FTK Imager and Win7...
 
Notifications
Clear all

FTK Imager and Win7 BitLocker

16 Posts
8 Users
0 Reactions
8,626 Views
bshavers
(@bshavers)
Estimable Member
Joined: 20 years ago
Posts: 211
 

FYI

Manage-bde -unlock E -recoverypassword 11111-222222-…….777777-888888 works just fine from WinFE Lite thumb drive

Where E is the drive to be imaged and 11111-222222-…….777777-888888 is the recovery key (48-character)

Cheers

WinFE is very cool D

and free…


   
ReplyQuote
(@cults14)
Reputable Member
Joined: 17 years ago
Posts: 367
Topic starter  

You can take the physical drive image (dd) of a BitLockered drive and mount it as a VHD using a bit of ingenuity. Once mounted, it will show up as a BitLockered drive, and prompt for the key. Thereafter you can access it as a regular drive, decrypt it, image it logically, search it, etc.

When I have to image in situ, I take the physical of a BitLockered drive every time instead of mucking with boot up, login, etc.

Search for 'dd image to VHD'.

Every BitLockered boot drive has a minimum 2 partitions. One unencrypted boot, and one encrypted. Most 'full disk' encryption in my experience work this way.

Jhup, I just had my first Image delivered to me by a vendor who did some work abroad for us, including images of a couple of Bitlockered systems with no ID and no Recovery Password

Your method worked a treat, so thank you very much (for the record, I used the convertfromraw option with VBoxManage.exe which is bundled with VirtualBox)

Many thanks!! )


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

You are welcome.

Now go forth and spread your knowledge to other forensicators. mrgreen


   
ReplyQuote
(@mansiu)
Trusted Member
Joined: 16 years ago
Posts: 83
 

FYI

Manage-bde -unlock E -recoverypassword 11111-222222-…….777777-888888 works just fine from WinFE Lite thumb drive

Where E is the drive to be imaged and 11111-222222-…….777777-888888 is the recovery key (48-character)

Cheers

WinFE is very cool D

and free…

any windows license issue building WinFE?


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

any windows license issue building WinFE?

No.

As long as you hold a valid corresponding license for a Windows OS, you do not redistribute the built WinPE/WinFE and you do not use it as a replacement for a "full" OS, you are good to go.
The WinFE is nothing but a specially built WinPE, and though it can be built from Windows install files (i.e. the WAIK/ADK is not really-really needed) usually, by extension, the WAIK/ADK license is used as reference.

jaclaz


   
ReplyQuote
bshavers
(@bshavers)
Estimable Member
Joined: 20 years ago
Posts: 211
 

If you have a Windows license, you can build a WinFE/PE.

Free online course on how-to build a WinFE at http//courses.dfironlinetraining.com/windows-forensic-environment


   
ReplyQuote
Page 2 / 2
Share: