Elcomsoft iOS Forensic Toolkit 8.11 decrypts iOS 15.5 keychain

Elcomsoft iOS Forensic Toolkit 8.11 adds the ability to extract and decrypt the keychain from devices running all versions of iOS/iPadOS up to and including 15.5. The Windows edition is currently available in iOS Forensic Toolkit 7.71, which receives the same update.

Elcomsoft iOS Forensic Toolkit 8.11 brings keychain decryption support to devices running iOS/iPadOS versions up to and including version 15.5 by using the extraction agent. All models capable of running iOS 15 are supported, which includes devices based on the Apple A12 through A15 Bionic, as well as Apple Silicone based devices built on the M1 SoC. For older devices such as the iPhone 8/X, keychain extraction is supported for iOS 15.2.1 and below.

Elcomsoft iOS Forensic Toolkit 8.11 is only available for Mac computers for the time being. For this reason, we are fully committed to maintaining the previous branch of the product, which is also available as a Windows edition. Elcomsoft iOS Forensic Toolkit 7.71 gains the very same features as the newer branch, except for checkm8 support. In this update, the tool received the ability to extract and decrypt the keychain from the same range of iOS/iPadOS devices as iOS Forensic Toolkit 8.11.

The keychain contains the most essential evidence, which includes passwords to web sites, Wi-Fi access points and mail accounts, passwords to cloud services/accounts, credit card numbers and a lot of encryption keys such as those protecting encrypted conversations in secure instant messaging apps.

Please refer to the following chart for details on the types of extraction supported on the different platforms:

Elcomsoft iOS Forensic Toolkit release notes:

  • Extraction agent: added keychain acquisition for iOS 15.2 to 15.5
  • Extraction agent: improved keychain acquisition for iOS 14 and older versions
  • Minor fixes and improvements