Post Reply 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Acquisition of hardware-encrypted USB devices
05-08-2017, 12:54 AM
Post: #1
Acquisition of hardware-encrypted USB devices
Hello all,

I'm working a case where I need to acquire an external USB hard drive (IronKey H100) and several Kingston DataTraveler (DTVP30) devices. As I understand it, these devices use hardware encryption and, I presume the area of flash memory where the encrypted data is stored isn't even presented to the operating system until their proprietary software is launched and a password is provided. In a perfect world, I would write-block the device, capture the encrypted partition, and then use a module or plug-in in EnCase or AXIOM to decrypt the partition (assuming such a module or plugin exists).

However, my instinct is that there is no such module or plug-in and I'll simply have to mount the devices as read/write, launch the proprietary software, enter the password, and then capture the image. Am I on the right track here? Or is there some other way of capturing these devices in a read-only mode?

Find all posts by this user
Quote this message in a reply
Post Reply 

Forum Jump:

User(s) browsing this thread: 1 Guest(s)