Icon Menu
Icon Search

Passware Kit Forensic

The world leader in encrypted electronic evidence discovery and decryption

Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer. The software recognizes 300+ file types and works in batch mode recovering passwords.

What's New

  • Passware Kit Forensic for Mac

  • Decryption of LUKS2 disks

  • Password recovery for Dashlane Desktop

  • Batch mode: improved performance for 1,000+ files

  • Passware Bootable Memory Imager supports UEFI 1.x

  • Keychain extraction improvements

Passware Kit Forenwsic

Password recovery for over 300 file types

MS Office, PDF, Zip and RAR, QuickBooks, FileMaker, Lotus Notes, Bitcoin wallets, Apple iTunes Backup, Mac OS X Keychain, password managers, and many other popular applications.

Full disk decryption

Decrypts or recovers passwords for APFS, Apple DMG, BitLocker, Dell, FileVault2, LUKS, McAfee, PGP, Symantec, TrueCrypt, and VeraCrypt disk images.

Live memory analysis

Analyzes live memory images and hibernation files and extracts encryption keys for hard disks and logins for Windows & Mac accounts. Passware Bootable Memory Imager acquires memory of Windows, Linux, and Mac computers.

Password recovery for over 300 file types

MS Office, PDF, Zip and RAR, QuickBooks, FileMaker, Lotus Notes, Bitcoin wallets, Apple iTunes Backup, Mac OS X Keychain, password managers, and many other popular applications.

Hardware
acceleration

Accelerated password recovery with multiple computers, NVIDIA and AMD GPUs, and Rainbow Tables.

Live memory
analysis

Analyzes memory images and hibernation files and extracts encryption keys for hard disks and files and passwords for Windows/Mac accounts and websites. Acquires memory of Windows, Linux, and Mac computers.

Mobile
forensics

Recovers passwords for Apple iPhone/iPad and Android backups as well as Android images and extracts data from images on Windows phones.

Mac
version

In addition to all the key features of a Windows version, Passware Kit Forensic for Mac provides access to APFS disks from Mac computers with Apple T2 chip.

Intelligent
detection

Detects all encrypted files and hard disk images and reports the type of encryption and the complexity of the decryption.

Automatic
updates

Optional automatic software and agents updates with one year of Software Maintenance and Support (SMS) subscription.

Passware Kit
Agents

Support for distributed password recovery for Windows, Linux, and Amazon EC2. The Linux version runs a portable Passware Kit Agent from a bootable Linux USB drive.

Decryption
of FDE

Decrypts or recovers passwords for APFS, Apple DMG, BitLocker, Dell, FileVault2, LUKS, McAfee, PGP, Symantec, TrueCrypt, and VeraCrypt disk images.

Hardware acceleration ofpassword recovery attacks

Accelerated password recovery with multiple computers, NVIDIA and AMD GPUs, and Rainbow Tables.

Passware

Passware Kit Agent is a network distributed password recovery worker for Passware Kit Forensic.

It runs on Windows and Linux, 64- and 32-bit, has linear performance scalability. Each computer running Passware Kit Agent supports multiple CPUs, GPUs, and TPR accelerators simultaneously. Passware Kit Forensic comes with 5 agents included with ability to purchase more separately as needed.

Network Distributed Password Recovery

Passware Kit Agent Passware Kit Agent is a network distributed password recovery worker for Passware Kit Forensic. It runs on Windows and Linux, 64- and 32-bit, has linear performance scalability. Each computer running Passware Kit Agent supports multiple CPUs, GPUs, and TPR accelerators simultaneously. Passware Kit Forensic comes with 5 agents included with ability to purchase more separately as needed.

Hardware Acceleration of Password Recovery Attacks

Passware Kit Forensic can increase password recovery speed up to 400 times by using a single GPU (Graphics Processing Unit) card, and up to 12,000 times by using a single Decryptum PR 2080TI-S/12 4U unit. Distribute password recovery tasks over a network of Windows or Linux computers, as well as Amazon EC2, for linear scalability. For even higher performance use Decryptum, our ultra-compact liquid-cooled GPU accelerated devices - world's fastest scalable turn-key decryption solution for password recovery.

Training available online - on demand

Passware Certified Examiner (PCE) Online Training is designed to provide computer forensic professionals the knowledge and skills they need to detect, analyze, and decrypt encrypted electronic evidence in the most efficient way. During the course, students learn how to detect encrypted evidence, recover passwords for all common file types, analyze memory images, recover passwords for mobile backups, decrypt hard drives, and more. The course consists of 15 short video sessions. Participants in this training course may take the exam to receive a Passware Certified Examiner (PCE) designation.