Elcomsoft
549 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Why Digital Forensic Reports Don’t Survive Cross-Examination❓

A forensic report
is not a summary of finished work. It’s a claim that has to survive someone trying to take it apart, and most reports aren’t built for that.

A lot of what gets filed today is automated tool output with a cover letter attached: the examiner runs a parser, exports a spreadsheet, writes three sentences of narrative, and calls it analysis. That holds up fine until an opposing expert asks how the software actually reached its conclusion.

🔉Three real cases show what happens when nobody asks that question early enough.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2
How to recover deleted data from your iPhone 👤

You accidentally deleted an important file from your iPhone, panicked, and hit the web looking for a way to get it back...

Instantly, you’re hit with a barrage of search results pushing “iPhone data recovery” software. If you look closely, you’ll notice almost all of these apps are low-quality rebrands or slightly tweaked forks of just a handful of identical tools.

❓Before you pull out your credit card, you need to understand what can actually be recovered from an iPhone, and what is gone for good.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
When the iCloud Backup Is the Only Copy Left ☁️

An iCloud backup is often the only surviving copy of data no longer on the device. Two ordinary situations show why, and neither involves anything clever on the suspect’s part.

What could possibly go wrong, and how can you access the data?

⏺Case one: the update that went wrong

Updates fail, usually for a boring reason: not enough free space. iOS downloads the update, starts installing, runs out of room, and the phone reboots into Recovery mode – the cable-and-computer screen, nothing else. Connect it to a Mac or PC and you get two options: Update, which reinstalls the system and keeps data, or Restore, which wipes it.
Major version jumps fail worse. We’ve seen updates leave a device unable to boot at all, with reports of the passcode being rejected afterward, which points at Secure Enclave state rather than the file system.
Either way, the outcome for an examiner is the same. A phone stuck in Recovery mode won’t yield a file system image.

⏺Case two: the data that was deleted

Deleting something on an iPhone takes two taps, and the safety net is thin. Photos, Notes, Voice Memos and iCloud Drive files go to Recently Deleted and stay about 30 days.
This is where synced data and backups diverge. Synced categories propagate a deletion within seconds of the device going online, so the cloud copy usually mirrors the device by the time anyone checks. Back up overnight, delete the file the next morning, and the file is still in last night’s backup. The older of the two stored backups can predate the deletion by weeks.

😀We covered the user-facing side of this recently: How to recover deleted data from your iPhone.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
🆕Special macOS Firewall: Safe Sideloading of the EIFT Extraction Agent🆕

Elcomsoft iOS Forensic Toolkit begins low-level extraction by sideloading the extraction agent, and the agent will not run until the phone has completed one or two checks against Apple’s servers.

Network requests, on a phone that is evidence. That single requirement is why we have shipped three different firewalls over the past three years.
💡The newest one, EIFT Firewall, is a free macOS application and a direct replacement for the 2023 script!

Why the phone needs the internet at all?

The phone has to reach a small number of Apple hosts, one of which has a name that resolves to a different address every few minutes, and nothing else. Arranging exactly that is harder than it sounds.

More information at the link📎

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
The iOS 27 Recovery Menu: What It Means for Forensics 👆

iOS 27
and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.

Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old “connect to computer” recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phone 📱

The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.

Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
Write Blockers in Forensics: What Controls How You Use Them? 🫆

In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.

Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.

🟡Hardware write blockers are physical devices you plug the source media into, software write blockers are installed on the acquisition system, and the former type is more robust than the latter.

The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.

🗣And here comes the question: which laws or standards mandate using a write blocker?

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
The True Meaning of Consent in ‘Consent Extractions’ ✅

In law enforcement use a “consent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.

❤️Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the “Trust This Computer” prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top.

An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.

🗣This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft System Recovery 8.38: Built-In BitLocker TPM Exploit Library, Browser Artefact Extraction, and Imaging Checksums

▪️Elcomsoft System Recovery, a bootable digital triage tool, now offers to build you a second USB flash drive for a BitLocker exploit during installation▪️

Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.

Let's talk about:

🟡what actually this does
🟡background
🟡browser extraction, imaging, checksums, and more
🟡Elcomsoft System Recovery 8.38 release notes

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
🆕Elcomsoft Quick Triage 2.2: Timeline, file system snapshot, and a plugin engine🆕

Elcomsoft Quick Triage 2.2 adds three things:

🟡a Timeline view that merges events from every timestamped artifact into one chronology
🟡a file system snapshot that copies metadata without file contents
🟡 a plugin architecture for artifact parsers

😀The release also brings MSA password attacks, OpenDocument parsing and recursive archive parsing in full-text search, and a list of fixes, but here we’ll mostly talk about the first three.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
IoT Forensics on the Rise: Extracting More Apple Watch, Apple TV and HomePod Models 📹

Seven years after checkm8, iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4 and Series 5, the second-generation Apple TV 4K, and the HomePod mini. In each case the result is the full file system image and the decrypted keychain.

⚡️This is the first time that the low-level extraction boundary has moved past the A11 generation, and the reason is a SecureROM exploit called usbliter8, published in June 2026.

🗣Let's talk about this!

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1
🆕Low-Level Extraction of the Apple Watch S4/S5🆕

iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4, the Apple Watch Series 5, and the second-generation Apple TV 4K.

▪️The method uses usbliter8, an exploit of the SecureROM, the read-only boot code in the chip. checkm8 works on Apple chips up to the A11 generation, while usbliter8 works on the generation after it.

The extraction procedure is forensically sound: the toolkit does all the work in the RAM, and never starts the operating system of the device. The toolkit never alters the content of the data partition, so if you do the extraction again, you get the same checksum.

usbliter8 requires a microcontroller board to apply, and you will need our specific firmware to flash the board. This is a one-time procedure; after flashing the board, you can use it for all subsequent extractions.

🗣This article gives the full procedure for each of the two Apple Watch devices.

More information at the link📎

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
🆕Low-Level Extraction the Apple TV 4K 2nd Generation🆕

We
’ve added bootloader-level low-level extraction support for the second-generation Apple TV 4K ❤️ iOS Forensic Toolkit

💡While the older 4K model was compatible with the checkm8 exploit, the second-generation is based on a newer SoC that required a newer exploit, usbliter8.

The exploit requires a custom adapter that uses a microcontroller board with our custom firmware.

🗣What you need? Let's talk!

More information at the link📎

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1