How to Access Encrypted Drive using EFDD (without password)

Sethioz
Sethioz
68.1 هزار بار بازدید - 9 سال پیش - On this video I'll show
On this video I'll show you how to use Elcomsoft Forensic Disk Decryptor to decrypt or mount a fully encrypted drive (TrueCrypt and Bitlocker). This is a detailed video, explaining every step on how to attack a PC that has full drive encryption.

Exact same method works for non-system drives and truecrypt containers.

Elcomsoft Forensic Disk Decryptor available here:
https://www.elcomsoft.com/efdd.html

Belkasoft RAM Capturer available here:
https://belkasoft.com/en/ram-capturer

IDE/SATA to USB Adapter
I did not include a link, because products change. Go to eBay or Amazon and search for "IDE SATA to USB" and you'll find it. They're very cheap, look at the pic and if it's similar, then it will work.


Elcomsoft Forensic Disk Decryptor (EFDD) can get the decryption keys from:
1. Memory Dump (Image of RAM while PC is running)
2. Hibernation File (if file is not encrypted)


Special thanks to Elcomsoft for providing the EFDD software.
9 سال پیش در تاریخ 1394/03/14 منتشر شده است.
68,178 بـار بازدید شده
... بیشتر