Elcomsoft iOS Forensic Toolkit 8.0 brings forensically sound bootloader-based extraction for select iPhone & iPad models
Elcomsoft iOS Forensic Toolkit 8.0 is a major release bringing support for repeatable, verifiable, and truly forensically sound bootloader-level extraction of 76 Apple devices ranging from the ancient iPhone 4 all the way up to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models, and featuring a refreshed, command-line driven user interface.
๐ https://www.elcomsoft.com/news/822.html
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16
Elcomsoft iOS Forensic Toolkit 8.0 is a major release bringing support for repeatable, verifiable, and truly forensically sound bootloader-level extraction of 76 Apple devices ranging from the ancient iPhone 4 all the way up to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models, and featuring a refreshed, command-line driven user interface.
๐ https://www.elcomsoft.com/news/822.html
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16
iOS 16: Extracting the File System and Keychain from A11 Devices
Bootloader-based acquisition is the only 100% forensically sound data extraction method for Apple devices. It is the only way to acquire the full set of data from those devices that run iOS 16, albeit with a huge caveat that makes the whole thing more of a brain exercise than a practical forensic tool. Letโs review the iOS 16 compatibility in iOS Forensic Toolkit and go through the whole process step by step.
๐ https://blog.elcomsoft.com/2022/09/ios-16-extracting-the-file-system-and-keychain-from-a11-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
Bootloader-based acquisition is the only 100% forensically sound data extraction method for Apple devices. It is the only way to acquire the full set of data from those devices that run iOS 16, albeit with a huge caveat that makes the whole thing more of a brain exercise than a practical forensic tool. Letโs review the iOS 16 compatibility in iOS Forensic Toolkit and go through the whole process step by step.
๐ https://blog.elcomsoft.com/2022/09/ios-16-extracting-the-file-system-and-keychain-from-a11-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
iOS Forensic Toolkit 8.0 Now Official: Bootloader-Level Extraction for 76 Devices
iOS Forensic Toolkit 8.0 is officially released! Delivering forensically sound checkm8 extraction and a new command-line driven user experience, the new release becomes the most sophisticated mobile forensic tool weโve released to date.
๐๐ป https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-now-official-bootloader-level-extraction-for-76-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
iOS Forensic Toolkit 8.0 is officially released! Delivering forensically sound checkm8 extraction and a new command-line driven user experience, the new release becomes the most sophisticated mobile forensic tool weโve released to date.
๐๐ป https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-now-official-bootloader-level-extraction-for-76-devices/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
iOS 16: SEP Hardening, New Security Measures and Their Forensic Implications
iOS 16 brings many changes to mobile forensics. Users receive additional tools to control the sharing and protection of their personal information, while forensic experts will face tighter security measures. In this review, weโll talk about the things in iOS 16 that are likely to affect the forensic workflow.
๐๐ป https://blog.elcomsoft.com/2022/09/ios-16-sep-hardening-new-security-measures-and-their-forensic-implications/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #checkm8
iOS 16 brings many changes to mobile forensics. Users receive additional tools to control the sharing and protection of their personal information, while forensic experts will face tighter security measures. In this review, weโll talk about the things in iOS 16 that are likely to affect the forensic workflow.
๐๐ป https://blog.elcomsoft.com/2022/09/ios-16-sep-hardening-new-security-measures-and-their-forensic-implications/
#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #checkm8
How to Put Apple TV 3 (2012-2013), Apple TV HD (2015) and Apple TV 4K (2017) into DFU
The title says it all. In this article weโll explain the steps required to put the listed Apple TV models into DFU mode. These Apple TV models are based on the A5, A8, and A10X chips that are susceptible to the checkm8 exploit and checkm8-based extraction with iOS Forensic Toolkit 8, and DFU mode is the required initial step of the process.
๐ https://blog.elcomsoft.com/2022/10/how-to-put-apple-tv-3-2012-2013-apple-tv-hd-2015-and-apple-tv-4k-2017-into-dfu/
#dfu #appletv #eift #mobileforensics #dfir
The title says it all. In this article weโll explain the steps required to put the listed Apple TV models into DFU mode. These Apple TV models are based on the A5, A8, and A10X chips that are susceptible to the checkm8 exploit and checkm8-based extraction with iOS Forensic Toolkit 8, and DFU mode is the required initial step of the process.
