In addition, Elcomsoft Forensic Disk Decryptor can be used to create a portable installation on a user-provided USB flash drive. EO1 format, as well as encrypted DMG images.
Windows 7 and up to the latest Windows 10 update.Įlcomsoft Forensic Disk Decryptor 2.0 now fully supports EnCase images in the industry-standard. The driver is digitally signed with a Microsoft signature, making it fully compatible with all 32-bit and 64-bit versions of Windows from The supplied RAM imaging tool operates through a custom kernel-level driver. The tool uses zero-level access to computer's volatile memory in order to create the most complete memory image.
The tool extracts cryptographic keys from RAM captures, hibernation and page files or uses plain-text password or escrow keys to decrypt files and folders stored in crypto containers or mount encrypted volumes as new drive letters for instant, real-time access.Ī forensic-grade memory imaging tool is included with Elcomsoft Forensic Disk Decryptor. Instantly access data stored in encrypted BitLocker, FileVault 2, PGP, TrueCrypt and VeraCrypt containers.