Can the software decrypt a BitLocker or TrueCrypt drive that was not mounted when the memory image was acquired?
Yes. First of all, the system hibernation file (hiberfil.sys) can be used instead of the memory image. If neither the memory image, nor the hibernation file contain the BitLocker/TrueCrypt encryption keys, Passware Kit assigns common attacks to recover the original password.
Comments
0 comments
Please sign in to leave a comment.