Mounts encrypted volumes as new drive letters, providing real-time, unrestricted access to files and folders.
Elcomsoft Forensic Disk Decryptor (EFDD) is a specialized forensic tool designed to provide investigators with instant access to data stored in encrypted volumes, including BitLocker, FileVault 2, VeraCrypt, and PGP. It is unique for its ability to bypass encryption by extracting binary encryption keys directly from a computer's volatile memory (RAM) or hibernation files. Portable Version Overview portable version
The standard EFDD requires installation on a forensic workstation. The portable edition is designed to be placed on a bootable USB drive or an external SSD. This allows an investigator to arrive at a scene, plug the USB into a live target computer (or a forensic bridge), and execute the decryption process without leaving traces on the suspect's hard drive.
