DOA Scene Group delivers a useful system tool for performing the complete forensic analysis of encrypted disks and volumes protected with desktop and portable versions of BitLocker, PGP and TrueCrypt.
Elcomsoft Forensic Disk Decryptor allows decrypting data from encrypted containers or mounting encrypted volumes, providing full forensic access to protected information stored in the three most popular types of crypto containers. Access to encrypted information is provided in real-time.
Features and Benefits
Decrypts information stored in three most popular crypto containers
Mounts encrypted BitLocker, PGP and TrueCrypt volumes
Supports removable media encrypted with BitLocker To Go
Supports both encrypted containers and full disk encryption
Acquires protection keys from RAM dumps, hibernation files
Extracts all the keys from a memory dump at once if there is more than one crypto container in the system
Fast acquisition (limited only by disk read speeds)
Zero-footprint operation leaves no traces and requires no modifications to encrypted volume contents
Recovers and stores original encryption keys
Supports all 32-bit and 64-bit versions of Windows
Registration : see key.txt
Note : As usual, block app with fw when registering!