Notifications
Clear all
Topic starter
06/03/2019 2:42 pm
Hello All,
I have had a couple of cases recently where the client has provided a laptop and I have been able to acquire a full forensic image but unable to process with standard tools (Axiom / Encase etc) due to not recognising the drive due to the encryption. I have been told it is due to the TMP chip in the laptop and the level of encryption. I have been able to mount the drive and enter the encryptions keys etc but unable to find a tool to recover artefacts such as LNK files.
I have been racking my brain but wondered if anyone else had come across similar?
Any advice would be much appreciated.
Thanks