Find data from True...
 
Notifications
Clear all

Find data from Truecrypt with Volatility

3 Posts
2 Users
0 Reactions
3,519 Views
(@banderas20)
Eminent Member
Joined: 6 years ago
Posts: 29
Topic starter  

Hello!

The thing is, I have a memory dump in which appears the process "Truecrypt.exe" and a mounted volume, and I want to find the key.

I issue

volatility truecryptmaster
volatility truecryptsummary
volatility truecryptpassphrase

The 2 firsts give me results, but the last one yields no results. I expect to find the key that must be stored somewhere in memory.

¿How can I achieve that?

Thanks!


   
Quote
(@Anonymous 6593)
Guest
Joined: 17 years ago
Posts: 1158
 

The 2 firsts give me results, but the last one yields no results. I expect to find the key that must be stored somewhere in memory.

¿How can I achieve that?

Passphrase caching is, as far as I know, disabled by default. You have to enable it first.


   
ReplyQuote
(@banderas20)
Eminent Member
Joined: 6 years ago
Posts: 29
Topic starter  

The 2 firsts give me results, but the last one yields no results. I expect to find the key that must be stored somewhere in memory.

¿How can I achieve that?

Passphrase caching is, as far as I know, disabled by default. You have to enable it first.

Ok. So there's nothing I can do now, then? Can I look for another cached files related with that crypted drive?

Thanks!


   
ReplyQuote
Share: