Decrypting EFS Help...
 
Notifications
Clear all

Decrypting EFS Help!

9 Posts
6 Users
0 Reactions
1,754 Views
(@pyre08)
New Member
Joined: 13 years ago
Posts: 2
Topic starter  

Hi!

I just want to ask how to decrypt these EFS Files which I believe can really help the case I'm investigating right now. I'm using Encase v6 and I stumble upon an EFS-encrypted file and its EFS Stream. I want to ask for the next steps to properly decrypt the file.

Here's a snapshot

Thanks in advance.

P.S. I tried to do the copy/unerase function of Encase to decrypt using other tools but apparently, the file attribute 'E' is removed during extraction. Cipher can't decrypt the file since I think its corrupted or broken during extraction.

Please advise next step. )


   
Quote
(@chrism)
Trusted Member
Joined: 16 years ago
Posts: 97
 

I believe you need to crack the user's password first - is it LANMAN or NTLM?

You can decrypt EFS using EnCase 6 if you know the user's password. You can use EnCase to brute force the password if it is simple enough.


   
ReplyQuote
(@pyre08)
New Member
Joined: 13 years ago
Posts: 2
Topic starter  

How can I brute-force the password? I've switched to Encase 7 since its has a function 'Analyze EFS'. I haven't figured it out yet whether its LANMAN or NTLM.

See pic below for details.

Thanks in Advance!


   
ReplyQuote
(@thepm)
Reputable Member
Joined: 17 years ago
Posts: 254
 

You can use Ophcrack, Passware to try and crack the passwords based on the SAM files.

Ophcrack uses rainbow tables and does a great job.

Based on the screenshots, this seems to be an XP machine so it should use LM by default.


   
ReplyQuote
(@digitalcoroner)
Eminent Member
Joined: 13 years ago
Posts: 46
 

how does one decrypt EFS files in encase 7? Could you please explain if you were successful? I don't see how this can be done using only encase 7.


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

?

how does one decrypt EFS files in encase 7? Could you please explain if you were successful? I don't see how this can be done using only encase 7.


   
ReplyQuote
(@digitalcoroner)
Eminent Member
Joined: 13 years ago
Posts: 46
 

Where can I download the EDS script from? Thanks.


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Where can I download the EDS script from? Thanks.

Did you install the sample scripts? If so that is where it is.


   
ReplyQuote
(@digitalcoroner)
Eminent Member
Joined: 13 years ago
Posts: 46
 

Are these scripts that come with the Encase software? If yes, I'm not seeing it.


   
ReplyQuote
Share: