Working with Elcomsoft iOS Forensic Toolkit
Elcomsoft iOS Forensic Toolkit (EIFT) is a set of tools aimed at making the acquisition of iOS devices easier. EIFT is a combination of software that is able to perform forensic acquisition of iOS devices running any version of iOS (note that some iOS versions require the device to be jailbroken). Currently, EIFT is not capable of physically acquiring data from 64-bit iOS devices (iPhone 6, 6s, and so on.). In order to get any data from a 64-bit iOS device, it must be jailbroken and the best acquisition will be a file system dump. For most other devices, EIFT can acquire bit-for-bit images of a device's file system, extract data including passcodes and passwords and decrypt the file system image. For more information on EIFT, visit http://www.elcomsoft.com/eift.html.
The toolkit was initially available only to law enforcement agencies, but now it is available to everyone. The toolkit supports both Mac OS X and Windows platforms with iTunes 10.6...