The toolkit allows using the volume's plain-text password, escrow or recovery keys, as well as the binary keys extracted from the computer's memory image or hibernation file. The portable installation can be used to image computer's volatile memory and/or decrypt encrypted volumes.Ī Fully Integrated Solution for Accessing Encrypted VolumesĮlcomsoft Forensic Disk Decryptor offers all available methods for gaining access to information stored in encrypted BitLocker, FileVault 2, PGP, TrueCrypt and VeraCrypt disks and volumes. In addition, Elcomsoft Forensic Disk Decryptor can be used to create a portable installation on a user-provided USB flash drive. EO1 format, as well as encrypted DMG images. Windows 7 and up to the latest Windows 10 update.Įlcomsoft Forensic Disk Decryptor 2.0 now fully supports EnCase images in the industry-standard. The driver is digitally signed with a Microsoft signature, making it fully compatible with all 32-bit and 64-bit versions of Windows from The supplied RAM imaging tool operates through a custom kernel-level driver. The tool uses zero-level access to computer's volatile memory in order to create the most complete memory image. New featuresĪ forensic-grade memory imaging tool is included with Elcomsoft Forensic Disk Decryptor. The tool extracts cryptographic keys from RAM captures, hibernation and page files or uses plain-text password or escrow keys to decrypt files and folders stored in crypto containers or mount encrypted volumes as new drive letters for instant, real-time access. Instantly access data stored in encrypted BitLocker, FileVault 2, PGP, TrueCrypt and VeraCrypt containers.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |