±Forensic Focus Partners

±Your Account


Nickname
Password


Forgotten password/username?


Membership:
New Today: 0
New Yesterday: 7
Overall: 27350
Visitors: 51

±Follow Forensic Focus

Join our LinkedIn group

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Decrypting EFS Help!

Forensic software discussion (commercial and open source/freeware). Strictly no advertising.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
Go to page 1, 2  Next 
  

Decrypting EFS Help!

Post Posted: Mon Dec 03, 2012 4:47 am

Hi!

I just want to ask how to decrypt these EFS Files which I believe can really help the case I'm investigating right now. I'm using Encase v6 and I stumble upon an EFS-encrypted file and its EFS Stream. I want to ask for the next steps to properly decrypt the file.

Here's a snapshot:



Thanks in advance.

P.S. I tried to do the copy/unerase function of Encase to decrypt using other tools but apparently, the file attribute 'E' is removed during extraction. Cipher can't decrypt the file since I think its corrupted or broken during extraction.

Please advise next step. Smile  

pyre08
Newbie
 
 
  

Re: Decrypting EFS Help!

Post Posted: Mon Dec 03, 2012 7:48 am

I believe you need to crack the user's password first - is it LANMAN or NTLM?

You can decrypt EFS using EnCase 6 if you know the user's password. You can use EnCase to brute force the password if it is simple enough.  

chrism
Senior Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Tue Dec 04, 2012 10:21 pm

How can I brute-force the password? I've switched to Encase 7 since its has a function 'Analyze EFS'. I haven't figured it out yet whether its LANMAN or NTLM.

See pic below for details.



Thanks in Advance!  

pyre08
Newbie
 
 
  

Re: Decrypting EFS Help!

Post Posted: Wed Dec 05, 2012 2:06 pm

You can use Ophcrack, Passware to try and crack the passwords based on the SAM files.

Ophcrack uses rainbow tables and does a great job.

Based on the screenshots, this seems to be an XP machine so it should use LM by default.  

PM_SQ
Senior Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Sat Jun 29, 2013 9:50 am

how does one decrypt EFS files in encase 7? Could you please explain if you were successful? I don't see how this can be done using only encase 7.  

digitalcoroner
Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Mon Jul 01, 2013 7:35 am

?


- digitalcoroner
how does one decrypt EFS files in encase 7? Could you please explain if you were successful? I don't see how this can be done using only encase 7.
 

jhup
Senior Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Mon Jul 01, 2013 8:02 am

Where can I download the EDS script from? Thanks.  

digitalcoroner
Member
 
 
Reply to topicReply to topic

Share this forum topic to encourage more replies



Page 1 of 2
Go to page 1, 2  Next