Elcomsoft Forensic Disk Decryptor

elcomsoft forensic disk decryptor is able to decrypt any windows operating system installed on a disk. elcomsoft forensic disk decryptor uses a special approach to decrypt the original files on a disk without any additional software.

elcomsoft forensic disk decryptor is a powerful application designed to instantly decrypt disks and volumes using the decryption key extracted from the computers volatile memory (ram). in addition, you can decrypt for offline analysis or instantly mount bitlocker volumes by utilizing the escrow key (bitlocker recovery key) extracted from the users microsoft account or retrieved from active directory. elcomsoft forensic disk decryptor works with physical disks as well as raw (dd) images.

if you are able to sign in to the computer, you may attempt capturing its memory image. by analyzing the ram image with elcomsoft forensic disk decryptor you may be able to discover the master key and decrypt the volume without any other attacks. this, however, will not be possible if the user specified a pre-boot protector such as an extra pin code (tpm+pin). if you attempt to brute-force the pin, the tpm will panic and lock access to the encryption key either permanently or for a period of time.

elcomsoft forensic disk decryptor offers forensic specialists an easy way to obtain complete real-time access to information stored in popular crypto containers. supporting desktop and portable versions of bitlocker, filevault 2, pgp disk, truecrypt and veracrypt protection, the tool can decrypt all files and folders stored in crypto containers or mount encrypted volumes as new drive letters for instant, real-time access.

You can install the Portable version of Forensic Disk Decryptor directly on a USB stick. If you are planning to work on multiple encrypted volumes, installing the Portable version on a flash drive will save a lot of disk space.
After downloading the installation program, make sure the drive has enough disk space. The Elcomsoft Forensic Disk Decryptor Portable software will be downloaded to it. Double-click on the setup.exe file to start the installation process.
The installation process will automatically check for already installed versions of Elcomsoft Forensic Disk Decryptor. If an older version is already installed, the Portable version will be replaced.
The Elcomsoft System Recovery utility is an easy-to-use boot-from-USB utility that allows booting a drive encrypted with BitLocker, PGP Disk, VeraCrypt, TrueCrypt and the recovery partitions of LUKS volumes.
Once the initial phase of the Elcomsoft System Recovery utility is completed, it will automatically launch the Elcomsoft Forensic Disk Decryptor Portable software. Click on the Elcomsoft Forensic Disk Decryptor wizard icon to install the Portable version of the tool on a USB drive.
Elcomsoft Forensic Disk Decryptor facilitates the processing of encrypted volumes in many cases. It works with a variety of disks: BitLocker – the full-disk encryption protocol used by Microsoft, with a large number of Windows versions supported: ME, NT, 2000, XP, Vista, 7, 8, 8.1, and 10; LUKS – the Linux-based full-disk encryption protocol used by Linux, including the Linux-based operating systems: Ubuntu, Fedora, Debian, openSUSE, CentOS, and SUSE Linux Enterprise Server; VeraCrypt – the full-disk encryption protocol used by Windows, Linux and MacOS; FileVault2 – the full-disk encryption protocol used by MacOS; PGP Disk – the full-disk encryption protocol used by Linux; Jetico BestCrypt – the full-disk encryption protocol used by OS X; TrueCrypt – the full-disk encryption protocol used by Linux and many other platforms.