Elcomsoft
553 subscribers
570 photos
1 video
1 file
455 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
iOS 15.5 Low-Level Keychain Extraction

The updated iOS Forensic Toolkit 8.11 brings keychain decryption support to devices running iOS/iPadOS versions up to and including the 15.5 by using the extraction agent. The tool supports recent models that can run iOS 15 , which includes devices based on the Apple A12 through A15 Bionic, as well as Apple Silicon based devices built on the M1 SoC.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/01/ios-15-5-low-level-keychain-extraction/

#ios #EIFT #mobileforensics #keychain #ios15 #ipad #agent
Advanced PDF Password Recovery and Archive Password Recovery updates

We released Advanced Archive Password Recovery 4.66 and Advanced PDF Password Recovery 5.11 with multiple bugfixes and enhancements. The archive recovery tool update brought support for RAR5 archives protected with passwords longer than 16 characters, and improved compatibility with self-extracting archives.

๐Ÿง‘โ€๐Ÿ’ป https://www.elcomsoft.com/news/828.html

#7Zip #Zip #Rar #Rar5 #PDF #passwordrecovery
Please open Telegram to view this post
VIEW IN TELEGRAM
Apple Releases iOS 12.5.7, iOS 15.7.3. What About Low-Level Extraction?

Apple is known for a very long time they support their devices. On January 23, 2023, alongside with iOS 16.3 the company rolled out security patches to older devices, releasing iOS 12.5.7, iOS 15.7.3 and iPadOS 15.7.3. iOS 12 was the last major version of iOS supported on Apple A7, A8, and A8X devices, which includes the iPhone 5s and iPhone 6 and 6 Plus generations along with several iPad models. We tested low-level extraction with these security-patched builds, and made several discoveries.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/01/apple-releases-ios-12-5-7-ios-15-7-3-what-about-low-level-extraction/

#ios #checkm8 #eift #agentextractor
Please open Telegram to view this post
VIEW IN TELEGRAM
Forensically Sound checkm8 Extraction: Repeatable, Verifiable and Safe

What does โ€œforensically sound extractionโ€ mean? The classic definition of forensically sound extraction means both repeatable and verifiable results. However, there is more to it. We believe that forensically sound extractions should not only be verifiable and repeatable, but verifiable in a safe, error-proof manner, so we tweaked our product to deliver just that.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/02/forensically-sound-checkm8-extraction-repeatable-verifiable-and-safe/

 #Apple #checkm8 #iOS #EIFT #dfir #mobileforensics
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft iOS Forensic Toolkit 8.12 adds checkm8 extraction support for iOS 16.3, 15.7.3, and 12.5.7

Elcomsoft iOS Forensic Toolkit 8.12 adds forensically sound checkm8 extraction support for iOS, iPadOS and tvOS 16.3, while also supporting the recent iOS 15.7.3 and 12.5.7 released for older devices.

๐Ÿง‘โ€๐Ÿ’ป https://www.elcomsoft.com/news/829.html

#checkm8 #EIFT #iOS #AppleTV #AppleWatch #dfir
Please open Telegram to view this post
VIEW IN TELEGRAM
Behind the Scenes of iOS Data Extraction: Exploring the Extraction Agent

Discover the benefits of agent-based data extraction from iOS devices. Learn about the purpose and development of the extraction agent, when it can be used, and best practices. Get a comprehensive understanding of the cutting-edge approach for iOS data extraction.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/02/behind-the-scenes-of-ios-data-extraction-exploring-the-extraction-agent/
Please open Telegram to view this post
VIEW IN TELEGRAM
Right Method, Wrong Order

In todayโ€™s digital age, extracting data from mobile devices is an essential aspect of forensic investigations. However, it must be done carefully and correctly to ensure the highest possible level of accuracy and reliability. To accomplish this, the appropriate extraction methods should be used in the right order, considering all available options for a given device running a specific version of the operating system. So what is the best order of extraction methods when acquiring an iPhone? Read along to find out.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/02/right-method-wrong-order/

#apple #ios #checkm8 #EIFT #EPB #EPV #mobileforensics #dfir
Please open Telegram to view this post
VIEW IN TELEGRAM
Building a Password Recovery Queue

