Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based full file system extraction

Elcomsoft iOS Forensic Toolkit 7.60 extends agent-based extraction support all the way up to iOS 15.3.1 on Apple A11-A15 and M1 devices. The new release delivers full file system extraction for iOS 15.2 through 15.3.1, while still offering file system and keychain extraction support for all earlier versions of iOS.

Elcomsoft iOS Forensic Toolkit 7.60 brings low-level file system extraction to Apple devices running a range previously unsupported versions of iOS. For Apple A11-A15 and M1 devices, the updated extraction agent now supports for iOS 15.2 through 15.3.1, adding full file system extraction support for the previously unsupported range of iOS builds.

In addition, we updated iOS Forensic Toolkit 8.0 beta 13, adding the same agent-based extraction support and extending forensically sound checkm8 extraction to the newly released iOS 15.6.1.

The updated toolkit now supports agent-based full file system extraction for the entire range of iOS releases since iOS 9.0 all the way up to iOS 15.3.1. In addition to file system extraction, keychain decryption is supported on a number of platforms for iOS 9.0 through iOS 15.1.1. Please refer to the following chart for details on the types of extraction supported on the different platforms:

Agent-based extraction offers numerous benefits compared to other acquisition method. The agent does not make any changes to user data, offering the most forensically sound extraction among available acquisition methods.

iOS Forensic Toolkit 7.60 release notes:

  • Agent extraction: added support for iOS 15.2 to 15.3.1 on A11-A15 and M1 devices (full file system only)
  • Bug fixes and performance improvements

iOS Forensic Toolkit 8.0 beta 13 for Mac release notes:

  • Agent extraction: added support for iOS 15.2 to 15.3.1 on A11-A15 and M1 devices (full file system only)
  • checkm8 extraction: added support for iOS 15.6.1
  • Bug fixes and performance improvements

Vedi anche