Decrypt or mount disk

Top  Previous  Next

The tool supports physical disk drives, disk images and encrypted containers.

 

Supported disk images:

RAW/DD

EnCase .E01

VHD/VHDX (Windows 8.1 or higher is required to work with these images)

 

Select the type of data first:

 

efdd9

 

The enumerates attached storage devices and list partitions, automatically detecting encryption type:

 

efdd10

 

You can either decrypt or mount the partition for immediate access. The latter is implemented via ImDisk virtual disk driver installed with EFDD.

 

One of the following is required:

 

Memory dump (see Extract keys)

Saved keys (see Extract keys)

Password

Hibernation file

Active Directory file (BitLocker only)

Recovery key (for BitLocker, PGP WDE, FileVault2)

 

Note that this feature is not yet available for APFS partitions encrypted with FileVault2.


 Get more information about Elcomsoft Forensic Disk Decryptor
 Get full version of Elcomsoft Forensic Disk Decryptor