Description of ElcomSoft iOS Forensic Toolkit
You can download the ElcomSoft iOS International Software Toolkit from our software library for free. This toolkit is designed for iOS to perform physical and logical acquisitions of iPhone, iPad, and iPod Touch devices. It allows for the imaging of the device's file system, extraction of device secrets (such as passwords, encryption keys, and protected data), and decryption of the file system image.
- Physical acquisition for 64-bit iOS devices
- Logical acquisition from backup extracts, crash logs, media, and shared files
- Unlocks iOS devices with pairing logs (lock files)
- Extracts and decrypts protected keychain items
- Real-time file system acquisition
- Automatically disables the screen lock for smooth and uninterrupted acquisition
Features of ElcomSoft iOS
Enhanced forensic access to iPhone/iPad/iPod devices running Apple iOS
Enables complete forensic acquisition of user data stored on iPhone/iPad/iPod devices. The Elcomsoft iOS Forensic Toolkit allows for imaging of device file systems and extraction of device secrets (passcodes, passwords, encryption keys) and decryption of the file system image. Access to most information is provided instantly. Please note that some models require jailbreaking. Check compatible devices and platforms for details.
Physical acquisition of iOS devices
Physical acquisition is the only method to extract complete application data, protected keychain items, downloaded messages, and location history. Physical acquisition returns more information compared to logical acquisition due to direct access to low-level data. The Elcomsoft iOS Forensic Toolkit supports jailbroken 64-bit devices (iPhone 5s and later) running most iOS versions from 7 to 12.
Logical acquisition with keychain extraction
The iOS Forensic Toolkit supports logical acquisition, which is a simpler and safer acquisition method compared to physical. Logical acquisition results in a standard iTunes-like backup of the information stored on the device. While logical acquisition returns less information than physical acquisition, experts recommend creating a logical backup of the device before attempting more intrusive acquisition techniques.
Logical acquisition with the iOS Forensic Toolkit is the only method that allows access to encrypted keychain items. Logical acquisition should be used in conjunction with physical acquisition to extract all possible types of evidence.
Physical Acquisitions for iOS Devices
- Physical acquisition is the only method to extract complete application data, protected keychain items, downloaded messages, and location history. Physical acquisition returns more information compared to logical acquisition due to direct access to low-level data. The Elcomsoft iOS Toolkit supports jailbroken 64-bit iPhone 5s and later devices running most iOS versions from 7 to 12.
Logical Acquisition with Key Extraction
- The iOS Forensic Toolkit supports logical acquisition, which is a simpler and safer acquisition method. Logical acquisition produces a standard iTunes-like backup of the information stored on the device. While logical acquisition returns less information than physical acquisition, experts recommend creating a logical backup of the device before attempting more aggressive acquisition techniques.
- Logical acquisition with the iOS Forensic Toolkit is the only method that allows access to encrypted keychain items. Logical acquisition should be used in conjunction with physical acquisition to extract all possible types of evidence.
System Requirements for ElcomSoft iOS Forensic Toolkit
Before you start downloading the ElcomSoft iOS Forensic Toolkit for free, make sure your computer meets the minimum system requirements. Operating System: Windows 7/8/8.1/10
Memory (RAM): 1 GB of RAM required.
Hard Disk Space: 500 MB of free space required.
Processor: Intel Pentium 4 or newer.

