Passware Kit Forensic is the complete electronic evidence discovery solution that reports all password-protected items on a computer and decrypts them. The software recognizes 280+ file types and works in batch mode recovering their passwords.
Live Memory analysys Home Page - https://www.passware.com/kit-forensic/
Extracts encryption keys for FileVault2, TrueCrypt, VeraCrypt, BitLocker, logins for Windows & Mac accounts from memory images & hibernation files.
Cloud Data Acqusition
Passware Kit acquires backups and data from cloud services: Apple iCloud and iCloud Drive, MS OneDrive, and Dropbox.
Mobile Forensics
Recovers Passwords for Apple iPhone/iPad and Android backups, as well as Android images. Extracts data from Windows Phones' images. Integrated with Oxygen Forensic Suite.
Hardware Acceleration
Accelerated password recovery with multiple computers, NVIDIA & AMD GPUs, Tableau Password Recovery and TACC, and Rainbow Tables.
Intelligent Detection
Detects all the encrypted files & hard disc images, reports encryption type and decryption complexity.
Linux Agent Ready
Run a portable Passware Kit Agent from a bootable Linux USB drive.
What's New in Passware Kit Forensic 2017.1.1 :
- Resolved issue with iCloud backup acquisition
- Minor FileVault GUI improvements
- Resolved 1Password attack model issue
- Resolved minor Linux Passware Kit Agent issue
Passware Kit Forensic 2017.1.0 (Major Update):
New Features:
- Instant FileVault2 decryption using data extracted from iOS backups
- Password recovery for QuickBooks 2015-2017
- Password recovery for 1Password for Mac Vaults
- Dictionaries for Danish and Swedish languages
- MD5 hash for evidence acquired from the cloud
TO MAC USERS: If RAR password doesn't work, use this archive program:
RAR Expander 0.8.5 Beta 4 and extract password protected files without error.
TO WIN USERS: If RAR password doesn't work, use this archive program:
Latest Winrar and extract password protected files without error.