Elcomsoft iOS Forensic Toolkit 2021 Mac perform physical and logical acquisition of iPhone, iPad and iPod Touch devices. Image device file system, extract device secrets and decrypt the file system image.
- Physical acquisition for 64-bit iOS devices with or without a jailbreak
- Logical acquisition extracts backups, crash logs, media and shared files
- Unlocks iOS devices with pairing records (lockdown files)
- Extracts and decrypts protected keychain items
- Real-time file system acquisition
- Automatically disables screen lock for smooth, uninterrupted acquisition.
Elcomsoft iOS Forensic Toolkit Mac Features:
- Supported Devices and Acquisition Methods
- Apple Watch and Apple TV Extraction
- Logical Acquisition with Lockdown Support
- Keychain Extraction.
Extracting all devices with iOS 13 through 13.5 with unc0ver. The latest release enables the extraction (full file system and keychain) of Apple devices running all versions of iOS 13 up to and including the latest iOS 13.5. The extraction is available for all devices compatible with the unc0ver jailbreak. The up to date compatibility matrix is applicable to all Apple devices capable of running the corresponding version of iOS:
- iOS 13.0 – 13.5: full file system + keychain via unc0ver or checkra1n jailbreaks
- iOS 13.0 – 13.3: full file system + keychain via forensically sound extraction agent (no jailbreak required)
- iOS 13.3.1 – 13.4.1: full file system only (no keychain) via forensically sound extraction agent (no jailbreak required).
- Mac OS X Kodiak, 10.0 (Cheetah), 10.1 (Puma), 10.2 (Jaguar), 10.3 (Panther), 10.4 (Tiger), 10.5 (Leopard), 10.6 (Snow Leopard), 10.7 (Lion)
- OS X 10.8 (Mountain Lion), 10.9 (Mavericks), 10.10 (Yosemite), 10.11 (El Capitan)
- macOS 10.12 (Sierra), 10.13 (High Sierra), 10.14 (Mojave), 10.15 (Catalina), 11.0 (Big Sur) and Later Version.
- Supported hardware: Intel or PowerPC Mac.