In the previous article we discussed the different methods available for gaining access to encrypted information, placing password recovery attacks at the bottom of the list. Password recovery attacks are one of the methods used to gain access to encrypted information. In this article weโ€™ll discuss the process of building a password recovery queue. Learn how to choose the appropriate workflow for the attack, the first prioritizing files with weaker protection, the second prioritizing faster and shorter attacks, and the third being a combination of the two. For your reference, we built a table to compare the relative strength of different file formats and encryption methods, helping users prioritize their attack queues.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/03/building-a-password-recovery-queue/

#password #dfir #EDPR
Please open Telegram to view this post
VIEW IN TELEGRAM
A Word About Dictionaries

Dictionary attacks are among the most effective ones because they rely on the human nature. It is human nature to select passwords that are easily memoizable, like their pet names, dates of birth, football teams or whatever. BBC counted 171,146 words in the English dictionary, while a typical native speaker (of any language) knows 15,000 to 20,000 word families (lemmas, or root words and inflections). Whatever the attack speed is, it will not take too much time to check all the English words.

๐Ÿ‘‰๐Ÿป https://blog.elcomsoft.com/2023/03/a-word-about-dictionaries/

#passwords #EDPR #dictionary #password #dfir
HomePod Forensics I: Pwning the HomePod

In this article, we will discuss how to access the hidden port of the first-generation HomePod and extract its file system image. Note that this process requires disassembly, voids the HomePod warranty, and requires specific tools, including a custom 3D-printable USB adapter, a set of screws, and a breakout cable. Therefore, this method is not recommended for casual users and should only be used by professionals who have a thorough understanding of the process.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/03/homepod-forensics-i-pwning-the-homepod/

#checkm8 #EIFT #HomePod #IoT #forensics
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft iOS Forensic Toolkit 8.13 adds checkm8 extraction for first-generation HomePod

Elcomsoft iOS Forensic Toolkit 8.13 adds forensically sound checkm8 extraction support for first-generation HomePod devices, and brings multiple improvements to the handling of legacy iPhone models.

๐Ÿง‘โ€๐Ÿ’ป https://www.elcomsoft.com/news/830.html

#HomePod #iOS #EIFT #mobileforensics #dfir #checkm8
Please open Telegram to view this post
VIEW IN TELEGRAM
HomePod Forensics II: checkm8 and Data Extraction

The first-generation HomePod is a smart speaker developed by Apple that offers high-quality audio and a range of features, including Siri integration and smart home controls. However, as with any electronic device, it can store valuable information that may be of interest in forensic investigations. In this article, we will explore how to use the forensically sound checkm8 extraction to access data stored in the HomePod, including the keychain and file system image. We will also outline the specific tools and steps required to extract this information and provide a cheat sheet for those looking to extract data from a HomePod. By the end of this article, youโ€™ll have have a better understanding of how to extract data from the first-generation HomePod and the potential limitations of this extraction method.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/03/homepod-forensics-ii-checkm8-and-data-extraction/

#iOS #checkm8 #HomePod #EIFT #DFIR #mobileforensics
Please open Telegram to view this post
VIEW IN TELEGRAM
Perfect Acquisition Part 1: Introduction

Forensic acquisition has undergone significant changes in recent years. In the past, acquisition was relatively easy, with storage media easily separable and disk encryption not yet widespread. However, with the rise of mobile devices and their built-in encryption capabilities, acquiring data has become increasingly challenging. Traditional approaches like disk dumps are no longer feasible, and software exploitation has become the industry standard. Despite these methods, there are limitations to mobile acquisition, including the need to collaborate with the device, the possibility of hardware defects or deliberate data tampering. As a result, there is a need for continuous innovation in forensic acquisition to address these challenges and ensure accurate and reliable data collection.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/03/perfect-acquisition-part-1-introduction/

#ios #legacy #lowlevelextraction
Please open Telegram to view this post
VIEW IN TELEGRAM
Perfect Acquisition Part 2: iOS Background

Welcome to part 2 of the Perfect Acquisition series! In case you missed part 1, make sure to check it out before continuing with this article. In this section, we will dive deeper into iOS data protection and understand the obstacles we need to overcome in order to access the data, which in turn will help us accomplish a Perfect Acquisition when certain conditions are met.

