TGViewer
Channel Public Channel
Elcomsoft

Elcomsoft

@elcomsoft

Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Subscribers
547
Photos
573
Videos
1
Links
458

Showing posts older than #527 · Back to latest

Older Posts 20 shown
Post #526 432
Cloud Forensics: Obtaining iCloud Backups, Media Files and Synchronized Data

Apple offers by far the most sophisticated solution for backing up, restoring, transferring and synchronizing data across devices belonging to the company’s ecosystem. Apple iCloud can store cloud backups and media files, synchronize essential information between Apple devices, and keep highly sensitive information such as Health and authentication credentials securely synchronized. In this article we’ll explain what kinds of data are stored in iCloud and what you need to access them.

👉 https://blog.elcomsoft.com/2022/11/cloud-forensics-obtaining-icloud-backups-media-files-and-synchronized-data/

#cloudforensics #PhoneBreaker #EPB #iCloud #backup #iOS #dfir
Post #525 389
Advanced Logical Extraction with iOS Forensic Toolkit 8: Cheat Sheet

Advanced logical acquisition is the most compatible and least complicated way to access essential evidence stored in Apple devices. In legacy versions of iOS Forensic Toolkit, we offered a 1-2-3 style, menu-driven extraction experience, while the updated release of iOS Forensic Toolkit 8.0 is driven by the command line. In this quick-start guide we will lay out the steps required to extract the most amount of data from Apple devices via the advanced logical process.

👉 https://blog.elcomsoft.com/2022/11/advanced-logical-extraction-with-ios-forensic-toolkit-8-cheat-sheet/

#eift #toolkit #ios #logicalacquisition #dfir #mobileforensics
Post #524 417
iOS Backups: Leftover Passwords

In Apple ecosystem, logical acquisition is the most convenient and the most compatible extraction method, with local backups being a major contributor. Password-protected backups contain significantly more information than unencrypted backups, which is why many forensic tools including iOS Forensic Toolkit automatically apply a temporary backup password before creating a backup. If a temporary password is not removed after the extraction, subsequent extraction attempts, especially made with a different tool, will produce encrypted backups protected with an effectively unknown password. In this article we’ll talk about why this happens and how to deal with it.

👉 https://blog.elcomsoft.com/2022/11/ios-backups-leftover-passwords/

#EDPR #EIFT #PhoneBreaker #password #iOS #iTunes
Post #523 418
checkm8 Extraction Cheat Sheet: iPhone and iPad Devices

The newly released iOS Forensic Toolkit 8.0 delivers forensically sound checkm8 extraction powered with a command-line interface. The new user experience offers full control over the extraction process, yet mastering the right workflow may become a challenge for those unfamiliar with command-line tools. In this quick-start guide we will lay out the steps required to perform a clean, forensically sound extraction of a compatible iPhone or iPad device.

👉 https://blog.elcomsoft.com/2022/11/checkm8-extraction-cheat-sheet-iphone-and-ipad-devices/

#eift #toolkit #checkm8 #ios16 #dfir #dfu #mobileforensics
Post #521 397
How to Put Apple TV 3 (2012-2013), Apple TV HD (2015) and Apple TV 4K (2017) into DFU

The title says it all. In this article we’ll explain the steps required to put the listed Apple TV models into DFU mode. These Apple TV models are based on the A5, A8, and A10X chips that are susceptible to the checkm8 exploit and checkm8-based extraction with iOS Forensic Toolkit 8, and DFU mode is the required initial step of the process.

👉 https://blog.elcomsoft.com/2022/10/how-to-put-apple-tv-3-2012-2013-apple-tv-hd-2015-and-apple-tv-4k-2017-into-dfu/

#dfu #appletv #eift #mobileforensics #dfir
Post #520 534
iOS 16: SEP Hardening, New Security Measures and Their Forensic Implications

iOS 16 brings many changes to mobile forensics. Users receive additional tools to control the sharing and protection of their personal information, while forensic experts will face tighter security measures. In this review, we’ll talk about the things in iOS 16 that are likely to affect the forensic workflow.

👉🏻 https://blog.elcomsoft.com/2022/09/ios-16-sep-hardening-new-security-measures-and-their-forensic-implications/

#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #checkm8
Post #519 529
iOS Forensic Toolkit 8.0 Now Official: Bootloader-Level Extraction for 76 Devices

iOS Forensic Toolkit 8.0 is officially released! Delivering forensically sound checkm8 extraction and a new command-line driven user experience, the new release becomes the most sophisticated mobile forensic tool we’ve released to date.

👉🏻 https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-now-official-bootloader-level-extraction-for-76-devices/

#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
Post #518 428
iOS 16: Extracting the File System and Keychain from A11 Devices

Bootloader-based acquisition is the only 100% forensically sound data extraction method for Apple devices. It is the only way to acquire the full set of data from those devices that run iOS 16, albeit with a huge caveat that makes the whole thing more of a brain exercise than a practical forensic tool. Let’s review the iOS 16 compatibility in iOS Forensic Toolkit and go through the whole process step by step.

👉 https://blog.elcomsoft.com/2022/09/ios-16-extracting-the-file-system-and-keychain-from-a11-devices/

#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16 #keychain
Post #517 407
Elcomsoft iOS Forensic Toolkit 8.0 brings forensically sound bootloader-based extraction for select iPhone & iPad models

Elcomsoft iOS Forensic Toolkit 8.0 is a major release bringing support for repeatable, verifiable, and truly forensically sound bootloader-level extraction of 76 Apple devices ranging from the ancient iPhone 4 all the way up to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models, and featuring a refreshed, command-line driven user interface.

👉 https://www.elcomsoft.com/news/822.html

#eift8 #toolkit #apple #iphone #mobileforensic #dfir #ios16
Post #516 420
Entering DFU: iPhone 8, 8 Plus, and iPhone X

DFU (Device Firmware Update) is a special service mode available in many Apple devices for recovering corrupted devices by uploading a clean copy of the firmware. Forensic specialists use DFU during checkm8 extractions (Elcomsoft iOS Forensic Toolkit). Unlike Recovery, which serves a similar purpose, DFU operates on a lower level and is undocumented. Surprisingly, there might be more than one DFU mode, one being more reliable than the others when it comes to forensic extractions. The method described in this article works for the iPhone 8, 8 Plus and iPhone X.

👉 https://blog.elcomsoft.com/2022/09/entering-dfu-iphone-8-8-plus-and-iphone-x/

#iphone #DFU #iOS #eift #mobileforensics
Post #514 446
Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based full file system extraction

Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based extraction support all the way up to iOS 15.3.1 on Apple A11-A15 and M1 devices. The new release delivers full file system extraction for iOS 15.2 through 15.3.1, while still offering file system and keychain extraction support for all earlier versions of iOS.

👉 https://www.elcomsoft.com/news/821.html

#eift #ios #agent #mobileforensics #dfir
Post #513 432
Probing Linux Disk Encryption: LUKS2, Argon 2 and GPU Acceleration

Disk encryption is widely used desktop and laptop computers. Many non-ZFS Linux distributions rely on LUKS for data protection. LUKS is a classic implementation of disk encryption offering the choice of encryption algorithms, encryption modes and hash functions. LUKS2 further improves the already tough disk encryption. Learn how to deal with LUKS2 encryption in Windows and how to break in with distributed password attacks.

👉 https://blog.elcomsoft.com/2022/08/probing-linux-disk-encryption-luks2-argon-2-and-gpu-acceleration/

#LUKS2 #EDPR #EFDD #diskencryption #dfir
Post #512 371
Breaking Windows Passwords: LM, NTLM, DCC and Windows Hello PIN Compared

Modern versions of Windows have many different types of accounts. Local Windows accounts, Microsoft accounts, and domain accounts feature different types of protection. There is also Windows Hello with PIN codes, which are protected differently from everything else. How secure are these types of passwords, and how can you break them? Read along to find out!

👉 https://blog.elcomsoft.com/2022/08/breaking-windows-passwords-lm-ntlm-dcc-and-windows-hello-pin-compared/

#edpr #Windows11 #pincode #dfir #windowshello #password
Post #510 348
Elcomsoft Distributed Password Recovery 4.45 supports Windows Hello PIN codes and LUKS2 encryption

We updated Elcomsoft Distributed Password Recovery and Elcomsoft Forensic Disk Decryptor with support for LUKS2, an updated version of Linux disk encryption tool. The tools work together to extract encryption metadata and launch a password recovery attack. In addition, Elcomsoft Distributed Password Recovery can now break PIN codes protecting Windows accounts on TPM-less systems.

📝 Release notes (PDF)

👉 https://www.elcomsoft.com/news/820.html

#LUKS2 #Windows11 #EDPR #EFDD #diskencryption #pincode #dfir
  • ❤ 1
Post #508 376
New in Elcomsoft System Recovery: Microsoft Azure Accounts, LUKS2 and Forensic Tool Filters

Elcomsoft System Recovery 8.30 introduced the ability to break Windows Hello PIN codes on TPM-less computers. This, however, was just one of the many new features added to the updated release. Other features include the ability to detect Microsoft Azure accounts and LUKS2 encryption, as well as new filters for bootable forensic tools.

👉 https://blog.elcomsoft.com/2022/08/new-in-elcomsoft-system-recovery-microsoft-azure-accounts-luks2-and-forensic-tool-filters/

#ESR #Windows11 #Windows10 #MicrosoftAzure #LUKS2
Post #507 343
Elcomsoft System Recovery 8.30 recovers PIN-protected Windows accounts, supports LUKS2 encryption

Elcomsoft System Recovery, a digital field triage tool, is updated to support PIN-protected Windows 10 and Windows 11 accounts with in-place PIN recovery. The update adds LUKS2 support, detects Microsoft Azure accounts, and improves bootable forensic tools with custom filters.

📝 Release notes (PDF)

👉 https://www.elcomsoft.com/news/819.html

#ESR #Windows #MicrosoftAzure #LUKS2
Post #506 390
checkm8 Extraction: iPhone 7

Elcomsoft iOS Forensic Toolkit supports checkm8 extraction from all compatible devices ranging from the iPhone 4s and all the way through the iPhone X (as well as the corresponding iPad, iPod Touch, Apple Watch and Apple TV models). The new update removes an important obstacle to the acquisition of the iPhone 7 and iPhone 7 Plus devices running recent versions of iOS.

👉 https://blog.elcomsoft.com/2022/07/checkm8-extraction-iphone-7/

#eift #iphone7 #checkm8 #dfir #mobileforensics
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →