Elcomsoft iOS Forensic Toolkit

06.07.2012
Forensics extraction is the process of getting into a computer device (in this case an iOS device) and extracting all the data from it. And is an incredibly powerful piece of kit that enables you to hack into, and extract pretty much everything on an iPhone (passcodes, keys, files, messages, audio recordings, and so on).

Why would you want to do such a thing? Well aside from hacker curiosity the main market for forensics software is law enforcement. In court cases there is often a requirement for detailed recording and analysis of mobile phone devices (text messages, emails, phone voicemail messages, call records, photos and so on).

What piqued our interest at first was data recovery: a friend of a friend's iPhone was showing no signs of life (the battery would not charge).

An iPhone that refuses to charge could be because of a faulty battery, but it's often the case that it's a firmware or iOS installation problem. In this case restoring the iPhone usually fixes the issue, but wipes the iPhone: our friend was adamant that the content on the iPhone was more important than the phone itself. And there was no backup.

All the important files are securely held inside the device itself in encrypted files, often with a passcode lock on the front of the phone. In our situation (with access to passcodes) we could use less powerful software than this; but once we'd heard of the software we asked to give it a professional test.