You've already used Elcomsoft iOS Forensic Toolkit for filesystem acquisition; now it's time to put your hands on physical acquisition with the help of this forensic tool.
Here are the steps:
- Connect the device to your workstation and start Toolkit-JB.command (Mac) or Toolkit-JB.cmd (Windows).
- Starting from the GET KEYS option, type 4. It will help you to get the device keys you need to decrypt the physical image.
Extracting the device keys
- We are ready to start imaging. Choose the IMAGE DISK option, and type 6. You will see two partitions, System (unencrypted) and