Decrypt or mount disk

Top  Previous  Next

You can work with actual dist attached to the computer (e.g. via USB interface), with disk images (in RAW/DD or EnCase .E01 formats), or with the disk containers (speaking of PGP and TrueCrypt/VeraCrypt). Select the type of the date first:

 

1decrypt

 

Until the disk container is selected, the program parses it, and shows the list of partitions (if there is more than one), detecting the encryption:

 

1decrypt_select

 

Decryption or mounting (the latter is implemented using ImDisk virtual disk driver installed with EFDD; typically, you don't need to change any settings.

 

One of the following is required:

 

memory dump (see Extract keys)

saved keys (see Extract keys)

password

hibernation file

active directory file (BitLocker only)

recovery key (for BitLocker, PGP WDE, FileVault2)

 


 Get more information about Elcomsoft Forensic Disk Decryptor
 Get full version of Elcomsoft Forensic Disk Decryptor

 © 2016 ElcomSoft Co.Ltd.