Checking for encryption
One area of concern for responders is the use of Full Disk Encryption (FDE). Windows system administrators are likely to be familiar with FDE tools such as BitLocker, which is now part of the Windows OS. Outside of that, there are a number of tools such as VeraCrypt that allow users to encrypt individual files all the way to entire volumes. As part of the acquisition process, responders should check for any encryption.
Tools such as Endpoint Disk Detector from Magnet Forensics determine whether there are any encrypted volumes. This tool, available for free at https://www.magnetforensics.com/resources/encrypted-disk-detector/, can determine what, if any, encryption is being used. Simply running the executable as administrator ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access