How to Access Encrypted Drive using EFDD (without password)

Channel:
Subscribers:
12,400
Published on ● Video Link: https://www.youtube.com/watch?v=K_mI_I8Qdsc



Category:
Guide
Duration: 13:17
67,672 views
138


On this video I'll show you how to use Elcomsoft Forensic Disk Decryptor to decrypt or mount a fully encrypted drive (TrueCrypt and Bitlocker). This is a detailed video, explaining every step on how to attack a PC that has full drive encryption.

Exact same method works for non-system drives and truecrypt containers.

*Elcomsoft Forensic Disk Decryptor* available here:
https://www.elcomsoft.com/efdd.html

*Belkasoft RAM Capturer* available here:
https://belkasoft.com/en/ram-capturer

*IDE/SATA to USB Adapter*
I did not include a link, because products change. Go to eBay or Amazon and search for "IDE SATA to USB" and you'll find it. They're very cheap, look at the pic and if it's similar, then it will work.


Elcomsoft Forensic Disk Decryptor (EFDD) can get the decryption keys from:
1. Memory Dump (Image of RAM while PC is running)
2. Hibernation File (if file is not encrypted)


Special thanks to Elcomsoft for providing the EFDD software.







Tags:
elcomsoft forensic disk decryptor
elcomsoft
sethioz
forensic
disk
decrypter
decryptor
EFDD
how to
howto
truecrypt
crack
bitlocker
attack
firewire
memory dump
ram
capturer
crack truecrypt
Computer
encrypter
encryption
decrypt
Mount
access
recover