๐ https://blog.elcomsoft.com/2022/10/how-to-put-apple-tv-3-2012-2013-apple-tv-hd-2015-and-apple-tv-4k-2017-into-dfu/
#dfu #appletv #eift #mobileforensics #dfir
Elcomsoft Phone Breaker 10.12: better compatibility, iCloud-related improvements
Elcomsoft Phone Breaker 10.12 fixes bugs and improves compatibility with Windows 11, macOS 12 and 13. The new build also improves compatibility with iOS 16 backups and recognizes iCloud backups created by iPhone 14 series and iPhone SE 2022 devices.
๐ https://www.elcomsoft.com/news/823.html
#phonebreaker #dfir #mobileforensics #icloud #ios16
Elcomsoft Phone Breaker 10.12 fixes bugs and improves compatibility with Windows 11, macOS 12 and 13. The new build also improves compatibility with iOS 16 backups and recognizes iCloud backups created by iPhone 14 series and iPhone SE 2022 devices.
๐ https://www.elcomsoft.com/news/823.html
#phonebreaker #dfir #mobileforensics #icloud #ios16
checkm8 Extraction Cheat Sheet: iPhone and iPad Devices
The newly released iOS Forensic Toolkit 8.0 delivers forensically sound checkm8 extraction powered with a command-line interface. The new user experience offers full control over the extraction process, yet mastering the right workflow may become a challenge for those unfamiliar with command-line tools. In this quick-start guide we will lay out the steps required to perform a clean, forensically sound extraction of a compatible iPhone or iPad device.
๐ https://blog.elcomsoft.com/2022/11/checkm8-extraction-cheat-sheet-iphone-and-ipad-devices/
#eift #toolkit #checkm8 #ios16 #dfir #dfu #mobileforensics
The newly released iOS Forensic Toolkit 8.0 delivers forensically sound checkm8 extraction powered with a command-line interface. The new user experience offers full control over the extraction process, yet mastering the right workflow may become a challenge for those unfamiliar with command-line tools. In this quick-start guide we will lay out the steps required to perform a clean, forensically sound extraction of a compatible iPhone or iPad device.
๐ https://blog.elcomsoft.com/2022/11/checkm8-extraction-cheat-sheet-iphone-and-ipad-devices/
#eift #toolkit #checkm8 #ios16 #dfir #dfu #mobileforensics
iOS Backups: Leftover Passwords
In Apple ecosystem, logical acquisition is the most convenient and the most compatible extraction method, with local backups being a major contributor. Password-protected backups contain significantly more information than unencrypted backups, which is why many forensic tools including iOS Forensic Toolkit automatically apply a temporary backup password before creating a backup. If a temporary password is not removed after the extraction, subsequent extraction attempts, especially made with a different tool, will produce encrypted backups protected with an effectively unknown password. In this article weโll talk about why this happens and how to deal with it.
๐ https://blog.elcomsoft.com/2022/11/ios-backups-leftover-passwords/
#EDPR #EIFT #PhoneBreaker #password #iOS #iTunes
In Apple ecosystem, logical acquisition is the most convenient and the most compatible extraction method, with local backups being a major contributor. Password-protected backups contain significantly more information than unencrypted backups, which is why many forensic tools including iOS Forensic Toolkit automatically apply a temporary backup password before creating a backup. If a temporary password is not removed after the extraction, subsequent extraction attempts, especially made with a different tool, will produce encrypted backups protected with an effectively unknown password. In this article weโll talk about why this happens and how to deal with it.
๐ https://blog.elcomsoft.com/2022/11/ios-backups-leftover-passwords/
#EDPR #EIFT #PhoneBreaker #password #iOS #iTunes
Advanced Logical Extraction with iOS Forensic Toolkit 8: Cheat Sheet
Advanced logical acquisition is the most compatible and least complicated way to access essential evidence stored in Apple devices. In legacy versions of iOS Forensic Toolkit, we offered a 1-2-3 style, menu-driven extraction experience, while the updated release of iOS Forensic Toolkit 8.0 is driven by the command line. In this quick-start guide we will lay out the steps required to extract the most amount of data from Apple devices via the advanced logical process.
๐ https://blog.elcomsoft.com/2022/11/advanced-logical-extraction-with-ios-forensic-toolkit-8-cheat-sheet/
#eift #toolkit #ios #logicalacquisition #dfir #mobileforensics
Advanced logical acquisition is the most compatible and least complicated way to access essential evidence stored in Apple devices. In legacy versions of iOS Forensic Toolkit, we offered a 1-2-3 style, menu-driven extraction experience, while the updated release of iOS Forensic Toolkit 8.0 is driven by the command line. In this quick-start guide we will lay out the steps required to extract the most amount of data from Apple devices via the advanced logical process.