๐Ÿง‘โ€๐Ÿ’ป https://blog.elcomsoft.com/2023/03/perfect-acquisition-part-2-ios-background/

#iOS #lowlevelextraction #dfir #mobileforensics
Please open Telegram to view this post
VIEW IN TELEGRAM
iOS Forensic Toolkit 8.20 and 7.80 add partial file system extraction for iOS 16.1.2 and older

Elcomsoft iOS Forensic Toolkit 8.20 and 7.80 add low-level extraction support for a range of iOS versions, pulling parts of the file system. The newly supported iOS versions go all the way up to iOS 16.1.2. The new method supports devices built with the A11 through A16 Bionic chips, effectively covering the iPhone 8/X through iPhone 14 range, and supports many iPads including those based on Apple M1 and M2 chips.

๐Ÿ‘‰ https://www.elcomsoft.com/news/831.html

#EIFT #iOS #agent #toolkit #dfir #mobileforensics
Obtaining Serial Number, MAC, MEID and IMEI of a locked iPhone

Obtaining information from a locked iPhone can be challenging, particularly when the device is passcode-protected. However, four critical pieces of information that can aid forensic analysis are the deviceโ€™s International Mobile Equipment Identity (IMEI), Mobile Equipment IDentifier (MEID), MAC address of the deviceโ€™s Wi-Fi adapter, and its serial number. These unique identifiers can provide valuable insights into a deviceโ€™s history, including its manufacture date, hardware specifications, and carrier information.

๐Ÿ‘‰ https://blog.elcomsoft.com/2023/03/obtaining-serial-number-mac-meid-and-imei-of-a-locked-iphone/

#EIFT #iPhone #iOS #DFIR #mobileforensics
Elcomsoft tools gain support for NVIDIA Ada Lovelace boards, nearly double password recovery speeds

Elcomsoft Advanced Office Password Recovery 7.20, Wireless Security Auditor 7.50, and Advanced PDF Password Recovery 5.20 gain support for NVIDIAโ€™s latest-generation GeForce RTX 40 boards. The resulting performance increase nearly doubles the password recovery speeds of respective formats.

๐Ÿ‘‰ https://www.elcomsoft.com/news/832.html

#NVIDIA #AOPR #password #EWSA #APDFPR #passwordrecovery #GeForceRTX40
Perfect Acquisition Part 3: Perfect HFS Acquisition

Welcome to Part 3 of the Perfect Acquisition series! If you havenโ€™t read Part 1 and Part 2 yet, be sure to check them out before proceeding with this article. In this section, we will introduce our newly developed Perfect HFS Acquisition method, which enables the extraction of data from legacy iOS devices that do not have SEP and utilize the HFS file system.

๐Ÿ‘‰ https://blog.elcomsoft.com/2023/04/perfect-acquisition-part-3-perfect-hfs-acquisition/

#iOS #lowlevelextraction #dfir #mobileforensics
Perfect Acquisition Part 4: The Practical Part

Welcome to Part 4 of the Perfect Acquisition series! In case you missed the other parts (1, 2, and 3), please check them out for more background information, or dive straight in and learn how to perform Perfect HFS Acquisition yourself. This section contains a comprehensive guide on how to perform the Perfect HFS Acquisition procedure.

๐Ÿ‘‰ https://blog.elcomsoft.com/2023/04/perfect-acquisition-part-4-the-practical-part/

#ios #lowlevelextraction #eift #dfir #keychain
Elcomsoft iOS Forensic Toolkit 8.21 add auto-DFU and automated screen shot capture

Elcomsoft iOS Forensic Toolkit 8.21 adds support for automated DFU mode and automated screen shot capturing using a pre-programmed Raspberry Pi Pico board. In addition, the new release adds checkm8 extraction support for compatible devices running iOS 15.7.3-15.7.5.

๐Ÿ‘‰ https://www.elcomsoft.com/news/833.html

#checkm8 #EIFT #DFU #mobileforensics #iOS #iPhone #DFIR
Automating DFU Mode with Raspberry Pi Pico

The latest update to iOS Forensic Toolkit brings two new features, both requiring the use of a Raspberry Pi Pico board. The first feature automates the switching of iPhone 8, iPhone 8 Plus, and iPhone X devices into DFU, while the second feature adds the ability to make long, scrollable screen shots in a semi-automatic fashion. In this article we will show how to build, program, and use a Raspberry Pi Pico board to automate DFU mode.

๐Ÿ‘‰ https://blog.elcomsoft.com/2023/04/automating-dfu-mode-with-raspberry-pi-pico/

#DFU #EIFT #iOS #Raspberry #raspberrypipico #DFIR