Behind the Scenes of iOS Data Extraction: Exploring the Extraction Agent
Discover the benefits of agent-based data extraction from iOS devices. Learn about the purpose and development of the extraction agent, when it can be used, and best practices. Get a comprehensive understanding of the cutting-edge approach for iOS data extraction.
π§βπ» https://blog.elcomsoft.com/2023/02/behind-the-scenes-of-ios-data-extraction-exploring-the-extraction-agent/
Discover the benefits of agent-based data extraction from iOS devices. Learn about the purpose and development of the extraction agent, when it can be used, and best practices. Get a comprehensive understanding of the cutting-edge approach for iOS data extraction.
Please open Telegram to view this post
VIEW IN TELEGRAM
Right Method, Wrong Order
In todayβs digital age, extracting data from mobile devices is an essential aspect of forensic investigations. However, it must be done carefully and correctly to ensure the highest possible level of accuracy and reliability. To accomplish this, the appropriate extraction methods should be used in the right order, considering all available options for a given device running a specific version of the operating system. So what is the best order of extraction methods when acquiring an iPhone? Read along to find out.
π§βπ» https://blog.elcomsoft.com/2023/02/right-method-wrong-order/
#apple #ios #checkm8 #EIFT #EPB #EPV #mobileforensics #dfir
In todayβs digital age, extracting data from mobile devices is an essential aspect of forensic investigations. However, it must be done carefully and correctly to ensure the highest possible level of accuracy and reliability. To accomplish this, the appropriate extraction methods should be used in the right order, considering all available options for a given device running a specific version of the operating system. So what is the best order of extraction methods when acquiring an iPhone? Read along to find out.
#apple #ios #checkm8 #EIFT #EPB #EPV #mobileforensics #dfir
Please open Telegram to view this post
VIEW IN TELEGRAM
Building a Password Recovery Queue
In the previous article we discussed the different methods available for gaining access to encrypted information, placing password recovery attacks at the bottom of the list. Password recovery attacks are one of the methods used to gain access to encrypted information. In this article weβll discuss the process of building a password recovery queue. Learn how to choose the appropriate workflow for the attack, the first prioritizing files with weaker protection, the second prioritizing faster and shorter attacks, and the third being a combination of the two. For your reference, we built a table to compare the relative strength of different file formats and encryption methods, helping users prioritize their attack queues.
π§βπ» https://blog.elcomsoft.com/2023/03/building-a-password-recovery-queue/
#password #dfir #EDPR
In the previous article we discussed the different methods available for gaining access to encrypted information, placing password recovery attacks at the bottom of the list. Password recovery attacks are one of the methods used to gain access to encrypted information. In this article weβll discuss the process of building a password recovery queue. Learn how to choose the appropriate workflow for the attack, the first prioritizing files with weaker protection, the second prioritizing faster and shorter attacks, and the third being a combination of the two. For your reference, we built a table to compare the relative strength of different file formats and encryption methods, helping users prioritize their attack queues.
#password #dfir #EDPR
Please open Telegram to view this post
VIEW IN TELEGRAM
A Word About Dictionaries
Dictionary attacks are among the most effective ones because they rely on the human nature. It is human nature to select passwords that are easily memoizable, like their pet names, dates of birth, football teams or whatever. BBC counted 171,146 words in the English dictionary, while a typical native speaker (of any language) knows 15,000 to 20,000 word families (lemmas, or root words and inflections). Whatever the attack speed is, it will not take too much time to check all the English words.
ππ» https://blog.elcomsoft.com/2023/03/a-word-about-dictionaries/
#passwords #EDPR #dictionary #password #dfir
Dictionary attacks are among the most effective ones because they rely on the human nature. It is human nature to select passwords that are easily memoizable, like their pet names, dates of birth, football teams or whatever. BBC counted 171,146 words in the English dictionary, while a typical native speaker (of any language) knows 15,000 to 20,000 word families (lemmas, or root words and inflections). Whatever the attack speed is, it will not take too much time to check all the English words.
ππ» https://blog.elcomsoft.com/2023/03/a-word-about-dictionaries/
#passwords #EDPR #dictionary #password #dfir
HomePod Forensics I: Pwning the HomePod
In this article, we will discuss how to access the hidden port of the first-generation HomePod and extract its file system image. Note that this process requires disassembly, voids the HomePod warranty, and requires specific tools, including a custom 3D-printable USB adapter, a set of screws, and a breakout cable. Therefore, this method is not recommended for casual users and should only be used by professionals who have a thorough understanding of the process.
