomsoft.com/2022/09/entering-dfu-iphone-8-8-plus-and-iphone-x/
#iphone #DFU #iOS #eift #mobileforensics
DFU (Device Firmware Update) is a special service mode available in many Apple devices for recovering corrupted devices by uploading a clean copy of the firmware. Forensic specialists use DFU during checkm8 extractions (Elcomsoft iOS Forensic Toolkit). Unlike Recovery, which serves a similar purpose, DFU operates on a lower level and is undocumented. Surprisingly, there might be more than one DFU mode, one being more reliable than the others when it comes to forensic extractions. The method described in this article works for the iPhone 8, 8 Plus and iPhone X.
π https://blog.elcomsoft.com/2022/09/entering-dfu-iphone-8-8-plus-and-iphone-x/
#iphone #DFU #iOS #eift #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.0 brings forensically sound bootloader-based extraction for select iPhone & iPad models
Elcomsoft iOS Forensic Toolkit 8.0 is a major release bringing support for repeatable, verifiable, and truly forensically sound bootloader-level extraction of 76 Apple devices ranging from the ancient iPhone 4 all the way up to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models, and featuring a refreshed, command-line driven user interface.
π https://www.elcomsoft.com/news/822.html
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16
Elcomsoft iOS Forensic Toolkit 8.0 is a major release bringing support for repeatable, verifiable, and truly forensically sound bootloader-level extraction of 76 Apple devices ranging from the ancient iPhone 4 all the way up to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models, and featuring a refreshed, command-line driven user interface.
π https://www.elcomsoft.com/news/822.html
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16
iOS 16: Extracting the File System and Keychain from A11 Devices
Bootloader-based acquisition is the only 100% forensically sound data extraction method for Apple devices. It is the only way to acquire the full set of data from those devices that run iOS 16, albeit with a huge caveat that makes the whole thing more of a brain exercise than a practical forensic tool. Letβs review the iOS 16 compatibility in iOS Forensic Toolkit and go through the whole process step by step.
π https://blog.elcomsoft.com/2022/09/ios-16-extracting-the-file-system-and-keychain-from-a11-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
Bootloader-based acquisition is the only 100% forensically sound data extraction method for Apple devices. It is the only way to acquire the full set of data from those devices that run iOS 16, albeit with a huge caveat that makes the whole thing more of a brain exercise than a practical forensic tool. Letβs review the iOS 16 compatibility in iOS Forensic Toolkit and go through the whole process step by step.
π https://blog.elcomsoft.com/2022/09/ios-16-extracting-the-file-system-and-keychain-from-a11-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
iOS Forensic Toolkit 8.0 Now Official: Bootloader-Level Extraction for 76 Devices
iOS Forensic Toolkit 8.0 is officially released! Delivering forensically sound checkm8 extraction and a new command-line driven user experience, the new release becomes the most sophisticated mobile forensic tool weβve released to date.
ππ» https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-now-official-bootloader-level-extraction-for-76-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
iOS Forensic Toolkit 8.0 is officially released! Delivering forensically sound checkm8 extraction and a new command-line driven user experience, the new release becomes the most sophisticated mobile forensic tool weβve released to date.
ππ» https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-now-official-bootloader-level-extraction-for-76-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
iOS 16: SEP Hardening, New Security Measures and Their Forensic Implications
iOS 16 brings many changes to mobile forensics. Users receive additional tools to control the sharing and protection of their personal information, while forensic experts will face tighter security measures. In this review, weβll talk about the things in iOS 16 that are likely to affect the forensic workflow.
ππ» https://blog.elcomsoft.com/2022/09/ios-16-sep-hardening-new-security-measures-and-their-forensic-implications/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #checkm8
iOS 16 brings many changes to mobile forensics. Users receive additional tools to control the sharing and protection of their personal information, while forensic experts will face tighter security measures. In this review, weβll talk about the things in iOS 16 that are likely to affect the forensic workflow.
ππ» https://blog.elcomsoft.com/2022/09/ios-16-sep-hardening-new-security-measures-and-their-forensic-implications/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #checkm8
How to Put Apple TV 3 (2012-2013), Apple TV HD (2015) and Apple TV 4K (2017) into DFU
The title says it all. In this article weβll explain the steps required to put the listed Apple TV models into DFU mode. These Apple TV models are based on the A5, A8, and A10X chips that are susceptible to the checkm8 exploit and checkm8-based extraction with iOS Forensic Toolkit 8, and DFU mode is the required initial step of the process.
π https://blog.elcomsoft.com/2022/10/how-to-put-apple-tv-3-2012-2013-apple-tv-hd-2015-and-apple-tv-4k-2017-into-dfu/
#dfu #appletv #eift #mobileforensics #dfir
The title says it all. In this article weβll explain the steps required to put the listed Apple TV models into DFU mode. These Apple TV models are based on the A5, A8, and A10X chips that are susceptible to the checkm8 exploit and checkm8-based extraction with iOS Forensic Toolkit 8, and DFU mode is the required initial step of the process.
π https://blog.elcomsoft.com/2022/10/how-to-put-apple-tv-3-2012-2013-apple-tv-hd-2015-and-apple-tv-4k-2017-into-dfu/
#dfu #appletv #eift #mobileforensics #dfir
Elcomsoft Phone Breaker 10.12: better compatibility, iCloud-related improvements
Elcomsoft Phone Breaker 10.12 fixes bugs and improves compatibility with Windows 11, macOS 12 and 13. The new build also improves compatibility with iOS 16 backups and recognizes iCloud backups created by iPhone 14 series and iPhone SE 2022 devices.
π https://www.elcomsoft.com/news/823.html
#phonebreaker #dfir #mobileforensics #icloud #ios16
Elcomsoft Phone Breaker 10.12 fixes bugs and improves compatibility with Windows 11, macOS 12 and 13. The new build also improves compatibility with iOS 16 backups and recognizes iCloud backups created by iPhone 14 series and iPhone SE 2022 devices.
π https://www.elcomsoft.com/news/823.html
#phonebreaker #dfir #mobileforensics #icloud #ios16