Dedicated to the branch of forensic science encompassing the recovery and investigation of material found in digital devices, often in relation to computer crime. This field involves the application of several information security principles and aims to provide for attribution and event reconstruction following forth from audit processes. This subreddit is not limited to just personal computers and encompasses all media that may also fall under digital forensics (e.g., cellphones, video, etc.).
hi everyone,
i have made a full ddrescue image from a w11 SSD that had deleted files to search for,
however i later realized that the drive was bitlocker encrypted
problem is i have full access to the PC, but being a home edition i apparently have no way to obtain the key without re-encrypting and thus making my image useless
can i somehow grab the key from a running system with admin account ? i'm kinda amazed that it's not an option officially in any way
i can search for deleted files on the running system but there has been changes in the documents since my image was done so i'd realllly like to search in it instead