Frequently Asked Questions

Why does ElcomSoft forensic disk decryptor need the original encryption keys?

Elcomsoft Forensic Disk Decryptor needs the original encryption keys in order to access protected information stored in crypto containers. The encryption keys can be extracted from hibernation files or memory dump files acquired while the encrypted volume was mounted. There are three ways available to acquire the original encryption keys:

What is ElcomSoft encrypted disk Hunter?

Elcomsoft Encrypted Disk Hunter is a free, portable command-line tool to quickly discover the presence of encrypted volumes when performing live system analysis. Multiple Windows, Linux and macOS full-disk encryption tools are supported including TrueCrypt/VeraCrypt, all versions of Microsoft BitLocker, PGP WDE, FileVault2, BestCrypt and LUKS.

What is forensic disk decryptor?

In the real-time mode, Elcomsoft Forensic Disk Decryptor mounts the encrypted volume as a new drive letter on the investigator’s PC. In this mode, forensic specialists enjoy fast, real-time access to protected information. Information read from mounted disks and volumes is decrypted on-the-fly in real time.

How to recover BitLocker passwords in ElcomSoft forensic disk decryptor?

1 Launch Elcomsoft Forensic Disk Decryptor. 2 Select “ Extract/prepare data for further password recovery “. 3 Open the physical device or disk image containing BitLocker volume (s). ... 4 EFDD will display the list of encrypted volumes. ... 5 Click Next to extract the encryption metadata and save it into a file.

