Mcafee Endpoint Enc...
 
Notifications
Clear all

Mcafee Endpoint Encryption Forensics

3 Posts
2 Users
0 Reactions
871 Views
(@billa316)
Active Member
Joined: 10 years ago
Posts: 5
Topic starter  

Hi All,

I was researching on pre-boot authentications and hit upon this issue.

For example after a bit-by-bit copy of a system which has Mcafee Endpoint encryption I tried restoring the system and booting it up using another hardware.

After this I could not login at the pre-boot level because it is showing decryption fails even though i have the credentials.

Any idea what is the issue? Is there some TPM mechanism used for Mcafee Endpoint Encryption solutions? (Can't find any whitepaper on it).

FTK and EnCase have modules to handle such endpoint solutions but guess if need to bootup the system there are issues.

Thanks and Regards


   
Quote
jpickens
(@jpickens)
Estimable Member
Joined: 18 years ago
Posts: 130
 

Wouldn't pre-boot authentication be on the firmware and not the drive that is encrypted?


   
ReplyQuote
(@billa316)
Active Member
Joined: 10 years ago
Posts: 5
Topic starter  

@JasonPickens

Not sure if that is the case. Couldn't find any Mcafee documentation regarding their preboot methods.

But from my testing so far, decryption fails if I use another hardware.

Not sure anyone have faced the same issue before.


   
ReplyQuote
Share: