Removing the encryp...
 
Notifications
Clear all

Removing the encryption to create an image

11 Posts
8 Users
0 Reactions
3,168 Views
neddy
(@neddy)
Estimable Member
Joined: 21 years ago
Posts: 182
 

If you can acquire the original HDD using a writeblocker and use this to create a clone, you can then use the clone in the original exhibit to disable the encryption or acquire an on the fly decrypted image. This at least preserves the original HDD and is best evidence. In most cases however it seems that clones are not compatible with the systems and this is as a result of security measures.
Decrypting the original HDD on the fly (if provided with passwords) and acquiring a forensic image to a connected harvest disk using something like FTK Imager Lite, is probably the best image you can get and under the circumstances this is not probihited by the UK ACPO guidelines, you will change things but this is unavoidable and a competent examiner should be able to justify this and show what files have been accessed or altered during the process.


   
ReplyQuote
Page 2 / 2
Share: