±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 0 Overall: 28985
New Yesterday: 4 Visitors: 88

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

Subscribe to news

Subscribe to forums

Decrypting EFS Help!

Forensic software discussion (commercial and open source/freeware). Strictly no advertising.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
Go to page 1, 2  Next 
  

Decrypting EFS Help!

Post Posted: Mon Dec 03, 2012 4:47 am

Hi!

I just want to ask how to decrypt these EFS Files which I believe can really help the case I'm investigating right now. I'm using Encase v6 and I stumble upon an EFS-encrypted file and its EFS Stream. I want to ask for the next steps to properly decrypt the file.

Here's a snapshot:



Thanks in advance.

P.S. I tried to do the copy/unerase function of Encase to decrypt using other tools but apparently, the file attribute 'E' is removed during extraction. Cipher can't decrypt the file since I think its corrupted or broken during extraction.

Please advise next step. Smile  

pyre08
Newbie
 
 
  

Re: Decrypting EFS Help!

Post Posted: Mon Dec 03, 2012 7:48 am

I believe you need to crack the user's password first - is it LANMAN or NTLM?

You can decrypt EFS using EnCase 6 if you know the user's password. You can use EnCase to brute force the password if it is simple enough.  

chrism
Senior Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Tue Dec 04, 2012 10:21 pm

How can I brute-force the password? I've switched to Encase 7 since its has a function 'Analyze EFS'. I haven't figured it out yet whether its LANMAN or NTLM.

See pic below for details.



Thanks in Advance!  

pyre08
Newbie
 
 
  

Re: Decrypting EFS Help!

Post Posted: Wed Dec 05, 2012 2:06 pm

You can use Ophcrack, Passware to try and crack the passwords based on the SAM files.

Ophcrack uses rainbow tables and does a great job.

Based on the screenshots, this seems to be an XP machine so it should use LM by default.  

PM_SQ
Senior Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Sat Jun 29, 2013 9:50 am

how does one decrypt EFS files in encase 7? Could you please explain if you were successful? I don't see how this can be done using only encase 7.  

digitalcoroner
Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Mon Jul 01, 2013 7:35 am

?


- digitalcoroner
how does one decrypt EFS files in encase 7? Could you please explain if you were successful? I don't see how this can be done using only encase 7.
 

jhup
Senior Member
 
 
  

Re: Decrypting EFS Help!

Post Posted: Mon Jul 01, 2013 8:02 am

Where can I download the EDS script from? Thanks.  

digitalcoroner
Member
 
 
Reply to topicReply to topic

Share this forum topic to encourage more replies




Page 1 of 2
Go to page 1, 2  Next