The New Passware Kit 2021 v1: Bootable Memory Imager And Instant APFS Decryption

Memory analysis is an essential method of electronic evidence discovery. It allows computer forensics to decrypt hard disks and files and extract encryption keys and passwords.

We are proud to introduce Passware Bootable Memory Imager – a new UEFI compatible tool that acquires memory images of Windows, Linux, and Mac computers.

Fine-tuning password recovery attacks is a complicated process. The new version features an improved attack editor that shows examples of generated passwords and makes it easy to experiment with attack settings.

We have also improved the performance of PDF password recovery, which is now 7 times faster on Decryptum. The new version supports instant decryption of FileVault/APFS volumes using a keychain file, introduces support for Tally.ERP 9, and more.

What’s new in Passware Kit 2021 v1

  • Passware Bootable Memory Imager
  • Preview of generated passwords
  • Instant FileVault/APFS decryption with a keychain
  • Password recovery for Tally.ERP 9
  • GPU-accelerated recovery of PDF owner password
  • PDF password recovery improvements
  • Password recovery for MS SQL
  • Import of dictionaries preserving the order of passwords

Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.

Unsubscribe any time. We respect your privacy - read our privacy policy.

Passware Bootable Memory Imager

Passware introduces a new tool that runs from a bootable USB drive and acquires memory images of Windows, Linux, and Mac computers.

Passware Memory Imager works with Windows computers that have Secure Boot enabled.

The tool is available in Passware Kit Forensic and Business editions.

Preview of generated passwords

When you configure password recovery attacks in the “Customize Settings” option, Passware Kit displays examples of generated passwords that match the selected attack settings.

Instant FileVault/APFS decryption with a keychain

Passware Kit 2021 v1 instantly decrypts FileVault/APFS volumes and unlocks APFS on Macs with the Apple T2 Chip if a Keychain file from the corresponding iOS device image is available after decryption by third-party tools.

Password recovery for Tally.ERP 9

The new Passware Kit recovers passwords for company files created with Tally.ERP 9 software – Company.900. The recovery speed is up to 10 million passwords per second.

GPU-accelerated recovery of PDF owner password

In addition to PDF file open passwords, Passware Kit now recovers owner passwords and accelerates the recovery on both NVIDIA and AMD GPUs.

PDF password recovery improvements

GPU acceleration of password recovery for PDF files is even greater now!

Decryptum DPR 2080TI-T/12 4U is over 700% faster, processing over 450 million passwords per second on PDF with encryption revision 3-4.

The new version also supports PDF documents with custom length encryption keys.

Password recovery for MS SQL

In addition to resetting MS SQL passwords, Passware Kit 2021 v1 also recovers the original passwords for MS SQL databases (*.MDF). The password recovery speed is over 58,000 passwords per second.

Import of dictionaries preserving the order of passwords

There is now a new option that allows users to keep the original order of passwords in a dictionary when importing it into the Passware Kit.

This allows the use of password lists sorted by the frequency of use of those passwords. It is helpful when recovering passwords for file types with secure encryption, such as iTunes backups or hard disk images.

What’s New Video

For your convenience, we put together a video on all the recent features of Passware Kit 2021 v1. Take a look!

Leave a Comment

Latest Videos

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feeds settings page to add an API key after following these instructions.

Latest Articles