ElcomSoft Co. Ltd. updates Elcomsoft System Recovery, a bootable tool for unlocking Windows accounts, accessing encrypted volumes and unlocking encrypted virtual machines. The newly added tools for helping investigators finding encrypted virtual machines and imaging hard drives by booting from a USB drive make Elcomsoft System Recovery a Swiss army knife of the digital forensic specialist.
Helps Unlock Encrypted Virtual Machines
In the world of hi-tech crime, encrypted virtual machines are one the most used cover-up tools. Manually identifying the presence of such virtual machines can be an involving manual process. Elcomsoft System Recovery 7.07 makes this process straightforward by automatically discovering encrypted virtual machines in most common formats. Once a password-protected virtual machine is found, the tool extracts the required encryption metadata to enable subsequent attacks on the password with Elcomsoft Distributed Password Recovery.
Disk Imaging Made Easy
For a number of reasons, experts investigating incidents work with disk images as opposed to physical hard drives. The general workflow suggests taking the disks out before imaging, which may add significant time to the investigation. Elcomsoft System Recovery makes forensic disk images easy to make by imaging the suspect’s hard drives without the need to remove them from the computer while eliminating the risks associated with investigating a live system.
Elcomsoft System Recovery 7.07 arrives with a host of features aimed at making the recovery of various passwords more efficient and straightforward. The new release can extract security questions and answers and password hints in the newest format from local Windows accounts for subsequent analysis. The underlying Windows PE environment has been updated to the newest release, bringing the associated support for the newest hardware, compatibility improvements and security fixes.
Elcomsoft System Recovery offers unprecedented compatibility thanks to the use of the genuine Windows PE environment. The tool creates a bootable Windows PE flash drive, allowing experts to load additional drivers if required. The tool is compatible with 32-bit and 64-bit BIOS and UEFI computers running all versions of Windows up to and including the last versions of Windows 10 and Windows Server 2019.
About Elcomsoft System Recovery
Elcomsoft System Recovery helps users and digital forensic experts recover or reset lost or forgotten passwords to Windows accounts. With instant access to locked and disabled accounts, Elcomsoft System Recovery can assign or revoke administrative privileges to user accounts, replace and recover account passwords. The ability to recover account passwords helps experts access EFS-encrypted files and folders, while the ability to extract hibernation files and password hashes from encrypted disk volumes offers faster access to protected evidence stored on encrypted partitions.
Elcomsoft System Recovery operates from the familiar Windows environment by booting into portable Windows PE from a USB flash drive. ElcomSoft makes it easy creating a flash drive with Windows bootable environment, delivering a complete bootable disc or image for both BIOS and UEFI computers.
About ElcomSoft Co. Ltd.
Founded in 1990, ElcomSoft Co.Ltd. is a global industry-acknowledged expert in computer and mobile forensics providing tools, training, and consulting services to law enforcement, forensics, financial and intelligence agencies. ElcomSoft pioneered and patented numerous cryptography techniques, setting and exceeding expectations by consistently breaking the industry’s performance records. ElcomSoft is Microsoft Certrified Partner (Gold competency), and Intel Software Premier Elite Partner. For more information about Elcomsoft System Recovery visit https://www.elcomsoft.com/esr.html
Praha 5, Zličín,
Czech Republic, PSČ 155 21
Zvezdnyi blvd. 21, office 615