Elcomsoft Forensic Disk Decryptor is a detailed and powerful suite that offers users complete access to data stored in crypto containers. The software recognizes PGP encrypted volumes, as well as full disk encryptions.

The software is intended to help forensic specialists and other affiliated professionals in obtaining locked information. Therefore, anyone who operates on a regular basis with encrypted volumes will find this application highly beneficial. It can also be employed to test the decryption resilience of such items.

Elcomsoft Forensic Disk Decryptor ships with a very intuitive interface that guides users through the sequential steps required to decrypt items. Navigation is performed with the several on-screen buttons, and some knowledge is required to obtain palpable results.

The resource comes with two fundamental operating modes: “Decrypt or mount disk” and “Extract keys”. Both rely on memory images and the difference is that with the first option, users can mount the volume as a drive letter (as an unlocked, unencrypted item).

When extracting keys from a memory image, users can choose from a wide variety of encryption modes, including PGP, BitLocker or TrueCrypt volume master keys. The source input memory document can take either the form of a memory dump or a hibernation file.

One of the great features of this software is that it leaves no traces behind it. Decrypting the data in no way affects the target items, and previously encrypted volumes will not be tempered with. This is a highly important aspect for forensic specialists.

To conclude, Elcomsoft Forensic Disk Decryptor is a highly specialized and powerful decryption tool that can unlock BitLocker, PGP and TrueCrypt disks or containers.