«iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4, the Apple Watch Series 5, and the second-generation Apple TV 4K. This article gives the full procedure for each of the two Apple Watch devices. The method uses usbliter8, an exploit of the SecureROM, the read-only boot code in the chip. checkm8 […]»
23 September, 2026Vladimir Katalov
«Seven years after checkm8, iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4 and Series 5, as well as the second-generation Apple TV 4K. In each case the result is the full file system image and the decrypted keychain. This is the first time that the low-level extraction boundary has moved […]»
22 September, 2026Oleg Afonin
«Elcomsoft Quick Triage 2.2 adds three things: a Timeline view that merges events from every timestamped artifact into one chronology, a file system snapshot that copies metadata without file contents, and a plugin architecture for artifact parsers. The release also brings MSA password attacks, OpenDocument parsing and recursive archive parsing in full-text search, and a […]»
3 September, 2026Oleg Afonin