Hello,
I am currently trying to Acquire an SSD with Checkpoint FDE connected via a Tableau Write Blocker. I have created the case in EnCase Forensic and have got to the point where i select acquire and get the box pop up asking for the .rec file and username. I have got a copy of the .rec file from the companies service desk but they have offered two different solution's in order to decrypt the disk;
1) They can provide me with 2 recovery PIN number's, i am assuming this will not work with EnCase as this is not what EnCase is asking for?
2) I can get a username and password from the service desk which they are saying i then need to create a bootable Win32Disk Imager USB in order to image the drive. Am i correct in thinking that instead of doing this i can just enter the username and password into EnCase when prompted and that will work?
I have never worked with Checkpoint FDE before and have been trying to read up on exactly how it work's, i have looked at the KB article on Guidance Software's Customer Portal and believe i am correct in my assumtion in point 2 from what i have read but just wanted to get it confirmed from someone out there who has worked with Checkpoint FDE before.
Any advice greatly appreciated.
↧