Hi,
I have a partially acquired image using Encase Enterprise that is Safeboot/McAfee encrypted. Is EnCase able to decrypt it? My guess is no. Just wamt to confirm this.
Also, Encase has a acquisitiom restart function. Anyone use it before? Does that actually work? If yes, is it only available on ECC?
Thanks.
From the EnCase 6.15 manual -
EnCase provides a way for you to view SafeBoot encrypted hard drives during an investigation. This feature is only available to a user with an EDS cert enabled
From the EnCase 6.15 manual -
EnCase provides a way for you to view SafeBoot encrypted hard drives during an investigation. This feature is only available to a user with an EDS cert enabled
Common Sense Manual 3.58 (yes I have an old version) tells me
even if you have an EDS cert enabled Encase 6.15 (Deluxe Version 😯 ) you won't be able to decrypt a partial Safeboot image, at least to the same extent as you cannot decrypt a partial Safeboot image in Safeboot already knowing it's password, and of course "partial" says nothing, some parts of a Safeboot volume are anyway "vital" and if they are missing you have little (please read as "NO") chances with *any* tool.
Also, actual Version of Safeboot (or Endpoint Encryption) may make a difference, in case of need
http//
jaclaz


