Encrypted files · BitLocker · FileVault · VeraCrypt · password-protected · Passware · key
Encrypted files and drives. An examination finds the encrypted material; opening it needs a key, a password or a memory capture, and sometimes it cannot be opened at all.
An examination frequently meets encryption: a whole drive protected by BitLocker, FileVault or VeraCrypt, or individual password-protected documents and archives. The first job is to detect and report it, because the presence of encrypted material is itself a finding, and the second, where the client has authority and the means, is to open it lawfully. With the recovery key or password in hand, or a memory image or hibernation file captured while the volume was mounted, the material can be decrypted and examined with forensic tools. Where a document or drive is protected by a weak, human-chosen password, a password attack may recover it. But the honest position, the same one our BitLocker service takes, governs here too: strong encryption without a key or password cannot be broken, there is no backdoor, and a modern encrypted drive with a genuinely lost key and no memory capture cannot be opened by anyone. The report detects the encryption, opens what can lawfully and feasibly be opened, and says plainly what cannot.
Rather talk it through? An engineer answers the bench line
0800 6890668
Detecting encryption, and the lawful routes into it.
The examination detects encrypted material, whether a whole volume locked by BitLocker, FileVault or VeraCrypt, or individual password-protected Office documents, PDFs and archives, and reports it, because the presence of encrypted material is a finding in itself, and because it tells the client and their solicitor what is, and is not, accessible.
Opening it lawfully depends on having a route to the key. With the recovery key or password, which the owner or an authorised party may hold, the material is decrypted and examined normally. Where a machine was running and its volume mounted, the key may be recoverable from a memory image or hibernation file. Where a document or drive used a weak, human-chosen password, a password attack with forensic tools may recover it. We use Passware Kit Forensic for this work, strictly in the authorised context, for a client with authority over the material.
The honest limit is the one our dedicated BitLocker service states, and it holds here: strong encryption cannot be broken without the key. There is no backdoor, modern full-disk encryption uses algorithms that cannot be brute-forced in any feasible time, and a drive or file protected by a strong password, with no key and no memory capture, cannot be opened by us or anyone. The report opens what can lawfully and feasibly be opened and is candid about what cannot, rather than promise access that the mathematics does not allow.
What it records, and what it means.
Describe your situation →| What is recorded | Where it comes from | What it shows, and does not |
|---|---|---|
| Encrypted files and volumes present | Detection across the exhibit | That material is encrypted; not its contents until opened |
| Material opened with a key or password | The key, password, or memory/hibernation capture | The decrypted content; where a route to the key exists |
| A weak password recovered | A password attack with forensic tools | Where the password was weak; a strong one is not recoverable |
| What cannot be opened | The honest assessment | That strong encryption without a key is beyond anyone |
From the exhibit arriving to the report.
Work we have closed →The first conversation, and the authority check Free
Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.
Imaging behind a write blocker, and the hashes
When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.
The examination, on the image
The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.
The report
The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.
From the bench
- Provide the recovery key or password if you have it; it is the difference between a routine decryption and a dead end.
- Do not shut down a running, encrypted machine before taking advice; the key may be recoverable from memory while it runs.
- Accept the honest limit; a strong password with no key cannot be broken, and we will say so rather than promise access.
Strong encryption without a key cannot be broken, by us or anyone; an honest examination opens what it lawfully can and says plainly what it cannot.
What helps, and what harms.
Do this much first
- Stop using the device and keep it powered off
- Preserve it as it is; record who has held it
- Gather your proof of ownership or authority
- Tell us the questions you need answered
What sets us back
- Letting IT or anyone open it to have a look
- Reinstalling, wiping or running recovery software
- Carrying on using the device
- Assuming artefacts prove who was at the keyboard
Questions answered before you instruct.
Can you get into an encrypted drive or file?
With the recovery key or password, yes, routinely. Where a machine was running with the volume mounted, the key may be recoverable from memory. Where a file used a weak password, a password attack may recover it. But a strong password with no key and no memory capture cannot be broken, by us or anyone, and we will tell you that honestly.
Is there a backdoor into BitLocker or FileVault?
No. Modern full-disk encryption has no backdoor and uses algorithms that cannot be brute-forced in any feasible time. The only routes in are the key or password, a memory or hibernation capture, or, for a weak password, a password attack. Our dedicated BitLocker service explains this in full.
Is it lawful for you to decrypt material?
Only for a client with authority over the material, the owner or an authorised party, and only on that basis. We detect and report encryption as part of an examination; opening it is done in the authorised context, with the client's key or password or lawful means, never covertly.
What if the encrypted drive has also failed?
That is where our sister services combine: the drive is recovered and imaged, and the image decrypted with the key. A failed encrypted drive with the key is recoverable; without the key, the honest limit applies. We would discuss the specifics with you.
What does it cost?
Detecting and, where feasible, opening encrypted material is part of the standard forensic report, £800 + VAT for a one-disk system; substantial password-recovery work is discussed separately. The first conversation is free.
The record is on the device; preserve it first.
The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.