iOS 16: SEP Hardening, New Security Measures and Their Forensic Implications

September 23rd, 2022 by Vladimir Katalov

iOS 16 brings many changes to mobile forensics. Users receive additional tools to control the sharing and protection of their personal information, while forensic experts will face tighter security measures. In this review, we’ll talk about the things in iOS 16 that are likely to affect the forensic workflow.

Read the rest of this entry »

iOS Forensic Toolkit 8.0 Now Official: Bootloader-Level Extraction for 76 Devices

September 22nd, 2022 by Oleg Afonin

iOS Forensic Toolkit 8.0 is officially released! Delivering forensically sound checkm8 extraction and a new command-line driven user experience, the new release becomes the most sophisticated mobile forensic tool we’ve released to date.

Read the rest of this entry »

iOS 16: Extracting the File System and Keychain from A11 Devices

September 22nd, 2022 by Vladimir Katalov

Bootloader-based acquisition is the only 100% forensically sound data extraction method for Apple devices. It is the only way to acquire the full set of data from those devices that run iOS 16, albeit with a huge caveat that makes the whole thing more of a brain exercise than a practical forensic tool. Let’s review the iOS 16 compatibility in iOS Forensic Toolkit and go through the whole process step by step.

Read the rest of this entry »

Entering DFU: iPhone 8, 8 Plus, and iPhone X

September 13th, 2022 by Oleg Afonin

DFU (Device Firmware Update) is a special service mode available in many Apple devices for recovering corrupted devices by uploading a clean copy of the firmware. Forensic specialists use DFU during checkm8 extractions (Elcomsoft iOS Forensic Toolkit). Unlike Recovery, which serves a similar purpose, DFU operates on a lower level and is undocumented. Surprisingly, there might be more than one DFU mode, one being more reliable than the others when it comes to forensic extractions. The method described in this article works for the iPhone 8, 8 Plus and iPhone X.

Read the rest of this entry »

Low-Level Extraction of iOS 15.2-15.3.1

August 25th, 2022 by Oleg Afonin

iOS Forensic Toolkit 7.60 brings gapless low-level extraction support for several iOS versions from iOS 15.2 up to and including iOS 15.3.1, adding full file system extraction support for Apple devices based on Apple A11-A15 and M1 chips.

Read the rest of this entry »

Probing Linux Disk Encryption: LUKS2, Argon 2 and GPU Acceleration

August 16th, 2022 by Oleg Afonin

Disk encryption is widely used desktop and laptop computers. Many non-ZFS Linux distributions rely on LUKS for data protection. LUKS is a classic implementation of disk encryption offering the choice of encryption algorithms, encryption modes and hash functions. LUKS2 further improves the already tough disk encryption. Learn how to deal with LUKS2 encryption in Windows and how to break in with distributed password attacks.

Read the rest of this entry »

Breaking Windows Passwords: LM, NTLM, DCC and Windows Hello PIN Compared

August 16th, 2022 by Oleg Afonin

Modern versions of Windows have many different types of accounts. Local Windows accounts, Microsoft accounts, and domain accounts feature different types of protection. There is also Windows Hello with PIN codes, which are protected differently from everything else. How secure are these types of passwords, and how can you break them? Read along to find out!

Read the rest of this entry »

Windows Hello: No TPM No Security

August 4th, 2022 by Oleg Afonin

While Windows 11 requires a Trusted Platform Module (TPM), older versions of Windows can do without while still using PIN-based Windows Hello sign-in. We prove that all-digit PINs are a serious security risk on systems without a TPM, and can be broken in a matter of minutes.

Read the rest of this entry »

New in Elcomsoft System Recovery: Microsoft Azure Accounts, LUKS2 and Forensic Tool Filters

August 4th, 2022 by Oleg Afonin

Elcomsoft System Recovery 8.30 introduced the ability to break Windows Hello PIN codes on TPM-less computers. This, however, was just one of the many new features added to the updated release. Other features include the ability to detect Microsoft Azure accounts and LUKS2 encryption, as well  as new filters for bootable forensic tools.

Read the rest of this entry »

checkm8 Extraction: iPhone 7

July 28th, 2022 by Vladimir Katalov

Elcomsoft iOS Forensic Toolkit supports checkm8 extraction from all compatible devices ranging from the iPhone 4s and all the way through the iPhone X (as well as the corresponding iPad, iPod Touch, Apple Watch and Apple TV models). The new update removes an important obstacle to the acquisition of the iPhone 7 and iPhone 7 Plus devices running recent versions of iOS.

Read the rest of this entry »