
ElcomSoft
@ElcomSoft
Followers
11K
Following
4K
Media
722
Statuses
7K
ElcomSoft's Official Twitter. Password recovery, mobile & cloud forensics.
Joined March 2009
Apple Watch S0 forensics: cracking the passcode, full physical acquisition #dfir.
blog.elcomsoft.com
Welcome to Part 5 of the Perfect Acquisition series! In case you missed the previous parts, please check them out for background information. This section provides a comprehensive guide to performing...
0
0
0
We previously tested disk imaging speeds using high-performance storage devices. But raw speed is only part of the equation. In this article, we explore the key reasons why both speed and accuracy can fall short during disk imaging. #dfir.
blog.elcomsoft.com
We previously tested disk imaging speeds using high-performance storage devices. But raw speed is only part of the equation. Even under ideal conditions, getting a fully correct and complete image...
0
0
7
Can AI help with password cracking? The idea sounds promising: use LLMs to produce rules and templates for guessing highly probable password variants, prioritizing the most likely ones first. But in practice, things aren’t so straightforward. #dfir.
blog.elcomsoft.com
Artificial intelligence is everywhere - from phones that guess your next move to fridges that shop for you. It's only natural to ask whether AI can help in a more serious domain: digital forensics,...
0
0
2
Apple’s unified logging system offers a wealth of information for forensic investigators analyzing iOS, iPadOS, watchOS, tvOS devices. This article explores the content, availability, and forensic value of these logs #dfir.
blog.elcomsoft.com
Apple’s unified logging system offers a wealth of information for forensic investigators analyzing iOS, iPadOS, watchOS, tvOS, and other devices from Apple ecosystems. Originally designed for...
0
2
6
The 16 Billion Passwords Panic: What Really Happened and Why It Matters (Or Doesn’t) #dfir.
blog.elcomsoft.com
In June 2025, headlines shouted that 16 billion passwords had leaked. Major outlets warned that credentials for Apple, Google, and other platforms were now exposed. As expected, this triggered a wave...
0
0
2
If you’re doing forensic work today, odds are you’re imaging SSDs, not just spinning hard drives. And SSDs don’t behave like HDDs – especially when it comes to deleted files. One key reason: the TRIM command. TRIM makes SSDs behave different to HDD drives
blog.elcomsoft.com
If you're doing forensic work today, odds are you’re imaging SSDs, not just spinning hard drives. And SSDs don’t behave like HDDs - especially when it comes to deleted files. One key reason: the TRIM...
0
1
4
Why Every Digital Forensics Lab Needs a Good USB Hub #dfir.
blog.elcomsoft.com
In modern digital forensics, a reliable USB hub isn’t just a convenience - it’s a critical piece of lab infrastructure. With today's laptops (especially MacBooks) offering only one or two USB-C ports...
0
0
4
With minimal functional differences between Mac, Windows & Linux editions, the new, bootable Live Linux version of iOS Forensic Toolkit allows for seamless bootloader-level extractions, booting from an external device and utilizing all the necessary tools
blog.elcomsoft.com
Acquiring data from iOS devices can be a complex task, particularly when performing bootloader-based extractions leveraging the checkm8 exploit. Traditionally, these extractions required access to a...
0
0
3
A forensic examiner receives a locked smartphone – a recent-model iPhone, encrypted and secured with an unknown passcode. No tool works, checkm8 long obsolete, USB port locked. Is this a dead end? Not quite. iPhones don’t operate in isolation. #dfir.
blog.elcomsoft.com
A forensic examiner receives a locked smartphone - a recent-model iPhone, encrypted and secured with an unknown passcode. No tool works, checkm8 long obsolete, USB port locked. Is this a dead end?...
0
0
5
In Elcomsoft iOS Forensic Toolkit 8.70, we introduce a critical improvement: you can now sideload and launch the extraction agent completely offline using any Apple Developer account – regardless of when it was created.
blog.elcomsoft.com
We are excited to announce an update to Elcomsoft iOS Forensic Toolkit that solves a long-lasting issue connected to the installation and use of the low-level extraction agent. In version 8.70, we...
0
1
2
We’ve released an important update to iOS Forensic Toolkit: the Toolkit now supports logical extraction from Apple Watch Series 7 through 10, SE2, Ultra, and Ultra 2 (via a special wireless adapter). #dfir.
blog.elcomsoft.com
We've released an important update to iOS Forensic Toolkit: the Toolkit expands logical acquisition to all newer models of Apple Watch starting from Apple Watch Series 6 (with a wired third-party...
0
1
2
Microsoft Goes Passwordless: Forensic Implications of Passwordless Microsoft Accounts #dfir.
blog.elcomsoft.com
Microsoft has officially announced that newly created Microsoft Accounts will now be passwordless by default for "simpler, safer sign-ins". This change extends the direction set by Windows 11, where...
1
0
4
NVIDIA GeForce RTX 5090 Power Connectors Melting Again
blog.elcomsoft.com
Just a week ago, we published an article about NVIDIA’s new generation of Blackwell-based graphics cards. Despite a noticeable price hike, performance gains in this generation are minimal, with one...
0
0
1
Apple Disables Advanced Data Protection for iCloud in UK #dfir.
blog.elcomsoft.com
In the beginning of February, Apple may have received a secret order requiring the company to create an encryption backdoor. According to a leak, the UK government demanded blanket, covert access to...
0
0
1
Intelligent Load Balancing: Optimizing Password Recovery Across Heterogeneous Units. #dfir #passwords.
blog.elcomsoft.com
In the latest update of Elcomsoft Distributed Password Recovery (EDPR), we've introduced a revamped load-balancing feature. The new feature aims to enhance resource utilization on local workstations...
0
0
1
When Speed Matters: Imaging Fast NVMe Drives #dfir // thanks to @OSForensics.
blog.elcomsoft.com
Modern NVMe SSDs require specialized approaches for forensic analysis. Each year, the speed and capacity of these devices grow, presenting significant challenges related to both the speed and...
0
1
2
Outlook Forensic Toolbox Helps Access Deleted Messages #dfir.
blog.elcomsoft.com
What can a forensic expert find in an Outlook data file? Can they recover deleted emails, contacts and appointments from Microsoft Outlook? Can users erase unwanted correspondence from Outlook? In...
0
0
7
When Speed Matters: Optimizing Disk Imaging #dfir // Many thanks to @OSForensics !.
blog.elcomsoft.com
We recently shared an article about maximizing disk imaging speeds, which sparked a lot of feedback from our users and, surprisingly, from the developers of one of the disk imaging tools who quickly...
1
2
11