When the iCloud Backup Is the Only Copy Left

July 31st, 2026 by Oleg Afonin

An iCloud backup is often the only surviving copy of data no longer on the device. Two ordinary situations show why, and neither involves anything clever on the suspect’s part. What could possibly go wrong, and how can you access the data?

Read the rest of this entry »

The Cloud Gap: Forensic Triage vs. Disk Imaging in the Age of On-Demand Sync

January 8th, 2026 by Oleg Afonin

For decades, the forensic “gold standard” was straightforward: isolate the computer, pull the plug, and image the drive. In that era, what you saw on the screen was physically present on the magnetic platters, waiting to be extracted bit by bit. Today, that assumption is not just outdated; it is plain wrong. The rapid adoption of cloud storage services, partial on-demand synchronization, and full-disk encryption has fundamentally broken the traditional dead-box workflow, turning the simple act of powering down a suspect’s computer into a potential destroyer of evidence.

Read the rest of this entry »

The Shift from Disk Imaging to Digital Triage

January 5th, 2026 by Oleg Afonin

Modern digital forensic labs are facing a crisis of scale. When a search warrant results in the seizure of a dozen laptops, several servers, and a mountain of external drives, the traditional forensic workflow – bit-for-bit imaging followed by exhaustive analysis – becomes a liability rather than an asset. This is precisely where our new tool, Elcomsoft Quick Triage, enters the picture. Designed as a solution for rapid, in-field data acquisition, EQT allows investigators to bypass the “imaging bottleneck” and identify the “smoking gun” in minutes rather than months.

Read the rest of this entry »

Introducing Elcomsoft Quick Triage

December 30th, 2025 by Oleg Afonin

We’re expanding our product line with a new tool: Elcomsoft Quick Triage. With this release, we are expanding into an area we had not previously covered – digital forensic triage. EQT is designed to address a very specific need that arises at the earliest stages of an investigation, when time is limited and quick decisions matter. The new tool is not intended to replace full-featured forensic platforms or in-depth analysis. Instead, it focuses on a different phase of the workflow: fast identification, collection, and review of the most relevant evidence before committing resources to a complete examination.

Read the rest of this entry »

Eighteen Years of GPU Acceleration

November 27th, 2025 by Oleg Afonin

Eighteen years ago, before “GPU acceleration” and “AI data center” became household terms, a small hi-tech company changed the rules of cryptography. In 2007, we unveiled a radical idea – using the untapped power of graphics processors to recover passwords, which coincided with the release of video cards capable of performing fixed-point calculations. What began as an experiment would soon redefine performance computing across nearly every field.

Read the rest of this entry »

Leveraging User Profiles for Smarter Password Attacks

November 24th, 2025 by Oleg Afonin

Most real-world passwords aren’t random – they follow the owner’s habits, preferences, and personal history. Names, birthdays, pets, team loyalties, and even old usernames affect how people build their “secret” strings. By turning this everyday information into structured, prioritized password candidates, analysts can reach higher success rates than with generic dictionaries or blind brute force. This article explains how to transform user data into a focused attack strategy.

Read the rest of this entry »

Password Managers: Security, Risks, and Forensic Implications

November 18th, 2025 by Oleg Afonin

Password managers have become a common part of everyday digital life, helping users handle hundreds of online accounts. They simplify authentication and reduce the need to remember complex credentials, yet the same centralization that makes them convenient also concentrates risk. Modern platforms from Apple, Google and Microsoft all ship with built-in password managers, and many users rely on third-party apps for the same purpose.

Read the rest of this entry »

Breaking Barriers: First Full File System Extraction from Apple TV 4K Running tvOS 26

November 17th, 2025 by Vladimir Katalov

Big news is coming – and this time, it’s from the living room. Our team has successfully extracted a complete file system image from an Apple TV 4K running tvOS 26. This marks the first-ever low-level extraction of Apple’s 26th-generation operating systems, including iOS 26, iPadOS 26, and tvOS 26. No one – not even the major forensic players! – has been able to achieve this before.

Read the rest of this entry »

Which Versions of iOS Are Supported, and Why “It Depends” Is The Best Answer

November 12th, 2025 by Oleg Afonin

Our customers often ask us which exact iOS versions are supported by iOS Forensic Toolkit. There’s always a temptation to answer “all of them,” and while that answer is technically correct, there are a lot of caveats. The devil is in the details, and the real answer depends on what you mean by “support”.

Read the rest of this entry »

Don’t Be a Louvre: How Weak Passwords and Unpatched Software Encourage Breaches

November 10th, 2025 by Oleg Afonin

During the recent investigation into the October 2025 Louvre Museum heist, it was revealed that parts of the museum’s video surveillance network were protected by the default password “Louvre.” Further reporting indicated that sections of the system operated on Windows Server 2003 and relied on outdated surveillance management software. These findings point to long-term neglect of basic cybersecurity practices – specifically, the continued use of obsolete systems and weak authentication measures.

Read the rest of this entry »

Exploring iPadOS, tvOS and audioOS 17 and 18 Devices: File System and Keychain Extraction

November 6th, 2025 by Oleg Afonin

The latest update to iOS Forensic Toolkit brought bootloader-level extraction to a bunch of old iPads, Apple TVs, and even the first-gen HomePod running OS versions 17 and 18. This enabled full file system and keychain extraction on a those older Apple devices that can still run these versions of the OS.

Read the rest of this entry »