About iOS device images

<< Click to Display Table of Contents >>

Navigation:  Elcomsoft Phone Viewer > Working with Apple device data >

About iOS device images

EPV allows you to view iOS device images acquired via Elcomsoft iOS Forensic Toolkit.

 

Elcomsoft iOS Forensic Toolkit (EIFT) is a set of tools aimed at acquiring iOS devices. EIFT allows you to do the following:

Obtain information about the device, even if it is locked.

Obtain the snapshot of user partitions, capturing the entire file system.

Perform logical acquisition by producing the iTune-style backup (can use lockdown file to unlock).

32-bit devices: Obtain the physical (dd-style) dump of the root (system) and user (data) partitions.

32-bit devices: Extract all keys required to decrypt user (data) filesystem as well as keychain items.

32-bit devices: Run the passcode recovery attack.

NOTE: Jailbreak and OpenSSH installation are required to acquire iPhone 4s and newer devices.

 

EIFT iOS device images have the .tar extension. Currently, EPV supports only physical iOS device images acquired via EIFT.