ElcomSoft Co. Ltd. rolls out the second beta of iOS Forensic Toolkit 8.0 for Mac, the company’s mobile forensic tool for extracting data from a range of Apple devices. The second beta, which becomes the first publicly available build, expands the ability to perform forensically sound file system extractions from a range of iPhone and iPad devices, now supporting all versions of iOS 14 and 15.
Elcomsoft iOS Forensic Toolkit 8.0 beta for Mac improves what was originally implemented in the first beta, continuing to deliver forensically sound extraction of iPhone 5s, iPhone 6, 6 Plus, 6s, 6s Plus, and original iPhone SE devices with a known or empty screen lock passcode. Limited BFU extraction is available for locked devices. Compared to the first beta, EIFT 8.0 b2 brings support for iOS 14 and 15 up to and including iOS 15.1, enabling bootloader-based, forensically sound extraction of supported devices running the latest available versions of iOS.
To preserve digital evidence, the chain of custody begins from the first point of data collection to ensure that digital evidence collected during the investigation remains court admissible. With Elcomsoft iOS Forensic Toolkit, ElcomSoft introduces a forensically sound extraction solution offering verifiable and repeatable results on subsequent extractions. The new method extracts everything from the device down to the last bit, including app sandboxes and encrypted app data, secret chats, some deleted records and a lot more.
When using iOS Forensic Toolkit on a supported device, the checksum of the first extracted image will match the checksums of subsequent extractions provided that the device never rebooted and is stored in the powered-off state between extractions.
The new extraction method is the cleanest yet. ElcomSoft’s implementation of bootloader-based exploit is derived directly from the source. All the work is performed completely in the RAM, and the operating system installed on the device is left untouched and is not used during the boot process.
With this update, Elcomsoft iOS Forensic Toolkit becomes the most advanced iOS acquisition tool on the market, and the only truly forensically sound one delivering repeatable results after subsequent extractions. The list of supported devices will be expanded in subsequent releases.
About Elcomsoft iOS Forensic Toolkit
Elcomsoft iOS Forensic Toolkit provides forensic access to encrypted information stored in popular Apple devices running iOS, offering file system imaging and keychain extraction from the latest generations of iOS devices. By performing low-level extraction of the device, the Toolkit offers instant access to all protected information including SMS and email messages, call history, contacts and organizer data, Web browsing history, voicemail and email accounts and settings, stored logins and passwords, geolocation history, the original plain-text Apple ID password, conversations carried over various instant messaging apps such as Skype or Viber, as well as all application-specific data saved in the device.
About ElcomSoft Co. Ltd.
Founded in 1990, ElcomSoft Co.Ltd. is a global industry-acknowledged expert in computer and mobile forensics providing tools, training, and consulting services to law enforcement, forensics, financial and intelligence agencies. ElcomSoft pioneered and patented numerous cryptography techniques, setting and exceeding expectations by consistently breaking the industry’s performance records. ElcomSoft is Microsoft Certrified Partner, and Intel Software Premier Elite Partner.
Praha 5, Zličín,
Czech Republic, PSČ 155 21
Formulaire pour la réaction des représentats officiels de la compagnie Elcomsoft.