Elcomsoft iOS Forensic Toolkit begins low-level extraction by sideloading the extraction agent, and the agent will not run until the phone has completed one or two checks against Appleβs servers.
Network requests, on a phone that is evidence. That single requirement is why we have shipped three different firewalls over the past three years.
Why the phone needs the internet at all?
The phone has to reach a small number of Apple hosts, one of which has a name that resolves to a different address every few minutes, and nothing else. Arranging exactly that is harder than it sounds.
More information at the link
#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
The iOS 27 Recovery Menu: What It Means for Forensics π
iOS 27 and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.
Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old βconnect to computerβ recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phoneπ±
The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.
Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.
More information at the linkπ
iOS 27 and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.
Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old βconnect to computerβ recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phone
The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.
Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
β€1
Write Blockers in Forensics: What Controls How You Use Them? π«
In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.
Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.
π‘ Hardware write blockers are physical devices you plug the source media into, software write blockers are installed on the acquisition system, and the former type is more robust than the latter.
The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.
π£ And here comes the question: which laws or standards mandate using a write blocker?
More information at the linkπ
In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.
Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.
The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
The True Meaning of Consent in βConsent Extractionsβ β
In law enforcement use a βconsent extractionβ means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.
β€οΈ Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the βTrust This Computerβ prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top.
An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.
π£ This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.
More information at the linkπ
In law enforcement use a βconsent extractionβ means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.
An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft System Recovery 8.38: Built-In BitLocker TPM Exploit Library, Browser Artefact Extraction, and Imaging Checksums
βͺοΈ Elcomsoft System Recovery, a bootable digital triage tool, now offers to build you a second USB flash drive for a BitLocker exploit during installationβͺοΈ
Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.
Let's talk about:
π‘ what actually this does
π‘ background
π‘ browser extraction, imaging, checksums, and more
π‘ Elcomsoft System Recovery 8.38 release notes
More information at the linkπ
Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.
Let's talk about:
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft Quick Triage 2.2 adds three things:
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
IoT Forensics on the Rise: Extracting More Apple Watch, Apple TV and HomePod Models πΉ
Seven years after checkm8, iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4 and Series 5, the second-generation Apple TV 4K, and the HomePod mini. In each case the result is the full file system image and the decrypted keychain.
β‘οΈ This is the first time that the low-level extraction boundary has moved past the A11 generation, and the reason is a SecureROM exploit called usbliter8, published in June 2026.
π£ Let's talk about this!
More information at the linkπ
Seven years after checkm8, iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4 and Series 5, the second-generation Apple TV 4K, and the HomePod mini. In each case the result is the full file system image and the decrypted keychain.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
β€1π1
iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4, the Apple Watch Series 5, and the second-generation Apple TV 4K.
The extraction procedure is forensically sound: the toolkit does all the work in the RAM, and never starts the operating system of the device. The toolkit never alters the content of the data partition, so if you do the extraction again, you get the same checksum.
usbliter8 requires a microcontroller board to apply, and you will need our specific firmware to flash the board. This is a one-time procedure; after flashing the board, you can use it for all subsequent extractions.
More information at the link
#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
β€1
Weβve added bootloader-level low-level extraction support for the second-generation Apple TV 4K
The exploit requires a custom adapter that uses a microcontroller board with our custom firmware.
More information at the link
#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
β€1
The update includes:
More information at the link
#EPB
Please open Telegram to view this post
VIEW IN TELEGRAM
iOS Forensic Toolkit 10.12 extracts the full file system image and the decrypted keychain from yet another IoT device: Apple HomePod mini.
Know your HomePod
Apple has shipped three HomePod models, each based on a different chip. Appleβs specifications do not list the processor; use the model identifier page and match it to the chip below:
More information at the link
#EIFT #update
Please open Telegram to view this post
VIEW IN TELEGRAM