๐ https://blog.elcomsoft.com/2022/11/advanced-logical-extraction-with-ios-forensic-toolkit-8-cheat-sheet/
#eift #toolkit #ios #logicalacquisition #dfir #mobileforensics
Cloud Forensics: Obtaining iCloud Backups, Media Files and Synchronized Data
Apple offers by far the most sophisticated solution for backing up, restoring, transferring and synchronizing data across devices belonging to the companyโs ecosystem. Apple iCloud can store cloud backups and media files, synchronize essential information between Apple devices, and keep highly sensitive information such as Health and authentication credentials securely synchronized. In this article weโll explain what kinds of data are stored in iCloud and what you need to access them.
๐ https://blog.elcomsoft.com/2022/11/cloud-forensics-obtaining-icloud-backups-media-files-and-synchronized-data/
#cloudforensics #PhoneBreaker #EPB #iCloud #backup #iOS #dfir
Apple offers by far the most sophisticated solution for backing up, restoring, transferring and synchronizing data across devices belonging to the companyโs ecosystem. Apple iCloud can store cloud backups and media files, synchronize essential information between Apple devices, and keep highly sensitive information such as Health and authentication credentials securely synchronized. In this article weโll explain what kinds of data are stored in iCloud and what you need to access them.
๐ https://blog.elcomsoft.com/2022/11/cloud-forensics-obtaining-icloud-backups-media-files-and-synchronized-data/
#cloudforensics #PhoneBreaker #EPB #iCloud #backup #iOS #dfir
iOS Forensic Toolkit 8 Extraction Agent Cheat Sheet
iOS Forensic Toolkit 8 brings new powerful user experience based on the command line. While this approach offers experts full control over the extraction process, mastering the right workflow may become a challenge for those unfamiliar with command-line tools. In this quick-start guide we will lay out the steps required to extract the file system and decrypt the keychain of a compatible iPhone or iPad device.
๐ https://blog.elcomsoft.com/2022/11/ios-forensic-toolkit-8-extraction-agent-cheat-sheet/
#ios #eift #extractionagent #dfir #mobileforensics
iOS Forensic Toolkit 8 brings new powerful user experience based on the command line. While this approach offers experts full control over the extraction process, mastering the right workflow may become a challenge for those unfamiliar with command-line tools. In this quick-start guide we will lay out the steps required to extract the file system and decrypt the keychain of a compatible iPhone or iPad device.
๐ https://blog.elcomsoft.com/2022/11/ios-forensic-toolkit-8-extraction-agent-cheat-sheet/
#ios #eift #extractionagent #dfir #mobileforensics
Approaching iOS Extractions: Choosing the Right Acquisition Method
The extraction method or methods available for a particular iOS device depend on the deviceโs hardware platform and the installed version of iOS. While logical acquisition is available for all iOS and iPadOS devices, more advanced extraction methods are available for older platforms and versions of iOS. But what if more than one way to extract the data is available for a given device? In this guide, weโll discuss the applicable acquisition methods as well as the order in which they should be used.
๐ https://blog.elcomsoft.com/2022/11/approaching-ios-extractions-choosing-the-right-acquisition-method/
#ios #checkm8 #agent #edpr #eift #toolkit #dfir #mobileforensics #dataextraction
The extraction method or methods available for a particular iOS device depend on the deviceโs hardware platform and the installed version of iOS. While logical acquisition is available for all iOS and iPadOS devices, more advanced extraction methods are available for older platforms and versions of iOS. But what if more than one way to extract the data is available for a given device? In this guide, weโll discuss the applicable acquisition methods as well as the order in which they should be used.
๐ https://blog.elcomsoft.com/2022/11/approaching-ios-extractions-choosing-the-right-acquisition-method/
#ios #checkm8 #agent #edpr #eift #toolkit #dfir #mobileforensics #dataextraction
iOS Forensic Toolkit 8 Apple Watch S3 checkm8 Extraction Cheat Sheet
checkm8 is the only extraction method available for the Apple Watch S3 allowing full access to essential evidence stored in the device. In this guide, we will talk about connecting the Apple Watch S3 to the computer, placing the watch into DFU mode, applying the checkm8 exploit and extracting the file system from the device with iOS Forensic Toolkit 8.0.
๐ https://blog.elcomsoft.com/2022/11/ios-forensic-toolkit-8-apple-watch-s3-checkm8-extraction-cheat-sheet/
#applewatch #checkm8 #eift #dfir
checkm8 is the only extraction method available for the Apple Watch S3 allowing full access to essential evidence stored in the device. In this guide, we will talk about connecting the Apple Watch S3 to the computer, placing the watch into DFU mode, applying the checkm8 exploit and extracting the file system from the device with iOS Forensic Toolkit 8.0.
