Many thanks for input.
Yes, am assuming FDE using SecurStar SecurBoot product now marketed as DriveCrypt. Don't know anymore than this at the moment.
Sorry, shld have mentioned this before as it seems this product uses pre-boot authentication which I assume is why CAINE and AIR can't see the hard disk as a potential 'source' drive (AIR doesn't even list it!).
Any ideas how to at least achieve an encrypted raw image in the hope that the key is found at some point?
Many thanks
rgds
M
↧