Encrypted NTFS Imag...
 
Notifications
Clear all

Encrypted NTFS Images - Or Not????

12 Posts
9 Users
0 Reactions
7,647 Views
(@thefuf)
Reputable Member
Joined: 17 years ago
Posts: 262
 

When mounting a physical image using FTK Imager and/or Arsenal Image Mounter, do you see the "-FVE-FS-" signature in the first sector of the encrypted partition?

Yes

ëX.-FVE-FS-……….ø..?.ÿ..8……à………………………..)….NO NAME FAT32 3É.Ѽô{.Á.Ù½.| û}´}.ð¬.@tHt.´.»..Í.ëï ý}ëæÍ.Í……………………;ÖgI).ØJ..ö£9ãÐ….þ…… þ……¡þ……………………………………………………
Remove disks or other media.ÿ
Disk errorÿ
Press any key to restart
…………………

That's strange. My first guess was about a misaligned partition (because of a different sector size for example, a 4Kn drive mounted as a 512n drive), but now we know that the header is there, so the encrypted volume is aligned properly. I have no idea what's going on (a possible problem with partition types is mentioned in another post, but I don't think it's the real reason, because another tool was able to mount the image without the issue; also, a wrong partition type is expected to make the system unbootable, but this is not the case).


   
ReplyQuote
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 13 years ago
Posts: 576
Topic starter  

SOLUTION:

While logged into Windows, in a command prompt window, type the below command to have Windows display the BitLocker recovery key:

manage-bde -protectors <DRIVE> -get

   
ReplyQuote
Page 2 / 2
Share: