Elcomsoft
549 subscribers
575 photos
1 video
1 file
460 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
πŸ†•Special macOS Firewall: Safe Sideloading of the EIFT Extraction AgentπŸ†•

Elcomsoft iOS Forensic Toolkit begins low-level extraction by sideloading the extraction agent, and the agent will not run until the phone has completed one or two checks against Apple’s servers.

Network requests, on a phone that is evidence. That single requirement is why we have shipped three different firewalls over the past three years.
πŸ’‘The newest one, EIFT Firewall, is a free macOS application and a direct replacement for the 2023 script!

Why the phone needs the internet at all?

The phone has to reach a small number of Apple hosts, one of which has a name that resolves to a different address every few minutes, and nothing else. Arranging exactly that is harder than it sounds.

More information at the linkπŸ“Ž

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
The iOS 27 Recovery Menu: What It Means for Forensics πŸ‘†

iOS 27
and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.

Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old β€œconnect to computer” recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phone πŸ“±

The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.

Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.

More information at the linkπŸ“Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
Write Blockers in Forensics: What Controls How You Use Them? πŸ«†

In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.

Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.

🟑Hardware write blockers are physical devices you plug the source media into, software write blockers are installed on the acquisition system, and the former type is more robust than the latter.

The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.

πŸ—£And here comes the question: which laws or standards mandate using a write blocker?

More information at the linkπŸ“Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
The True Meaning of Consent in β€˜Consent Extractions’ βœ…

In law enforcement use a β€œconsent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.

❀️Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the β€œTrust This Computer” prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top.

An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.

πŸ—£This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.

More information at the linkπŸ“Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft System Recovery 8.38: Built-In BitLocker TPM Exploit Library, Browser Artefact Extraction, and Imaging Checksums

β–ͺ️Elcomsoft System Recovery, a bootable digital triage tool, now offers to build you a second USB flash drive for a BitLocker exploit during installationβ–ͺ️

Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.

Let's talk about:

🟑what actually this does
🟑background
🟑browser extraction, imaging, checksums, and more
🟑Elcomsoft System Recovery 8.38 release notes

More information at the linkπŸ“Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ†•Elcomsoft Quick Triage 2.2: Timeline, file system snapshot, and a plugin engineπŸ†•

Elcomsoft Quick Triage 2.2 adds three things:

🟑a Timeline view that merges events from every timestamped artifact into one chronology
🟑a file system snapshot that copies metadata without file contents
🟑 a plugin architecture for artifact parsers

πŸ˜€The release also brings MSA password attacks, OpenDocument parsing and recursive archive parsing in full-text search, and a list of fixes, but here we’ll mostly talk about the first three.

More information at the linkπŸ“Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
IoT Forensics on the Rise: Extracting More Apple Watch, Apple TV and HomePod Models πŸ“Ή

Seven years after checkm8, iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4 and Series 5, the second-generation Apple TV 4K, and the HomePod mini. In each case the result is the full file system image and the decrypted keychain.

⚑️This is the first time that the low-level extraction boundary has moved past the A11 generation, and the reason is a SecureROM exploit called usbliter8, published in June 2026.

πŸ—£Let's talk about this!

More information at the linkπŸ“Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1πŸ‘1
πŸ†•Low-Level Extraction of the Apple Watch S4/S5πŸ†•

iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4, the Apple Watch Series 5, and the second-generation Apple TV 4K.

β–ͺ️The method uses usbliter8, an exploit of the SecureROM, the read-only boot code in the chip. checkm8 works on Apple chips up to the A11 generation, while usbliter8 works on the generation after it.

The extraction procedure is forensically sound: the toolkit does all the work in the RAM, and never starts the operating system of the device. The toolkit never alters the content of the data partition, so if you do the extraction again, you get the same checksum.

usbliter8 requires a microcontroller board to apply, and you will need our specific firmware to flash the board. This is a one-time procedure; after flashing the board, you can use it for all subsequent extractions.

πŸ—£This article gives the full procedure for each of the two Apple Watch devices.

More information at the linkπŸ“Ž

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
πŸ†•Low-Level Extraction the Apple TV 4K 2nd GenerationπŸ†•

We
’ve added bootloader-level low-level extraction support for the second-generation Apple TV 4K ❀️ iOS Forensic Toolkit

πŸ’‘While the older 4K model was compatible with the checkm8 exploit, the second-generation is based on a newer SoC that required a newer exploit, usbliter8.

The exploit requires a custom adapter that uses a microcontroller board with our custom firmware.

πŸ—£What you need? Let's talk!

More information at the linkπŸ“Ž

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
πŸ†•Elcomsoft Phone Breaker 11.05: iCloud extraction support for iOS 27 and the iPhone 18 rangeπŸ†•

⚑️Elcomsoft Phone Breaker 11.05 adds support for iCloud backups of iOS 27 and iPadOS 27 devices, including the iPhone 18 lineup, and restores access to iCloud data on accounts where every registered device runs OS version 26 or 27.

The update includes:

⏺iCloud: added support for iPhone 18, 18 Pro, 18 Pro Max, and 18 Duo cloud backups
⏺iCloud: added support for iOS 27 and iPadOS 27 iCloud backups
⏺iCloud: improved support for iCloud data (backups, synced, files) for accounts with OS 26/27 devices only
⏺Bugfix: fixed program initialization issue on Intel-based Macs

More information at the linkπŸ“Ž

#EPB
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ†•Low-Level Extraction of the HomePod miniπŸ†•

iOS Forensic Toolkit 10.12 extracts the full file system image and the decrypted keychain from yet another IoT device: Apple HomePod mini.

πŸ˜€This is the first file system extraction of the device, the method uses the usbliter8 bootloader exploit and a custom adapter. This guide covers the hardware, the extraction and analysis steps.

Know your HomePod

Apple has shipped three HomePod models, each based on a different chip. Apple’s specifications do not list the processor; use the model identifier page and match it to the chip below:

🀩 HomePod (1st generation): A8.

🀩 HomePod mini: S5.

🀩 HomePod (2nd generation): S7.

πŸ—£Let’s talk about why a forensic specialist needs to analyze a smart speaker and what will be required for that.

More information at the linkπŸ“Ž

#EIFT #update
Please open Telegram to view this post
VIEW IN TELEGRAM