Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / Encrypted files and drives

Encrypted files · BitLocker · FileVault · VeraCrypt · password-protected · Passware · key

Encrypted files and drives. An examination finds the encrypted material; opening it needs a key, a password or a memory capture, and sometimes it cannot be opened at all.

An examination frequently meets encryption: a whole drive protected by BitLocker, FileVault or VeraCrypt, or individual password-protected documents and archives. The first job is to detect and report it, because the presence of encrypted material is itself a finding, and the second, where the client has authority and the means, is to open it lawfully. With the recovery key or password in hand, or a memory image or hibernation file captured while the volume was mounted, the material can be decrypted and examined with forensic tools. Where a document or drive is protected by a weak, human-chosen password, a password attack may recover it. But the honest position, the same one our BitLocker service takes, governs here too: strong encryption without a key or password cannot be broken, there is no backdoor, and a modern encrypted drive with a genuinely lost key and no memory capture cannot be opened by anyone. The report detects the encryption, opens what can lawfully and feasibly be opened, and says plainly what cannot.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

Detecting encryption, and the lawful routes into it.

The examination detects encrypted material, whether a whole volume locked by BitLocker, FileVault or VeraCrypt, or individual password-protected Office documents, PDFs and archives, and reports it, because the presence of encrypted material is a finding in itself, and because it tells the client and their solicitor what is, and is not, accessible.

Opening it lawfully depends on having a route to the key. With the recovery key or password, which the owner or an authorised party may hold, the material is decrypted and examined normally. Where a machine was running and its volume mounted, the key may be recoverable from a memory image or hibernation file. Where a document or drive used a weak, human-chosen password, a password attack with forensic tools may recover it. We use Passware Kit Forensic for this work, strictly in the authorised context, for a client with authority over the material.

The honest limit is the one our dedicated BitLocker service states, and it holds here: strong encryption cannot be broken without the key. There is no backdoor, modern full-disk encryption uses algorithms that cannot be brute-forced in any feasible time, and a drive or file protected by a strong password, with no key and no memory capture, cannot be opened by us or anyone. The report opens what can lawfully and feasibly be opened and is candid about what cannot, rather than promise access that the mathematics does not allow.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
Encrypted files and volumes presentDetection across the exhibitThat material is encrypted; not its contents until opened
Material opened with a key or passwordThe key, password, or memory/hibernation captureThe decrypted content; where a route to the key exists
A weak password recoveredA password attack with forensic toolsWhere the password was weak; a strong one is not recoverable
What cannot be openedThe honest assessmentThat strong encryption without a key is beyond anyone

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Provide the recovery key or password if you have it; it is the difference between a routine decryption and a dead end.
  • Do not shut down a running, encrypted machine before taking advice; the key may be recoverable from memory while it runs.
  • Accept the honest limit; a strong password with no key cannot be broken, and we will say so rather than promise access.

Strong encryption without a key cannot be broken, by us or anyone; an honest examination opens what it lawfully can and says plainly what it cannot.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you get into an encrypted drive or file?

With the recovery key or password, yes, routinely. Where a machine was running with the volume mounted, the key may be recoverable from memory. Where a file used a weak password, a password attack may recover it. But a strong password with no key and no memory capture cannot be broken, by us or anyone, and we will tell you that honestly.

Is there a backdoor into BitLocker or FileVault?

No. Modern full-disk encryption has no backdoor and uses algorithms that cannot be brute-forced in any feasible time. The only routes in are the key or password, a memory or hibernation capture, or, for a weak password, a password attack. Our dedicated BitLocker service explains this in full.

Is it lawful for you to decrypt material?

Only for a client with authority over the material, the owner or an authorised party, and only on that basis. We detect and report encryption as part of an examination; opening it is done in the authorised context, with the client's key or password or lawful means, never covertly.

What if the encrypted drive has also failed?

That is where our sister services combine: the drive is recovered and imaged, and the image decrypted with the key. A failed encrypted drive with the key is recoverable; without the key, the honest limit applies. We would discuss the specifics with you.

What does it cost?

Detecting and, where feasible, opening encrypted material is part of the standard forensic report, £800 + VAT for a one-disk system; substantial password-recovery work is discussed separately. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668