Encrypted drives · BitLocker · FileVault · VeraCrypt · recovery key · Passware
Encrypted drive forensics. An encrypted drive is examined the same way as any other, once it is open; opening it needs a key, and sometimes there is none.
A drive protected by BitLocker, FileVault or VeraCrypt is examined exactly like any other drive once it is open, but opening it is the whole question, and the honest position, the same one our dedicated BitLocker service takes, governs here. We image the encrypted drive behind a write blocker, and with the recovery key or password, or a memory image or hibernation file captured while the volume was mounted, we decrypt the image and examine it normally. A weak password may be recoverable by a password attack. But a modern encrypted drive with a strong password and no key and no memory capture cannot be opened, by us or anyone, because there is no backdoor and the encryption cannot be brute-forced. We examine what can lawfully and feasibly be opened, for a client with authority, and say plainly what cannot.
Rather talk it through? An engineer answers the bench line
0800 6890668
The routes into an encrypted drive, and the limit.
We image the encrypted drive behind a write blocker, exactly as any drive, capturing the encrypted volume. From there, opening it depends on a route to the key. With the owner's recovery key or password, the image is decrypted and examined normally. Where the machine was running with the volume mounted, the key may be recoverable from a memory image or hibernation file. Where a drive or file used a weak, human-chosen password, a password attack with Passware may recover it. All of this is done in the authorised context, for a client with authority over the drive.
The limit is the one our BitLocker service states in full: strong encryption cannot be broken without the key. There is no backdoor, modern full-disk encryption cannot be brute-forced in any feasible time, and a drive with a strong password, no escrowed key and no memory capture cannot be opened by anyone. We will say so honestly rather than promise access that the mathematics does not allow.
Where an encrypted drive has also failed physically, the recovery and the decryption combine: the drive is recovered and imaged, and the image decrypted with the key. For the depth of the encryption question, our dedicated BitLocker recovery service covers it fully.
What to know for this exhibit.
From the exhibit arriving to the report.
Work we have closed →The first conversation, and the authority check Free
Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.
Imaging behind a write blocker, and the hashes
When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.
The examination, on the image
The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.
The report
The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.
Before you send it
- Provide the recovery key or password if you have it; it is the difference between a routine examination and a dead end.
- Do not shut down a running, encrypted machine before taking advice; the key may be recoverable from memory while it runs.
- Accept the honest limit; a strong password with no key cannot be broken, and we will say so rather than promise access.
Strong encryption without a key cannot be broken, by us or anyone; we open what we lawfully and feasibly can and say plainly what we cannot.
What helps, and what harms.
Do this much first
- Stop using the device and keep it powered off
- Preserve it as it is; record who has held it
- Gather your proof of ownership or authority
- Tell us the situation and the questions you have
What sets us back
- Letting anyone open it to have a look
- Reinstalling, wiping or running recovery software
- Carrying on using the device
- Sending us a mobile phone; they are not examined
Questions answered before you instruct.
Can you examine a BitLocker or FileVault drive?
With the recovery key or password, yes, routinely: we decrypt the image and examine it like any drive. Where the machine was running, the key may be recoverable from memory. Where a weak password was used, a password attack may recover it. But a strong password with no key and no memory capture cannot be broken, by us or anyone, and we will tell you that honestly.
Is there a way in without the key?
Only a memory or hibernation capture taken while the volume was mounted, or, for a weak password, a password attack. There is no backdoor into modern full-disk encryption, and it cannot be brute-forced in any feasible time. Our dedicated BitLocker recovery service explains the position in full.
What if the encrypted drive has failed?
Then the recovery and the decryption combine: the drive is recovered and imaged, and the image decrypted with the key. A failed encrypted drive with the key is recoverable; without the key, the honest limit applies. We would discuss the specifics with you.
Is it lawful for you to decrypt a drive?
Only for a client with authority over the drive, the owner or an authorised party, on that basis, and never covertly. We detect and image the encryption as part of an examination; opening it is done in the authorised context with the client's key, password or lawful means.
What does it cost?
The standard forensic report is £800 + VAT for a one-disk system; substantial password-recovery work is discussed separately, and our BitLocker service covers encrypted-drive recovery in depth. The first conversation is free.
Preserve it, and let us image it first.
The first conversation is free. Tell us the exhibit and the situation, and who owns it, and we will tell you what can be examined, what authority we need, and whether we can take it on. Until then, stop using it and preserve it as it is.