Hello Reader,
            Kevin Stokes is the mobile forensics champion in our offices at G-C Partners. When we get a copy of the new Elcomsoft IOS toolkit it was Kevin who went to work to test it out and understand what it was capable of. Kevin was nice enough to write up a quick guide to walk you through the process of doing this yourself!

Elcomsoft 5.0 & rootlessJB by Kevin Stokes (02.25.2019)
This process was done on a device running iOS 12.1.
It is part of Elcomsoft’s tested jailbreaks listed in their documentation for iOS Toolkit 5.0.
*NOTE:  As always, for a forensic acquisition, document your steps and interactions.
  1. Using the Safari mobile browser…
      • (May work in other browsers? But Safari should exist on phone.)
  2. Go to https://ignition.fun, get the app.
      • Select the packages icon (circled in Blue).
      • This will bring up the App categories available.
      • Select Jailbreaks (also circled in Blue).
      • Select the “rootlessJB” from Jake James (again, in blue).
      • “GET” the app (In Red!), to continue
      • Select “Install”, to download and install on the phone.
      • You will now have the “rootlessJB” app installed
      • But wait!  No need to select it yet.
      • We need to work on our trust issues…
  1. Trust Issues
    • Go to Settings > General > Device Management
    • Select the Khodal Enterprise app
    • Select Trust Khodal Enterprise
    • Select “Trust” once more.
    • Once Trusted, the screen will look like the following (Allowing you to Delete the App, but don’t)
  1. Jailbreak it!
    • Open the rootless JB app, make sure to turn off “iSuperUS” and “Tweaks” (slide left)
    • No need to add these for an acquisition.
    • Select “Jailbreak” (the button with be greyed out for a moment).
    • A message will appear at the bottom when it is successful.  (In testing, this took less than a minute each time)
  1. iOS Toolkit Time!
    • Select “F” to perform a File System acquisition.
    • Give the tar file a name, default is “user.tar”
    • Provide the SSH password …  (Hint! It’s “alpine”)
    • Get another cup of coffee, while it downloads. Coffee