Get Help Now
    24/7 Support

    Volatility Framework plugin for extracting BitLocker FVEK

    This plugin, developed by Marcin Ulikowski, finds and extracts Full Volume Encryption Key (FVEK) from memory dumps and/or hibernation files. This allows rapid unlocking of systems that had BitLocker encrypted volumes mounted at the time of acquisition.

    Bitlocker_decryption_weare4n6

    It supports the following memory images:

    • Windows 10 (work in progress)
    • Windows 8.1
    • Windows Server 2012 R2
    • Windows 8
    • Windows Server 2012
    • Windows 7
    • Windows Server 2008 R2
    • Windows Server 2008
    • Windows Vista

    For more info use this link.



    DISCLAIMER: THIS POST IS FOR INFORMATIONAL PURPOSES ONLY AND IS NOT TO BE CONSIDERED LEGAL ADVICE ON ANY SUBJECT MATTER. DIGITAL FORENSICS CORP. IS NOT A LAWFIRM AND DOES NOT PROVIDE LEGAL ADVICE OR SERVICES. By viewing posts, the reader understands there is no attorney-client relationship, the post should not be used as a substitute for legal advice from a licensed professional attorney, and readers are urged to consult their own legal counsel on any specific legal questions concerning a specific situation.