Forensically Sound checkm8 Based Extraction of iPhone 5s, 6, 6s and SE
Back in 2019, independent researcher axi0mX has developed a ground-breaking exploit. Targeting a vulnerability in the bootloader of several generations of iOS devices, checkm8 made it possible to obtain BootROM code execution and perform forensic analysis on a long list of devices running a wide range of iOS versions. In this article, we’ll talk about the forensic use of checkm8 with iOS Forensic Toolkit.
checkm8 is widely accepted in the mobile forensic community. Multiple solutions exist, but none of them are perfect, and most aren’t even trying. Our solution works entirely in RAM; it does not boot the OS installed on the device, and does not touch the system partition. There won’t be a trace left on the iPhone extracted with iOS Forensic Toolkit, not a single log entry and not even a changed timestamp.
👉 https://blog.elcomsoft.com/2021/05/checkm8-based-extraction-of-iphone-5s-6-6s-and-se/
#iphone #ios #checkm8 #dfir #EIFT
Post #392
410
