Passware Kit Forensic

Password recovery for 280+ file types

MS Office, PDF, Zip and RAR, Quickbooks, FileMaker, Lotus Notes, Apple iTunes Backup, Mac OS X Keychain and many other popular applications.

Live Memory analysis

Analyzes live memory images, hibernation files and extract encryption keys for FileVault2, TrueCrypt, VeraCrypt, BitLocker, logins for Windows & Mac accounts from memory images & hibernation files.

Cloud Data Acquisition

Passware Kit acquires backups and data from cloud services: Apple iCloud and iCloud Drive, MS OneDrive, and Dropbox.

Mobile Forensics

Recovers passwords for Apple iPhone/iPad and Android backups as well as Android images and extracts data from images on Windows phones. Integrated with the Oxygen Forensic Suite.

Hardware Acceleration

Accelerated password recovery with multiple computers, NVIDIA and AMD GPUs, Tableau Password Recovery and TACC, and Rainbow Tables.

Intelligent Detection

Detects all the encrypted files and hard disk images, reports encryption type and decryption complexity.

Linux Agent Ready

Run a portable Passware Kit Agent from a bootable Linux USB drive.

Decryption of FDE

Decrypts or recovers passwords for BitLocker, FileVault2, TrueCrypt, VeraCrypt, LUKS, McAfee, Apple DMG, and PGP disk images.

Detect encrypted files and containers
Find all the encrypted or password-protected documents, archives and other files. Sort by decryption complexity. Passware Kit Forensic detects 280+ file types.

Extract encryption keys and passwords from memory images
quickly scan memory images and hibernation files. Extract encryption keys for FileVault 2, TrueCrypt, VeraCrypt and BitLocker for instant decryption of encrypted disks and containers. Build possible passwords dictionaries or extract account passwords for Windows and Mac.

Use hardware acceleration and distributed password recovery
Increase password recovery speed up to 400 times by using a single GPU (Graphics Processing Unit) card, and up to 3,200 times by using 8 GPUs in a single computer. Distribute password recovery tasks over a network of Windows or Linux computers for linear scalability.

Key Features

  • Recovers passwords for 200+ file types and decrypts hard disks providing an all-in-one user interface Updated!
  • Mobile forensics: recovers passwords for iTunes and Android backups, Android physical images, as well as acquires backups for iOS devices from iCloud
  • 64-bit version
  • Supports batch file processing
  • Scans computers and network for password-protected files and encrypted hard disk images (Encryption Analyzer Professional included)
  • Acquires memory images of the seized computers (FireWire Memory Imager included)
  • Retrieves electronic evidence in a matter of minutes from a Windows Desktop Search Database (Search Index Examiner included)
  • Recovers Mac User Login passwords and FileVault2 keys from computer memory
  • Supports Distributed and Cloud Computing password recovery on both Windows and Linux platforms
  • Runs from a USB thumb drive and recovers passwords without installation on a target

General Features

  • Instantly recovers many password types
  • Instantly decrypts MS Word and Excel files up to version 2003 (20 Credits for Decryptum attack included)
  • Resets passwords for Local and Domain Windows Administrators instantly, including passwords for Windows Live ID accounts
  • Recovers encryption keys for hard disks protected with BitLocker in minutes, including BitLocker ToGo
  • Decrypts TrueCrypt, FileVault2, and PGP volumes in minutes
  • Recovers passwords for Apple DMG and LUKS disk images Updated!
  • Recovers passwords for Windows users from a memory image or a standalone SAM file, including UPEK
  • Recovers passwords for Facebook, Google, and other websites from live memory images or hibernation files
  • Instantly recovers passwords for email, websites and network connections from standalone registry files
  • Extracts passwords from encrypted Mac keychain files

Includes 5 agents

Passware Kit Forensic 2018.1.2

  • Resolved issues with some APFS images being reported as damaged
  • Fixed minor iCloud backup issue [SUP-800]
  • Resolved issues with some Windows SAM databases
  • Resolved minor Portable Decryptum issues [SUP-807]
  • Resolved “setNetworkObserver” error [SUP-819]
  • Fixed issue with QuickBooks licensing [SUP-794]
  • Multiple minor GUI improvements and fixes
  • Resolved issues with the Undo option of the Attack Editor