ElcomSoft iOS Forensic Toolkit 2023

ElcomSoft iOS Forensic Toolkit


This article shows you how to download and install the full version of ElcomSoft iOS Forensic Toolkit v7.0.313 for free on PC. Follow the direct download link and instructions below for guidance on installing ElcomSoft iOS Forensic Toolkit v7.0.313 on your computer.

Table of contents

  • About the software
  • ElcomSoft iOS Forensic Toolkit v7.0.313 System Requirements
  • How to Download and Install ElcomSoft iOS Forensic Toolkit v7.0.313
  • Required files

About the software

Perform full file system and logical acquisition of iPhone, iPad and iPod Touch devices. Image device file system, extract device secrets (passwords, encryption keys and protected data) and decrypt the file system image.

iOS Forensic Toolkit 8 for Mac introduces a new extraction method for select iOS devices based on the modified bootloader. The new extraction method is the cleanest yet, enabling repeatable, verifiable extractions and forensically sound workflow.

The forensically sound bootloader-level extraction process is available for 76 Apple devices ranging from the ancient iPhone 4 all the way up to the iPhone X, a large number of iPad, iPod Touch, Apple Watch, and Apple TV models. The newly developed checkm8 extraction process supports a range of major OS releases from iOS 7 through iOS 16.2 in three different flavors (iOS, tvOS, watchOS) for three different architectures (arm64, armv7, armv7k).

For devices based on the armv7 and armv7k architecture full passcode unlock along with file system extraction and keychain decryption are available. For newer arm64-based devices, full file system extraction and keychain decryption are supported for devices with a known or empty passcode.

Elcomsoft iOS Forensic Toolkit can extract keychain items including those protected with ThisDeviceOnly attribute, opening investigators access to highly sensitive data such as login/password information to Web sites and other resources (and, in many cases, to Apple ID).

The device must remain unlocked during the entire keychain acquisition process. iOS Forensic Toolkit implements a tool to disable automatic screen lock.

The main features of ElcomSoft iOS Forensic Toolkit are:

  • Apple Watch and Apple TV Extraction
  • Keychain Extraction
  • DFU/Recovery Mode
  • Full file system extraction and keychain decryption without a jailbreak
  • Logical acquisition extracts backups, crash logs, media and shared files
  • Passcode unlock and physical acquisition for legacy devices
  • Extracts and decrypts protected keychain items
  • Repeatable, forensically sound extraction for select iPhone and iPad models through modified bootloader
  • Automatically disables screen lock for smooth, uninterrupted acquisition

ElcomSoft iOS Forensic Toolkit v7.0.313 System Requirements

  • Windows 7/8/8.1/10/11
  • macOS 10.13 High Sierra
  • macOS 10.14 Mojave
  • macOS 10.15 Catalina
  • macOS 11 Big Sur
  • macOS 12 Monterey

How to Download and Install ElcomSoft iOS Forensic Toolkit v7.0.313

  1. Click on the download button(s) below and finish downloading the required files. This might take from a few minutes to a few hours, depending on your download speed.
  2. Extract the downloaded files. If you don’t know how to extract, see this article. The password to extract will always be: QWERTY!
  3. Run Setup.exe and install the software