Sideloading the extraction agent: a Stolen Device Protection workaround
A new update to iOS Forensic Toolkit is out. The headline feature is an alternative installation method for the extraction agent – that is, deploying it onto an iPhone while bypassing the mandatory...
View ArticleDownloading iOS 26 iCloud Backups
Elcomsoft Phone Breaker 11.2 adds the ability to download iCloud backups created on devices running iOS and iPadOS 26 and, by extension, iOS/iPadOS 27 beta. With this release, Elcomsoft Phone Breaker...
View ArticleDownloading iPhone and iPad backups from Apple iCloud
Pulling a backup out of iCloud is one of the more technically demanding jobs in cloud forensics. An iCloud backup is not a single, ready-to-download file; instead, it is assembled from a large number...
View ArticleElcomsoft Phone Breaker 11 Restores iCloud Access
Extracting cloud data becomes increasingly valuable – and increasingly complex at the same time. In scenarios where a target device is physically unavailable cloud extraction is often the only real way...
View ArticleLow-Level Extraction for iOS 17 and 18
We’ve just updated iOS Forensic Toolkit to version 10.0, significantly expanding its low-level extraction capabilities for both the extraction agent and bootloader-based methods. Previously,...
View ArticlePerfect Acquisition With Passcode Unlock for A8/A8X Devices
Perfect Acquisition is the most reliable method to acquire data from an iOS device. It is completely forensically sound – it doesn’t modify a single bit of the filesystem. When supported, this method...
View ArticleIntroducing Elcomsoft Quick Triage
We’re expanding our product line with a new tool: Elcomsoft Quick Triage. With this release, we are expanding into an area we had not previously covered – digital forensic triage. EQT is designed to...
View ArticleBreaking Barriers: First Full File System Extraction from Apple TV 4K Running...
Big news is coming – and this time, it’s from the living room. Our team has successfully extracted a complete file system image from an Apple TV 4K running tvOS 26. This marks the first-ever low-level...
View ArticleExploring iPadOS, tvOS and audioOS 17 and 18 Devices: File System and...
The latest update to iOS Forensic Toolkit brought bootloader-level extraction to a bunch of old iPads, Apple TVs, and even the first-gen HomePod running OS versions 17 and 18. This enabled full file...
View ArticleExtracting Apple Unified Logs
In our previous post, Extracting and Analyzing Apple sysdiagnose Logs, we explained the difference between sysdiagnose logs and Apple Unified Logs. Today we’ll show how the latest build of iOS Forensic...
View ArticleCheat Sheet: Perfect Acquisition (32-bit)
Perfect Acquisition is the most sophisticated method for extracting data from compatible iOS devices. This method is completely forensically sound; it doesn’t modify a single bit of the filesystem....
View ArticleiOS Forensic Toolkit Now Supports All Models of Apple Watch
We’ve released an important update to iOS Forensic Toolkit: the Toolkit now supports logical extraction from Apple Watch Series 6 (with a wired third-party adapter) and Apple Watch Series 7 through 10,...
View ArticleExtraction Agent: Offline Extraction with All Developer Accounts
We are excited to announce an update to Elcomsoft iOS Forensic Toolkit that solves a long-lasting issue connected to the installation and use of the low-level extraction agent. In version 8.70, we...
View ArticleElcomsoft Forensic Acquisition System (EFAS)
Forensic acquisition using Elcomsoft iOS Forensic Toolkit (EIFT) has undergone significant changes over the last few years. The earlier major branch, EIFT 7, was a carefully crafted but Windows-only...
View ArticleThe Implications of Resetting the Screen Lock Passcode in iOS Forensics
In the realm of iOS device forensics, the use of the checkm8 exploit for low-level extractions has become a common practice. However, when using this method, you may occasionally need to remove the...
View Articlecheckm8: Advancements in iOS 16 Forensic Extraction
In iOS device forensics, the process of low-level extraction plays a crucial role in accessing essential data for analysis. Bootloader-level extraction through checkm8 has consistently been the best...
View ArticleResource Management in Distributed Password Attacks
In the latest update, Elcomsoft Distributed Password Recovery introduced a new feature that allows managing the available computational resources. The new resource management capability allows...
View ArticleBootloader-Level Extraction for Apple Hardware
The bootloader vulnerability affecting several generations of Apple devices, known as “checkm8”, allows for forensically sound extraction of a wide range of Apple hardware including several generations...
View ArticleiOS Forensic Toolkit: Mounting HFS Images in Windows
The latest update to iOS Forensic Toolkit brought the ability to mount HFS disk images extracted from legacy Apple devices as drive letters on Windows systems. This new capability to mount HFS images...
View ArticleForensically Sound Cold System Analysis
In the world of digital forensics, there are various ways to analyze computer systems. You might be familiar live system analysis or investigating forensic disk images, but there’s yet another method...
View Article