Notifications
Clear all
11/09/2013 5:07 pm
The new version (12.5) of Passware Kit Forensic and its smaller brother Evidence Analyzer (4.5 I believe) claim to do so - they are said to detect both encrypted disks/partitions and containers.
I haven't had a chance to try with containers but they definitely work for disks and partitions.
11/09/2013 9:44 pm
There are a lot of presumptions in this method, but an other way to approach this is eliminate all known and signature matched files at cluster level.
What remains most likely will contain your encrypted area.
Page 2 / 2
Prev