The toolkit now provides jailbreak-free forensic extraction for the entire range of devices, supporting iPhone 5s through iPhone 12. This update delivers the complete, zero-gap coverage for supported iPhone devices from iOS 9 onwards, up to and including iOS 14.3 on supported devices.
The extraction process is based on the in-house acquisition agent that establishes a communication channel between the iPhone and the computer, enabling low-level access to the file system and the keychain. The extraction agent covers the entire range of iOS releases since iOS 9.0 all the way up to iOS 14.3 for all iPhone models from the iPhone 5s through the current iPhone 12 range with no gaps or exclusions.
Agent-based extraction offers numerous benefits compared to other acquisition methods. The agent does not make any changes to user data, offering the most forensically sound extraction among available acquisition methods.
Elcomsoft iOS Forensic Toolkit 8.0 for Mac introduces a new forensically sound extraction workflow based on a bootloader exploit. The new checkm8-based extraction process enables the most complete extraction experience, pulling all keychain records regardless of the protection class and extracting the entire content of the file system including application sandboxes, chat sessions in secure messaging apps, and a lot of low-level system data that is never included in local or cloud backups.
The new, forensically sound workflow with 100% of the patching occurring in the device RAM enables repeatable, verifiable extractions. For 64-bit devices with unknown screen lock passwords a limited BFU (Before First Unlock) extraction is available, while USB restrictions can be completely bypassed. For 32-bit legacy devices the complete passcode unlock experience is available.
iOS Forensic Toolkit 8.0 brings a new, advanced user experience built around the command line. The use of the command line enables full control over every step of the extraction workflow, allowing experts to stay in control of every step of the process. Thanks to the command line, experts can also build their own scripts to automate their specific routines.
Elcomsoft iOS Forensic Toolkit 8.0 for Mac delivers forensically sound checkm8 extraction to 76 Apple devices ranging from the iPhone 4 to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models. The newly developed extraction process supports a range of major OS releases ranging from iOS 7 through iOS 15.7 in three different flavors (iOS, tvOS, watchOS) for three different architectures (arm64, armv7, armv7k).
For devices based on the armv7 and armv7k architecture full passcode unlock along with file system extraction and keychain decryption are available. For newer arm64-based devices, full file system extraction and keychain decryption are supported for devices with a known or empty passcode. Finally, the latest supported range including the iPhone 8, 8 Plus and iPhone X requires removing the passcode prior to extraction.
With this update, Elcomsoft iOS Forensic Toolkit becomes the most advanced iOS acquisition tool on the market. The toolkit now supports all possible acquisition methods including advanced logical, agent-based and checkm8-based low-level extraction.
Elcomsoft iOS Forensic Toolkit provides forensic access to encrypted information stored in popular Apple devices running iOS, offering file system imaging and keychain extraction from the latest generations of iOS devices. By performing low-level extraction of the device, the Toolkit offers instant access to all protected information including SMS and email messages, call history, contacts and organizer data, Web browsing history, voicemail and email accounts and settings, stored logins and passwords, geolocation history, conversations carried over all instant messaging apps, including the most secure ones such as Signal, Wickr, and Telegram, as well as all application-specific data saved in the device.
Elcomsoft iOS Forensic Toolkit 8 for Windows retains and extends all the features of EIFT 7. The Toolkit offers advanced logical and low-level extraction with the help of the custom extraction agent. The macOS edition continues to exclusively support forensically sound bootloader-level extraction.
iOS Forensic Toolkit 8 no longer requires installation. The new portable package enables experts to access the Toolkit without the hassle of installation. Experts can start using the product immediately by simply unpacking the archive using the password provided in the registration email.
iOS Forensic Toolkit 8.41 brings advanced user experience built around the command line. Leveraging the command line provides complete control throughout the extraction workflow, allowing experts to stay in control if any step of the process requires additional attention. Thanks to the command line, experts can also build custom scripts to automate their specific routines.
With this update, Elcomsoft iOS Forensic Toolkit becomes the most advanced iOS acquisition tool on the market. The toolkit supports all possible acquisition methods including advanced logical and agent-based extraction, while the macOS edition additionally features forensically sound low-level extraction based on the bootloader exploit.
NEW YORK, Nov. 30, 2023 /PRNewswire/ -- ElcomSoft releases iOS Forensic Toolkit 8.50, a major update to the company's mobile forensic extraction tool for Apple devices. The update introduces the Linux edition, which enables forensic extractions of Apple devices on Linux-based computers.
The Linux edition supports forensically sound bootloader-level extraction, previously a feature exclusive to macOS. This opens a window of opportunity for experts who don't have access to a Mac, enabling true forensically sound extractions of more than ten generations of Apple devices up to and including the iPhone 8, 8 Plus, and iPhone X.
The release of the Linux edition is ElcomSoft's final step towards true multiplatform compatibility. The tool has been tested on multiple Linux distributions, officially supporting the current Debian, Ubuntu, Kali Linux, and Mint distros.
The update improves iOS version identification during bootloader-level extraction. Formerly, the toolkit attempted to guesstimate the installed iOS version based on the version of the device's bootloader, which could result in several potential matches. The new approach achieves a nearly 100% accurate identification of the iOS version, eliminating any ambiguity in the extraction process.
The update adds support for older models of Apple Watch, allowing macOS and Linux users to get more data like passwords and complete file systems from these watches. Newly supported models include the original Apple Watch, Apple Watch Series 1 and Series 2.
Elcomsoft iOS Forensic Toolkit provides forensic access to encrypted information stored in popular Apple devices. With this update, Elcomsoft iOS Forensic Toolkit becomes the most advanced iOS acquisition tool on the market. The toolkit now supports all possible acquisition methods (with known limitations we're working on). Agent-based extraction and checkm8-based extraction via device RAM are some of the tool's unique features. The list of supported devices will be expanded in subsequent releases.
Founded in 1990, ElcomSoft develops state-of-the-art computer forensics tools, provides computer forensics training and computer evidence consulting services. Since 1997, ElcomSoft has been providing support to businesses, law enforcement, military, and intelligence agencies. ElcomSoft tools are used by most of the Fortune 500 corporations, multiple branches of the military all over the world, foreign governments, and all major accounting firms.
The new low-level extraction method utilizes Elcomsoft proprietary extraction agent, enables full access to the file system and includes the ability to extract sandboxed app data, system databases and other information available in the file system.
Elcomsoft will continue researching the vulnerability used in this release to expand the amount of extractable information, with keychain decryption and iOS 16.4 support planned for the next update. The company remains committed to offering innovative solutions to digital forensic investigators worldwide, and this latest release is a testament to its ongoing dedication to this mission.
With this update, Elcomsoft iOS Forensic Toolkit remains one of the most advanced yet affordable iOS acquisition tools on the market, and is the only forensic tool for extracting Apple Watch, Apple TV, and HomePod devices. The toolkit supports all possible acquisition methods including advanced logical, agent-based and checkm8-based low-level extraction.
795a8134c1