π§βπ» https://blog.elcomsoft.com/2023/03/homepod-forensics-i-pwning-the-homepod/
#checkm8 #EIFT #HomePod #IoT #forensics
In this article, we will discuss how to access the hidden port of the first-generation HomePod and extract its file system image. Note that this process requires disassembly, voids the HomePod warranty, and requires specific tools, including a custom 3D-printable USB adapter, a set of screws, and a breakout cable. Therefore, this method is not recommended for casual users and should only be used by professionals who have a thorough understanding of the process.
#checkm8 #EIFT #HomePod #IoT #forensics
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft iOS Forensic Toolkit 8.13 adds checkm8 extraction for first-generation HomePod
Elcomsoft iOS Forensic Toolkit 8.13 adds forensically sound checkm8 extraction support for first-generation HomePod devices, and brings multiple improvements to the handling of legacy iPhone models.
π§βπ» https://www.elcomsoft.com/news/830.html
#HomePod #iOS #EIFT #mobileforensics #dfir #checkm8
Elcomsoft iOS Forensic Toolkit 8.13 adds forensically sound checkm8 extraction support for first-generation HomePod devices, and brings multiple improvements to the handling of legacy iPhone models.
#HomePod #iOS #EIFT #mobileforensics #dfir #checkm8
Please open Telegram to view this post
VIEW IN TELEGRAM
HomePod Forensics II: checkm8 and Data Extraction
The first-generation HomePod is a smart speaker developed by Apple that offers high-quality audio and a range of features, including Siri integration and smart home controls. However, as with any electronic device, it can store valuable information that may be of interest in forensic investigations. In this article, we will explore how to use the forensically sound checkm8 extraction to access data stored in the HomePod, including the keychain and file system image. We will also outline the specific tools and steps required to extract this information and provide a cheat sheet for those looking to extract data from a HomePod. By the end of this article, youβll have have a better understanding of how to extract data from the first-generation HomePod and the potential limitations of this extraction method.
π§βπ» https://blog.elcomsoft.com/2023/03/homepod-forensics-ii-checkm8-and-data-extraction/
#iOS #checkm8 #HomePod #EIFT #DFIR #mobileforensics
The first-generation HomePod is a smart speaker developed by Apple that offers high-quality audio and a range of features, including Siri integration and smart home controls. However, as with any electronic device, it can store valuable information that may be of interest in forensic investigations. In this article, we will explore how to use the forensically sound checkm8 extraction to access data stored in the HomePod, including the keychain and file system image. We will also outline the specific tools and steps required to extract this information and provide a cheat sheet for those looking to extract data from a HomePod. By the end of this article, youβll have have a better understanding of how to extract data from the first-generation HomePod and the potential limitations of this extraction method.
#iOS #checkm8 #HomePod #EIFT #DFIR #mobileforensics
Please open Telegram to view this post
VIEW IN TELEGRAM
Perfect Acquisition Part 1: Introduction
Forensic acquisition has undergone significant changes in recent years. In the past, acquisition was relatively easy, with storage media easily separable and disk encryption not yet widespread. However, with the rise of mobile devices and their built-in encryption capabilities, acquiring data has become increasingly challenging. Traditional approaches like disk dumps are no longer feasible, and software exploitation has become the industry standard. Despite these methods, there are limitations to mobile acquisition, including the need to collaborate with the device, the possibility of hardware defects or deliberate data tampering. As a result, there is a need for continuous innovation in forensic acquisition to address these challenges and ensure accurate and reliable data collection.
π§βπ» https://blog.elcomsoft.com/2023/03/perfect-acquisition-part-1-introduction/
#ios #legacy #lowlevelextraction
Forensic acquisition has undergone significant changes in recent years. In the past, acquisition was relatively easy, with storage media easily separable and disk encryption not yet widespread. However, with the rise of mobile devices and their built-in encryption capabilities, acquiring data has become increasingly challenging. Traditional approaches like disk dumps are no longer feasible, and software exploitation has become the industry standard. Despite these methods, there are limitations to mobile acquisition, including the need to collaborate with the device, the possibility of hardware defects or deliberate data tampering. As a result, there is a need for continuous innovation in forensic acquisition to address these challenges and ensure accurate and reliable data collection.
#ios #legacy #lowlevelextraction
Please open Telegram to view this post
VIEW IN TELEGRAM
Perfect Acquisition Part 2: iOS Background
Welcome to part 2 of the Perfect Acquisition series! In case you missed part 1, make sure to check it out before continuing with this article. In this section, we will dive deeper into iOS data protection and understand the obstacles we need to overcome in order to access the data, which in turn will help us accomplish a Perfect Acquisition when certain conditions are met.
π§βπ» https://blog.elcomsoft.com/2023/03/perfect-acquisition-part-2-ios-background/
#iOS #lowlevelextraction #dfir #mobileforensics
Welcome to part 2 of the Perfect Acquisition series! In case you missed part 1, make sure to check it out before continuing with this article. In this section, we will dive deeper into iOS data protection and understand the obstacles we need to overcome in order to access the data, which in turn will help us accomplish a Perfect Acquisition when certain conditions are met.
#iOS #lowlevelextraction #dfir #mobileforensics
Please open Telegram to view this post
VIEW IN TELEGRAM
iOS Forensic Toolkit 8.20 and 7.80 add partial file system extraction for iOS 16.1.2 and older
Elcomsoft iOS Forensic Toolkit 8.20 and 7.80 add low-level extraction support for a range of iOS versions, pulling parts of the file system. The newly supported iOS versions go all the way up to iOS 16.1.2. The new method supports devices built with the A11 through A16 Bionic chips, effectively covering the iPhone 8/X through iPhone 14 range, and supports many iPads including those based on Apple M1 and M2 chips.
π https://www.elcomsoft.com/news/831.html
#EIFT #iOS #agent #toolkit #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.20 and 7.80 add low-level extraction support for a range of iOS versions, pulling parts of the file system. The newly supported iOS versions go all the way up to iOS 16.1.2. The new method supports devices built with the A11 through A16 Bionic chips, effectively covering the iPhone 8/X through iPhone 14 range, and supports many iPads including those based on Apple M1 and M2 chips.
π https://www.elcomsoft.com/news/831.html
#EIFT #iOS #agent #toolkit #dfir #mobileforensics
Obtaining Serial Number, MAC, MEID and IMEI of a locked iPhone
Obtaining information from a locked iPhone can be challenging, particularly when the device is passcode-protected. However, four critical pieces of information that can aid forensic analysis are the deviceβs International Mobile Equipment Identity (IMEI), Mobile Equipment IDentifier (MEID), MAC address of the deviceβs Wi-Fi adapter, and its serial number. These unique identifiers can provide valuable insights into a deviceβs history, including its manufacture date, hardware specifications, and carrier information.
π https://blog.elcomsoft.com/2023/03/obtaining-serial-number-mac-meid-and-imei-of-a-locked-iphone/
#EIFT #iPhone #iOS #DFIR #mobileforensics
Obtaining information from a locked iPhone can be challenging, particularly when the device is passcode-protected. However, four critical pieces of information that can aid forensic analysis are the deviceβs International Mobile Equipment Identity (IMEI), Mobile Equipment IDentifier (MEID), MAC address of the deviceβs Wi-Fi adapter, and its serial number. These unique identifiers can provide valuable insights into a deviceβs history, including its manufacture date, hardware specifications, and carrier information.
π https://blog.elcomsoft.com/2023/03/obtaining-serial-number-mac-meid-and-imei-of-a-locked-iphone/
#EIFT #iPhone #iOS #DFIR #mobileforensics
Elcomsoft tools gain support for NVIDIA Ada Lovelace boards, nearly double password recovery speeds
Elcomsoft Advanced Office Password Recovery 7.20, Wireless Security Auditor 7.50, and Advanced PDF Password Recovery 5.20 gain support for NVIDIAβs latest-generation GeForce RTX 40 boards. The resulting performance increase nearly doubles the password recovery speeds of respective formats.
π https://www.elcomsoft.com/news/832.html
#NVIDIA #AOPR #password #EWSA #APDFPR #passwordrecovery #GeForceRTX40
Elcomsoft Advanced Office Password Recovery 7.20, Wireless Security Auditor 7.50, and Advanced PDF Password Recovery 5.20 gain support for NVIDIAβs latest-generation GeForce RTX 40 boards. The resulting performance increase nearly doubles the password recovery speeds of respective formats.
π https://www.elcomsoft.com/news/832.html
#NVIDIA #AOPR #password #EWSA #APDFPR #passwordrecovery #GeForceRTX40
Perfect Acquisition Part 3: Perfect HFS Acquisition
Welcome to Part 3 of the Perfect Acquisition series! If you havenβt read Part 1 and Part 2 yet, be sure to check them out before proceeding with this article. In this section, we will introduce our newly developed Perfect HFS Acquisition method, which enables the extraction of data from legacy iOS devices that do not have SEP and utilize the HFS file system.
