Follow PATCtech Here

 

PATCtech NOW
news & updates

  1. Promotional Exams

Wi-Fi Forensics: What Wi-Fi Reveals

Oxygen Adds Spyware Detection

Internet Evidence Finder 5.4 Released

ISP Subscriber Information & 4th Amdnement

COW's and Cellular Records

Is Law Enforcement Ready for Wi-Fi Technology?

Free Webinar - Shadow Copy Forensics


 
Get a Quote

DIGITAL FORENSICS UTILITIES

IOS TOOLKIT
Crack Passwords, Recover Deleted Data and Beat Encyption on iPhones


Enhanced Forensic Access to iPhone/iPad/iPod Devices running Apple iOS

 

Perform the complete forensic analysis of encrypted user data stored in certain iPhone/iPad/iPod devices running iOS 4.x and 3.x. Elcomsoft iOS Forensic Toolkit allows eligible customers acquiring bit-to-bit images of devices’ file systems, extracting phone secrets (passcodes, passwords, and encryption keys) and decrypting the file system dump. Access to most information is provided in real-time.

 

Features and Benefits

  • An all-in-one, complete solution
  • Acquire complete, bit-precise device images
  • Device keys and keychain items recovery
  • Quick acquisition (1hr 20min typical – for 32 GB models)
  • Zero-footprint operation leaves no traces and requires no modifications to devices’ contents
  • Every step of investigation is fully logged
  • Support of most current iOS 3.x and 4.x devices
  • Passcode not required (*)
  • Instant iOS 3.x passcode recovery
  • Simple 4-digit iOS 4.x passcodes recovered in 20-40 minutes
  • Physical and logical acquisition supported
  • Mac and Windows versions available
  • Automatic and manual modes available
  • Availability restricted to select government entities

 

Lantern is available for resale through PATCtech
-Request Official Quote

 

Custom Labs

 

 X4 Data Auger ~ Digital Forensics Data Center
 X3 Digital Forensics Lab
 X2 Digital Forensics Lab
 X1 Digital Forensics Lab

 

Restricted Use: ElcomSoft restricts the availability of the toolkit to select government entities such as law enforcement and forensic organizations and intelligence agencies.

 

Access More Information than Available in iPhone Backups

 

ElcomSoft already offers the ability to access information stored in iPhone/iPad/iPod devices by decrypting data backups made with Apple iTunes. The new toolkit offers access to much more information compared to what’s available in those backups, including access to passwords and usernames, email messages, SMS and mail files.

 

Huge amounts of highly sensitive information stored in users’ smartphones can be accessed. Historical geolocation data, viewed Google maps and routes, Web browsing history and call logs, pictures, email and SMS messages, usernames, passwords, and nearly everything typed on the iPhone is being cached by the device and can be accessed with the new toolkit.

 

Zero Footprint Operation

 

Elcomsoft iOS Forensic Toolkit provides true zero-footprint operation, leaving no traces and making no changes to the contents of the device.

 

Real-Time Access to Encrypted Information

 

Unlike previously employed methods relying on lengthy dictionary attacks or brute force password recovery, the new toolkit can extract most encryption keys out of the physical device. With encryption keys handily available, access to most information is provided in real-time. A typical acquisition of an iPhone device takes approximately 1 hour and 20 minutes; more time is required to process 64-Gb versions of Apple iPad. The list of exceptions is short, and includes user’s passcode, which can be brute-forced or recovered with a dictionary attack.

 

Keychain Recovery

 

Elcomsoft iOS Forensic Toolkit can access iOS secrets including most keychain items, opening investigators access to highly sensitive data such as login/password information to Web sites and other resources.

 

Passcode Not Required (But May Come Handy)

 

Knowing the original passcode is never required, but may come handy in the case of iOS 4.x devices only. The following chart helps to understand whether you’ll need a passcode for a successful acquisition.

 

iOS 3.x: passcode not required. All information will be accessible. The original passcode will be instantly recovered and displayed.

 

iOS 4.x: certain information is protected with passcode-dependent keys, including the following:

  • Email messages;
  • Keychains (stored login/password information);
  • Certain third-party application data, if the application requested strong encryption.

iOS 4.x Passcode Recovery

Elcomsoft iOS Forensic Toolkit can brute-force iOS 4.x passcodes in 20-40 minutes for a 4-digit passcode. Complex passcodes can be recovered, but require more time.

 

Escrow File Support

 

Alternatively, an escrow file can be used to decrypt protected pieces of information even without knowing the original passcode. (An escrow file can be obtained from a computer with which the device under investigation has been connected/synced).

 

System Requirements

 

iOS Forensic Toolkit for Mac OS X requires an Intel-based Mac computer running Mac OS X 10.6 (Snow Leopard) or Mac OS X 10.7 (Lion) with iTunes 10.2 or later installed.

 

The Toolkit for Microsoft Windows requires the computer running Windows XP or Windows 7 with iTunes 10.2 or later installed.

 

Other versions of Mac OS X, Windows and iTunes might also work but have not been tested.

 

Compatible Devices and Platforms

 

The Toolkit currently supports the following iOS devices:

  • iPhone 3G
  • iPhone 3GS
  • iPhone 4 (GSM and CDMA models)
  • iPod Touch (3rd and 4th generations)
  • iPad (1st generation only)

Supported operating systems:

  • iOS 3.x (up to 3.1.3)
  • iOS 4.x – up to iOS 4.3.5 (up to iOS 4.2.10 for iPhone 4 CDMA)

 

  iPhone 3G iPhone 3Gs, iPod Touch 3th gen, iPad iPhone 4, iPod Touch 4th gen
  iOS 3.x iOS 4.x iOS 3.x iOS 4.x iOS 4.x
Physical imaging Yes! Yes! Yes! Yes! Yes!
Logical imaging Yes! Yes! Yes! Yes! Yes!
Passcode recovery instant Yes! instant Yes! Yes!
Keychain decryption Yes! Yes! Yes! Yes! Yes!
Disk decryption(*) N/A N/A N/A Yes! Yes!

 

(*) Devices originally shipped with iOS 3.x, including those running iOS 4.x that were upgraded from iOS 3.x without performing “erase install”, do not have Data Protection enabled, and user partitions are not encrypted. Therefore, the decryption is not required.

 
     
 
 
 

--FORENSICS--
--SOLUTIONS--

LABS
Kits
Mobile Forensics
Computer Forensic
Tools/Utilities
Free

VIEW ALL

GET QUOTE

--FORENSICS--
--SERVICES--

Cell Phone
Computer

--VIEW ALL--

 

All brand names and trademarks are the sole property of the respective manufacturers.

 
 
 
 
PATCtech is a division of the Public Agency Training Council
5235 Decatur Blvd  -   Indianapolis, IN  46241   -  800.365.0119