Reduce time spent on recovering passwords, improve recovery rates, and get more control over the password recovery process. Passware Kit Forensic is the complete electronic evidence discovery solution that reports all password-protected items on a computer and decrypts them. The software recognizes 300+ file types and works in batch mode recovering their passwords. MS Office, PDF, Zip and RAR, QuickBooks, FileMaker, Lotus Notes, Bitcoin wallets, Apple iTunes Backup, Mac OS X Keychain, password managers, and many other popular applications.
– Recovers passwords for 300+ file types and decrypts hard disks providing an all-in-one user interface Updated!
– Supports batch file processing
– Scans computers and network for password-protected files and encrypted hard disk images (Encryption Analyzer Professional included)
– Acquires memory images of the seized computers (FireWire Memory Imager included)
– Retrieves electronic evidence in a matter of minutes from a Windows Desktop Search Database (Search Index Examiner included)
– Recovers Mac User Login passwords and FileVault2 keys from computer memory
– Supports Distributed and Cloud Computing password recovery on both Windows and Linux platforms New!
– Runs from a USB thumb drive and recovers passwords without installation on a target PC (Portable Version included)
– Instantly recovers many password types
– Instantly decrypts MS Word and Excel files up to version 2019 (20 Credits for Decryptum attack included)
– Resets passwords for Local and Domain Windows Administrators instantly, including passwords for Windows Live ID accounts Updated!
– Recovers encryption keys for hard disks protected with BitLocker in minutes, including BitLocker ToGo
– Decrypts TrueCrypt, FileVault2, and PGP volumes in minutes
– Recovers passwords for Windows users from a memory image or a standalone SAM file, including UPEK
– Recovers passwords for Facebook, Google, and other websites from live memory images or hibernation files
– Recovers passwords for iTunes and Android backups, as well as Android physical images Updated!
– Instantly recovers passwords for email, websites and network connections from standalone registry files
– Extracts passwords from encrypted Mac keychain files
– Extracts passwords from Windows/Unix/Mac hashes
– Provides 9 different password recovery attacks (and any combination of them) with an easy-to-use setup wizard and drag & drop attacks editor)
– Uses multiple-core CPUs and NVIDIA and ATI GPUs efficiently to speed up the password recovery process by up to 100 times Updated!
– Uses Tableau TACC hardware accelerators to speed up the password recovery process by up to 25 times
– Provides detailed reports with MD5 hash values
– Integrated with Guidance EnCase
– Integrated with Oxygen Forensic Suite
Benefits for Computer Forensics
This complete electronic evidence discovery solution reports all password-protected items on a computer and gains access to these items using the fastest decryption and password recovery algorithms. Many types of passwords are recovered or reset instantly, and advanced acceleration methods are used to recover difficult passwords. Passware Kit Forensic introduces batch file processing and a new attacks editor, which sets up the password recovery process in the most precise way to provide the quickest decryption solution possible. The highest performance is achieved with Distributed Password Recovery, using the computing power of multiple computers, both Windows and Linux platforms.
Passware Kit Forensic includes a Portable version that runs from a USB drive and finds encrypted files, recovers files and websites passwords without modifying files or settings on the host computer. Perform a complete encrypted evidence discovery process without installing Passware Kit on a target PC.
Passware Kit Forensic, complete with Passware FireWire Memory Imager, is the first commercial software that instantly decrypts BitLocker, TrueCrypt, FileVault2, and PGP hard disks, MS Office documents, as well as instantly recovers passwords for websites, Windows and Mac users, by analyzing hibernation files and live memory images acquired via FireWire.
- Decryption of disks encrypted with Dell Data Protection
- Hardware benchmark tool
- Support for QuickBooks 2021
- Automatic FileVault2 Wipekey extraction
- GPU acceleration for Android 4.4 images
- 13x faster on Zip and support for large archives
- Ability to view settings of successful password recovery attacks
- Usability improvements
Dell Data Protection and Dell Encryption software used to be an obstacle for computer forensics because the encrypted data was inaccessible while processing an image of encrypted drives.
We are happy to announce that Passware Kit is the first software to recover passwords for Dell recovery files and decrypt data from disks encrypted with Dell Data Protection and Dell Encryption software provided that a Dell recovery file is available.
To address the challenges in setting up high-performance decryption systems, Passware Kit 2021 v2 introduces a new password recovery benchmark tool. With just a couple of clicks, it measures hardware performance on typical password recovery tasks, on either a single computer or a cluster of Passware Kit Agents.
The new version also decrypts QuickBooks 2021 databases, accelerates password recovery for Android images, and automatically extracts Wipekey files from FileVault2 disk images.
Decryption of disks encrypted with Dell Data Protection
Passware Kit 2021 v2 decrypts data from disks encrypted with Dell Data Protection and Dell Encryption software provided that a Dell recovery file is available.
Passware Kit is the first software to recover passwords for Dell recovery files and decrypt data from a Dell folder or mounted Dell image. The password recovery process can be accelerated on GPU, reaching speeds of 220,000 passwords per second on NVIDIA 2080Ti.
Passware Kit creates a folder with decrypted files. Dell Encryption software is not required to perform the decryption.
Hardware benchmark tool
Passware introduces a “Hardware Benchmark” option that assesses hardware performance on typical password recovery tasks. It gives a full report on the password recovery speed and temperature for CPU and GPU on local computers and distributed Agents.
To test performance, the user can choose any combination of more than a dozen file types: MS Office documents, iTunes backups, Zip, RAR, PDF, Bitcoin, APFS, iWorks, BitLocker, and others.
The benchmark is available in the “Tools” menu.
Automatic FileVault2 Wipekey extraction
Passware Kit no longer requires a user to provide a Wipekey file in order to recover a password for a FileVault2 volume.
Within a few seconds, the Wipekey file is automatically extracted from the Recovery partition, so that the user can immediately proceed to FileVault2 password recovery.
GPU acceleration for Android 4.4 images
Passware is the first to support GPU acceleration for Android images protected by the scrypt algorithm and introduces the fastest password recovery solution for Android images of version 4.4. The acceleration works on both NVIDIA and AMD GPUs and provides an average speed of over 190 passwords per second on an NVIDIA 2080Ti.
13x faster on Zip and support for large archives
The new Passware Kit supports Zip archives, which contain 4GB+ files, and recovers passwords 13 times faster for archives that use Zip Deflate compression, reaching speeds of 69 million passwords per second on CPU.
Ability to view settings of successful password recovery attacks
It is now possible to view and export the settings of each attack from the “Attacks” tab during or after the password recovery process.
This allows a user to access the detailed password recovery settings of the attack that found the password and reuse them to decrypt other files.
The “Attack settings” page of the Passware Kit now features expandable columns, e.g., Settings, Passwords to check, Complexity, etc., as well as a scroll bar to make the process of managing and customizing password recovery settings easier.
Also, it is now possible to add attacks from a PWM settings file to an existing list of attacks instead of overwriting them.
Passware Kit now shows a warning indicator next to the “Log” tab title if any error occurs during the password recovery process.