Passware Kit 2020 v2: Mac Version Provides Access To APFS From Mac with T2

Apple takes privacy, security, and encryption very seriously. While the latest improvements in macOS and iOS security help users to keep their data safe, they also create additional challenges for forensic examiners.

All the latest Apple computers are protected with the Apple T2 Chip that provides an additional layer of hardware-based encryption, making it difficult to access APFS disks in a forensically sound way.

We are excited to announce extended support for macOS with the release of a beta version of Passware Kit Forensic for Mac.WHAT'S NEW

  • Access to APFS disks from Mac computers with Apple T2 Chip
  • Passware Kit Forensic for Mac
  • Passwords extraction from macOS system keychains
  • Instant decryption and password recovery for QuickBooks 2020 databases
  • Support for Windows account selection for PIN / password recovery
  • Recovery of Windows accounts’ passwords from SAM databases in batch mode
  • Improved GPU performance
  • UI improvements for displaying recovered passwords
  • [/list:u]

    Access to APFS disks from Mac computers with Apple T2 Chip
    Passware Kit Forensic features a new built-in tool that unlocks APFS disks from Mac computers protected with T2 chip if the iCloud recovery option was enabled.


    Get The Latest DFIR News

    Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


    Unsubscribe any time. We respect your privacy - read our privacy policy.

    The tool requires either iCloud credentials or iOS backup of the same Apple ID.

    Passware Kit Forensic runs from a Mac connected to the target computer via thunderbolt/USB-C, unlocks the APFS disk via iCloud recovery, and mounts it to the customer’s Mac in a read-only mode.

    Passware Kit Forensic for Mac
    Passware introduces a beta version of Passware Kit Forensic for Mac, which supports the key features of a Windows version: file password recovery, FDE decryption, mobile forensics, batch file processing, distributed password recovery, etc.

    In addition to this, Passware Kit Forensic for Mac provides access to APFS disks from Mac computers with an Apple T2 chip.

    This Beta version is available for free to all Passware Kit Forensic customers with an active SMS subscription.

    Passwords extraction from macOS system keychains
    In addition to passwords extraction from macOS keychain, Passware Kit 2020 v2 also instantly extracts passwords from the macOS system keychain.

    This file named system.keychain stores Wi-Fi passwords, certifications, and private keys. The system keychain decryption requires a master key file.

    Instant decryption and password recovery for QuickBooks 2020 databases
    Passware Kit instantly decrypts databases created with QuickBooks 2020. A password recovery option is also available.

    Support for Windows account selection for PIN / password recovery
    The “Standalone System Analysis” option now analyzes both system folders: “Config” and “Users,” and allows to select a single Windows user to recover its password. Passware Kit now also displays users with no password set or with an empty password.

    After a Windows user password or PIN gets recovered, Passware Kit extracts websites, email, and other passwords stored in the registry for this user.

    Recovery of Windows accounts’ passwords from SAM databases in batch mode
    Passware Kit now analyzes SAM databases from different systems in batch mode and recovers passwords for Windows users.

    Improved GPU performance
    We have increased GPU acceleration performance up to 3 times for Zip AES, and 1.5 times for Bitcoin.

    A single Decryptum unit now checks over 27,000,000 passwords for Zip AES archives per second.

    UI improvements for displaying recovered passwords
    For files protected with multiple passwords, Passware Kit now shows the results immediately after the recovery of any password while keeping the recovery process for other passwords running.

    In case of a hard disk password recovery, Passware Kit displays all the passwords recovered immediately, rather than waiting for the MD5 calculation to complete.

    PRICING AND AVAILABILITY
    Passware Kit Forensic is available directly from Passware and a network of resellers worldwide. The price is $1,095 with one year of free updates. Additional product information and screenshots are available at http://www.passware.com/pkf.

    ABOUT PASSWARE, INC.
    Founded in 1998, Passware, Inc. is the worldwide leading maker of password recovery, decryption, and electronic evidence discovery software. Law enforcement and government agencies, institutions, corporations and private investigators, help desk personnel, and thousands of private consumers rely on Passware software products to ensure data availability in the event of lost passwords. Passware customers include many Fortune 100 companies and various US federal and state agencies, such as the IRS, US Army, US Department of Defense (DOD), US Department of Justice, US Department of Homeland Security, US Department of Transportation, US Postal Service, US Secret Service, US Senate, and US Supreme Court. Passware is a privately held corporation with its headquarters in Tallinn, Estonia.

    More information about Passware, Inc. is available at http://www.passware.com/.

Leave a Comment

Latest Videos

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feeds settings page to add an API key after following these instructions.

Latest Articles