๐ https://blog.elcomsoft.com/2022/11/ios-forensic-toolkit-8-apple-watch-s3-checkm8-extraction-cheat-sheet/
#applewatch #checkm8 #eift #dfir
iOS Forensic Toolkit 8: Apple TV 3, 4, and 4K checkm8 Extraction Cheat Sheet
Several generations of Apple TV devices have a bootloader vulnerability that can be exploited with checkm8 to extract information from the device. The vulnerability exists in the Apple TV 3 (2012 and 2013), Apple TV HD (formerly Apple TV 4) 2015 and 2021, and Apple TV 4K (2017). Newer generations of Apple TV do not have the vulnerability. This guide lists the tools and steps required to fully extract a compatible Apple TV device.
๐ https://blog.elcomsoft.com/2022/12/ios-forensic-toolkit-8-apple-tv-3-4-and-4k-checkm8-extraction-cheat-sheet/
#EIFT #appleTV #checkm8 #dfir
Several generations of Apple TV devices have a bootloader vulnerability that can be exploited with checkm8 to extract information from the device. The vulnerability exists in the Apple TV 3 (2012 and 2013), Apple TV HD (formerly Apple TV 4) 2015 and 2021, and Apple TV 4K (2017). Newer generations of Apple TV do not have the vulnerability. This guide lists the tools and steps required to fully extract a compatible Apple TV device.
๐ https://blog.elcomsoft.com/2022/12/ios-forensic-toolkit-8-apple-tv-3-4-and-4k-checkm8-extraction-cheat-sheet/
#EIFT #appleTV #checkm8 #dfir
Windows Account Passwords: Why and How to Break NTLM Credentials
Windows account passwords, or NTLM passwords, are among the easiest to recover due to their relatively low cryptographic strength. At the same time, NTLM passwords can be used to unlock DPAPI-protected data such as the userโs passwords stored in Web browsers, encrypted chats, EFS-protected files and folders, and a lot more. In this article we argue about prioritizing the recovery of NTLM hashes over any other types of encrypted data.
๐ https://blog.elcomsoft.com/2022/12/windows-account-passwords-why-and-how-to-break-ntlm-credentials/
#windows #ntlm #password #edpr #dpapi #microsoftaccount
Windows account passwords, or NTLM passwords, are among the easiest to recover due to their relatively low cryptographic strength. At the same time, NTLM passwords can be used to unlock DPAPI-protected data such as the userโs passwords stored in Web browsers, encrypted chats, EFS-protected files and folders, and a lot more. In this article we argue about prioritizing the recovery of NTLM hashes over any other types of encrypted data.
๐ https://blog.elcomsoft.com/2022/12/windows-account-passwords-why-and-how-to-break-ntlm-credentials/
#windows #ntlm #password #edpr #dpapi #microsoftaccount
Elcomsoft Phone Viewer 5.40 updated for iOS 16
Elcomsoft Phone Viewer gains full support for the updated local and cloud backup formats introduced in iOS 16. The tool can now display the content of iTunes and iCloud backups and synchronized data produced by devices running the new OS. In addition, Elcomsoft Phone Viewer 5.40 adds support for file system images obtained from devices running iOS 16.
๐ https://www.elcomsoft.com/news/825.html
#EPV #iCloud #iOS16 #dfir #mobileforensics
Elcomsoft Phone Viewer gains full support for the updated local and cloud backup formats introduced in iOS 16. The tool can now display the content of iTunes and iCloud backups and synchronized data produced by devices running the new OS. In addition, Elcomsoft Phone Viewer 5.40 adds support for file system images obtained from devices running iOS 16.
๐ https://www.elcomsoft.com/news/825.html
#EPV #iCloud #iOS16 #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.10 adds checkm8 extraction for iOS 16.2, fixes extraction agent signing
Elcomsoft iOS Forensic Toolkit 8.10 adds forensically sound checkm8 extraction support for iOS, iPadOS and tvOS 16.2. We are also bumping agent-based extraction support to iOS 15.5, and updating Elcomsoft iOS Forensic Toolkit 7.70 to fix the extraction agent installation issues in the Windows edition.
๐งโ๐ป https://www.elcomsoft.com/news/826.html
#EIFT #ios16 #agentextractor #DFIR #mobileforensics #checkm8
Elcomsoft iOS Forensic Toolkit 8.10 adds forensically sound checkm8 extraction support for iOS, iPadOS and tvOS 16.2. We are also bumping agent-based extraction support to iOS 15.5, and updating Elcomsoft iOS Forensic Toolkit 7.70 to fix the extraction agent installation issues in the Windows edition.
