Elcomsoft iOS Forensic Toolkit 2.1 Adds Physical Acquisition of Latest Versions of iOS, Implements Built-In Logical Acquisition

We updated iOS Forensic Toolkit with two major features. Version 2.1 comes with physical acquisition support for jailbroken iOS devices running Apple’s latest version of iOS, the iOS 9.3.3. In addition, we complemented iOS Forensic Toolkit with full logical acquisition support. Supporting iTunes pairing records and working completely stand-alone, Elcomsoft iOS Forensic Toolkit becomes a true one-stop solution for acquiring Apple mobile devices.

Jailbreak for the latest versions of iOS has not been available for four straight months. For the forensic community, this meant holding back their acquisition attempts if the device was running iOS 9.2 or newer. Pangu team released a new jailbreak for iOS 9.2 through 9.3.3, allowing us to quickly add physical acquisition support for devices running the current OS.

In this release, we added full logical acquisition support, allowing experts to create iTunes-style backups without using iTunes. Devices locked with unknown passcode may be acquired using lockdown files extracted from the suspect's PC. Finally, if no backup password is set, we’ll automatically configure the system with a temporary password in order to be able to decrypt keychain items (password will be reset after the acquisition).

Get more information on Elcomsoft iOS Forensic Toolkit:

Read a press release:

Read our new blog post "iOS Logical Acquisition: The Last Hope For Passcode-Locked Devices?"