Elcomsoft iOS Forensic Toolkit 6.51 adds forensic extraction support for devices running iOS 14. Full file system extraction with keychain decryption are available for devices supporting the checkra1n jailbreak, while extended logical acquisition is now compatible with all iOS 14 devices.
Elcomsoft iOS Forensic Toolkit 6.51 extends the list of supported iOS releases, adding forensic extraction support for iOS 14 devices. The new release offers full file system extraction with keychain decryption on devices supporting the checkra1n jailbreak, including BFU extraction of locked devices. Extended logical acquisition is now supported on all devices running iOS 14 and iPadOS 14.
File system and keychain extraction
The file system extraction and keychain decryption are now available for select Apple devices running iOS 14. The supported range of devices includes models supported by the checkra1n jailbreak, which currently include the iPhone 6s, 6s Plus and the original iPhone SE. Support for the iPhone 7 and 7 Plus is on the way, while the iPhone 8, 8 Plus and iPhone X generation support is unlikely at this point.
Jailbroken devices are supported in both AFU and BFU extraction modes. BFU extraction enables partial file system and partial keychain acquisition from devices locked with an unknown passcode.
Extended logical acquisition
Support for extended logical acquisition helps experts extract a local backup, pull media files, some system logs and app shared data from devices running iOS 14 and iPadOS 14. The updated iOS release introduced minor changes in the backup protocol. iOS Forensic Toolkit 6.51 has been updated to conform to these changes, now offering the full range of acquisition options from the extended logical workflow.
Release notes:
Per saperne di più
• Leggi l’articolo «Mobile Forensics: Are You Ready for iOS 14?» sul nostro blog (in ing.)Links