#EIFT #ios16 #agentextractor #DFIR #mobileforensics #checkm8
Please open Telegram to view this post
VIEW IN TELEGRAM
checkm8 for iOS 16.2 and Windows-based iOS Low-Level Extraction
Just before the turn of the year, weโve made an important update to Elcomsoft iOS Forensic Toolkit, a low-level iOS file system extraction and keychain decryption tool. The update brings checkm8 support to iOS, iPadOS and tvOS 16.2 devices, and enables agent-based low-level extraction of iOS 15.5. Weโve also fixed whatโs been long broken: the ability to sideload the extraction agent from Windows PCs, yet the two updates are delivered in different branches. Sounds confusing? Weโre here to solve it for you.
๐งโ๐ป https://blog.elcomsoft.com/2022/12/checkm8-for-ios-16-2-and-windows-based-ios-low-level-extraction/
#EIFT #ios16 #checkm8 #DFIR #mobileforensics #agentextractor
Just before the turn of the year, weโve made an important update to Elcomsoft iOS Forensic Toolkit, a low-level iOS file system extraction and keychain decryption tool. The update brings checkm8 support to iOS, iPadOS and tvOS 16.2 devices, and enables agent-based low-level extraction of iOS 15.5. Weโve also fixed whatโs been long broken: the ability to sideload the extraction agent from Windows PCs, yet the two updates are delivered in different branches. Sounds confusing? Weโre here to solve it for you.
#EIFT #ios16 #checkm8 #DFIR #mobileforensics #agentextractor
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft iOS Forensic Toolkit 8.11 decrypts iOS 15.5 keychain
Elcomsoft iOS Forensic Toolkit 8.11 adds the ability to extract and decrypt the keychain from devices running all versions of iOS/iPadOS up to and including 15.5. The Windows edition is currently available in iOS Forensic Toolkit 7.71, which receives the same update.
๐งโ๐ป https://www.elcomsoft.com/news/827.html
#ios #EIFT #mobileforensics #keychain #ios15
Elcomsoft iOS Forensic Toolkit 8.11 adds the ability to extract and decrypt the keychain from devices running all versions of iOS/iPadOS up to and including 15.5. The Windows edition is currently available in iOS Forensic Toolkit 7.71, which receives the same update.
๐งโ๐ป https://www.elcomsoft.com/news/827.html
#ios #EIFT #mobileforensics #keychain #ios15
Use The Brute Force, Luke
There are several methods for recovering the original password ranging from brute force to very complex rule-based attacks. Brute-force attacks are a last resort when all other options are exhausted. What can you reasonably expect of a brute-force attack, what is the chance of success, and how does it depend on the password and the data? Or just โhow long will it take you to break itโ? Letโs try to find out.
๐งโ๐ป https://blog.elcomsoft.com/2023/01/use-the-brute-force-luke/
#passwordrecovery #bruteforce #edpr
There are several methods for recovering the original password ranging from brute force to very complex rule-based attacks. Brute-force attacks are a last resort when all other options are exhausted. What can you reasonably expect of a brute-force attack, what is the chance of success, and how does it depend on the password and the data? Or just โhow long will it take you to break itโ? Letโs try to find out.
๐งโ๐ป https://blog.elcomsoft.com/2023/01/use-the-brute-force-luke/
#passwordrecovery #bruteforce #edpr
iOS 15.5 Low-Level Keychain Extraction
The updated iOS Forensic Toolkit 8.11 brings keychain decryption support to devices running iOS/iPadOS versions up to and including the 15.5 by using the extraction agent. The tool supports recent models that can run iOS 15 , which includes devices based on the Apple A12 through A15 Bionic, as well as Apple Silicon based devices built on the M1 SoC.
๐งโ๐ป https://blog.elcomsoft.com/2023/01/ios-15-5-low-level-keychain-extraction/
#ios #EIFT #mobileforensics #keychain #ios15 #ipad #agent
The updated iOS Forensic Toolkit 8.11 brings keychain decryption support to devices running iOS/iPadOS versions up to and including the 15.5 by using the extraction agent. The tool supports recent models that can run iOS 15 , which includes devices based on the Apple A12 through A15 Bionic, as well as Apple Silicon based devices built on the M1 SoC.
๐งโ๐ป https://blog.elcomsoft.com/2023/01/ios-15-5-low-level-keychain-extraction/
#ios #EIFT #mobileforensics #keychain #ios15 #ipad #agent