https://www.forensicfocus.com/Forums/viewtopic/t=15440/highlight=encrypted+surface/



1.Boot to CAINE (or similar) and take a physical image using Guymager

2.Boot the surface and log in (assume you have credentials since you have taken an image with FTK already)

3.open command prompt (as administrator), type

manage-bde -protectors C: -get

(I am assuming C: is the encrypted OS partition, change to the relevant drive letter if not)

This should display the bitlocker recovery password - make a note of it or take a picture or both.

Use the recovery password to decrypt the physical image you took with Caine (FTK for example will simply ask you for the recovery key when you add the image in).

+ Recent posts