[sleuthkit-users] dealing with whole disk encryption
Brought to you by:
carrier
From: <jan...@nr...> - 2010-08-14 17:32:16
|
Hello everyone, one question - is there any current canonical way of dealing with whole disk encryption when acquiring images apart from using FTK or Encase? I'd like to stick to Sleuthkit and Autopsy. The last time I had to manage hard disk encryption the system was still up and accessible and I could image via FAU's dd. Now, I am facing a machine with a locked session and SafeBoot. Anyone have any ideas or experience to share? Passwords are available. Thanks, Jan |