π https://blog.elcomsoft.com/2023/04/perfect-acquisition-part-3-perfect-hfs-acquisition/
#iOS #lowlevelextraction #dfir #mobileforensics
Welcome to Part 3 of the Perfect Acquisition series! If you havenβt read Part 1 and Part 2 yet, be sure to check them out before proceeding with this article. In this section, we will introduce our newly developed Perfect HFS Acquisition method, which enables the extraction of data from legacy iOS devices that do not have SEP and utilize the HFS file system.
π https://blog.elcomsoft.com/2023/04/perfect-acquisition-part-3-perfect-hfs-acquisition/
#iOS #lowlevelextraction #dfir #mobileforensics
Perfect Acquisition Part 4: The Practical Part
Welcome to Part 4 of the Perfect Acquisition series! In case you missed the other parts (1, 2, and 3), please check them out for more background information, or dive straight in and learn how to perform Perfect HFS Acquisition yourself. This section contains a comprehensive guide on how to perform the Perfect HFS Acquisition procedure.
π https://blog.elcomsoft.com/2023/04/perfect-acquisition-part-4-the-practical-part/
#ios #lowlevelextraction #eift #dfir #keychain
Welcome to Part 4 of the Perfect Acquisition series! In case you missed the other parts (1, 2, and 3), please check them out for more background information, or dive straight in and learn how to perform Perfect HFS Acquisition yourself. This section contains a comprehensive guide on how to perform the Perfect HFS Acquisition procedure.
π https://blog.elcomsoft.com/2023/04/perfect-acquisition-part-4-the-practical-part/
#ios #lowlevelextraction #eift #dfir #keychain
Elcomsoft iOS Forensic Toolkit 8.21 add auto-DFU and automated screen shot capture
Elcomsoft iOS Forensic Toolkit 8.21 adds support for automated DFU mode and automated screen shot capturing using a pre-programmed Raspberry Pi Pico board. In addition, the new release adds checkm8 extraction support for compatible devices running iOS 15.7.3-15.7.5.
π https://www.elcomsoft.com/news/833.html
#checkm8 #EIFT #DFU #mobileforensics #iOS #iPhone #DFIR
Elcomsoft iOS Forensic Toolkit 8.21 adds support for automated DFU mode and automated screen shot capturing using a pre-programmed Raspberry Pi Pico board. In addition, the new release adds checkm8 extraction support for compatible devices running iOS 15.7.3-15.7.5.
π https://www.elcomsoft.com/news/833.html
#checkm8 #EIFT #DFU #mobileforensics #iOS #iPhone #DFIR
Automating DFU Mode with Raspberry Pi Pico
The latest update to iOS Forensic Toolkit brings two new features, both requiring the use of a Raspberry Pi Pico board. The first feature automates the switching of iPhone 8, iPhone 8 Plus, and iPhone X devices into DFU, while the second feature adds the ability to make long, scrollable screen shots in a semi-automatic fashion. In this article we will show how to build, program, and use a Raspberry Pi Pico board to automate DFU mode.
π https://blog.elcomsoft.com/2023/04/automating-dfu-mode-with-raspberry-pi-pico/
#DFU #EIFT #iOS #Raspberry #raspberrypipico #DFIR
The latest update to iOS Forensic Toolkit brings two new features, both requiring the use of a Raspberry Pi Pico board. The first feature automates the switching of iPhone 8, iPhone 8 Plus, and iPhone X devices into DFU, while the second feature adds the ability to make long, scrollable screen shots in a semi-automatic fashion. In this article we will show how to build, program, and use a Raspberry Pi Pico board to automate DFU mode.
π https://blog.elcomsoft.com/2023/04/automating-dfu-mode-with-raspberry-pi-pico/
#DFU #EIFT #iOS #Raspberry #raspberrypipico #DFIR
Automating Scrolling Screenshots with Raspberry Pi Pico
The recent update to iOS Forensic Toolkit brought two automations based on the Raspberry Pi Pico board. One of the new automations makes it possible to make long, scrollable screen shots in a semi-automatic fashion. In this article we will show how to build, program, and use a Raspberry Pi Pico board to automate scrolling screenshots.
π https://blog.elcomsoft.com/2023/04/automating-scrolling-screenshots-with-raspberry-pi-pico/
#EIFT #iOS #logicalacquisition #Raspberry #raspberrypipico #screenshot #screenshot #dfir
The recent update to iOS Forensic Toolkit brought two automations based on the Raspberry Pi Pico board. One of the new automations makes it possible to make long, scrollable screen shots in a semi-automatic fashion. In this article we will show how to build, program, and use a Raspberry Pi Pico board to automate scrolling screenshots.
π https://blog.elcomsoft.com/2023/04/automating-scrolling-screenshots-with-raspberry-pi-pico/
#EIFT #iOS #logicalacquisition #Raspberry #raspberrypipico #screenshot #screenshot #dfir
Full low-level extraction for the entire iOS 15 range
Elcomsoft iOS Forensic Toolkit 8.22 and 7.81 expand low-level extraction support, now covering the entire iOS/iPadOS 15 range. The newly supported OS versions include 15.6 through 15.7.2. The new method enables the extraction of the full file system including keychain, and supports devices built with the A12 and newer chips, effectively covering the iPhone 8/X through iPhone 13 range, and many iPads including those based on Apple M1 chips.
πhttps://www.elcomsoft.com/news/834.html
#EIFT #ios #dfir #mobileforensics
Elcomsoft iOS Forensic Toolkit 8.22 and 7.81 expand low-level extraction support, now covering the entire iOS/iPadOS 15 range. The newly supported OS versions include 15.6 through 15.7.2. The new method enables the extraction of the full file system including keychain, and supports devices built with the A12 and newer chips, effectively covering the iPhone 8/X through iPhone 13 range, and many iPads including those based on Apple M1 chips.
πhttps://www.elcomsoft.com/news/834.html
#EIFT #ios #dfir #mobileforensics
Low-level Extraction for iOS 15
Last month, we introduced a new low-level mechanism, which enabled access to parts of the file system from many Apple devices. The partial extraction process relies on a weak exploit that did not allow full sandbox escape. Today, the limitations are gone, and we are proud to offer the full file system extraction and keychain decryption for the entire iOS 15 range up to and including iOS/iPadOS 15.7.2.
π https://blog.elcomsoft.com/2023/05/low-level-extraction-for-ios-15/
#iOS #EIFT #agentextractor #dfir #mobileforensics
Last month, we introduced a new low-level mechanism, which enabled access to parts of the file system from many Apple devices. The partial extraction process relies on a weak exploit that did not allow full sandbox escape. Today, the limitations are gone, and we are proud to offer the full file system extraction and keychain decryption for the entire iOS 15 range up to and including iOS/iPadOS 15.7.2.
π https://blog.elcomsoft.com/2023/05/low-level-extraction-for-ios-15/
#iOS #EIFT #agentextractor #dfir #mobileforensics
iOS Forensic Toolkit and Open Source
As a provider of mobile forensic tools, we at Elcomsoft strongly believe in giving back to the community. Our iOS Forensic Toolkit (EIFT) is a highly complex and powerful mobile acquisition tool, consisting of almost eighty sub-projects, many of which are open source. While we have benefited from the contributions of the community, we also believe that itβs time to contribute back to the open source community by publishing our changes to those projects as required by their permissive license.
π https://blog.elcomsoft.com/2023/05/ios-forensic-toolkit-and-open-source/
#EIFT #opensource #toolkit
As a provider of mobile forensic tools, we at Elcomsoft strongly believe in giving back to the community. Our iOS Forensic Toolkit (EIFT) is a highly complex and powerful mobile acquisition tool, consisting of almost eighty sub-projects, many of which are open source. While we have benefited from the contributions of the community, we also believe that itβs time to contribute back to the open source community by publishing our changes to those projects as required by their permissive license.
π https://blog.elcomsoft.com/2023/05/ios-forensic-toolkit-and-open-source/
#EIFT #opensource #toolkit
Elcomsoft Distributed Password Recovery 80% faster with NVIDIA GeForce RTX 40 Series graphics cards
Elcomsoft Distributed Password Recovery 80% faster with NVIDIA GeForce RTX 40 Series graphics cards We updated Elcomsoft Distributed Password Recovery with support for NVIDIA GeForce RTX 40 Series graphics cards, the companyβs latest and greatest GPU series. In addition, Elcomsoft Distributed Password Recovery can now break NetNTLM v1/v2 and IKE PSK MD5 hashes.
π https://www.elcomsoft.com/news/835.html
#EDPR #Nvidia #password #GPU #AdaLovelace #RTX
Elcomsoft Distributed Password Recovery 80% faster with NVIDIA GeForce RTX 40 Series graphics cards We updated Elcomsoft Distributed Password Recovery with support for NVIDIA GeForce RTX 40 Series graphics cards, the companyβs latest and greatest GPU series. In addition, Elcomsoft Distributed Password Recovery can now break NetNTLM v1/v2 and IKE PSK MD5 hashes.
π https://www.elcomsoft.com/news/835.html
#EDPR #Nvidia #password #GPU #AdaLovelace #RTX
π1