I'm having a devil of a time processing SafeBoot encrypted images in v7 (specifically 7.09.05.04). I'm using the built-in decyrption agent in EnCase. I assume the issue is related to the decryption-on-the-fly. Does anyone know of a good way to re-acquire the disk unencrypted? From what I've tried, re-acquisition just gives me another encrypted image and creating a LEF only gives me about 800MB of a 300GB image (besides omiting helpful info such as drive serial, etc). Has anyone found a useful work-around for this sort of issue?
Doug ? , yes.
You have two options.
Option 1 - logical
Mount image as a VHD in a machine with SafeBoot on it.
When accessing the drive it will ask for the key.
Provide it.
Image logical.
Option 2 - Physical
Mount image as a VHD in a machine with SafeBoot on it.
When accessing the drive it will ask for the key.
Decrypt.
Image decrypted VHD as physical.
This works, conceptually with most other FVE.