Elcomsoft Forensic Disk Decryptor

Elcomsoft Forensic Disk Decryptor 2.17

Opens encrypted BitLocker, TrueCrypt or PGP files

Gain complete access to data stored in crypto containers. The utility extracts information protected by desktop and portable versions of BitLocker, PGP, and TrueCrypt protection. It works with separate volumes or complete disks. Mounting encrypted volumes as new drive letters for the instant, real-time access is possible.

Elcomsoft Forensic Disk Decryptor can help you access encrypted data. The program is definitely not intended for the common users, as it is forensic specialists who benefit the most from this type of software. Despite the evident complexity of using such a program, its interface unquestionably makes the whole process feel much easier, particularly because it has been designed in a wizard-like fashion.

The tool is operated in two different modes. The first lets you decrypt or mount a disk, which becomes accessible through a system drive letter. The second mode simply provides the keys that are necessary to access the encrypted data.

Various decryption methods can be used, such as memory dump, saved keys, password and hibernation files. In this regard, it is quite significant that the program can capture the data contained in the computer’s RAM memory with its kernel-level tool. Another source of data can come from a computer’s hibernation file.

Elcomsoft Forensic Disk Decryptor can effectively deal with the most widely used disk encryption types, including VeraCrypt, TrueCrypt, BitLocker, PGP disk and PGP WDE. In the case of PGP, notice that it can equally provide access to both encrypted volumes and full disk encryptions.

In addition to its proven efficacy in unlocking protected data, the program also has the advantage of doing this without messing with the source files. Thus, it leaves no footprint of the operation when the encrypted volume is mounted as a drive, because the data is decrypted on the fly. It is also quite convenient that you can create a portable version of the software and run it from an external drive.

All in all, Elcomsoft Forensic Disk Decryptor can successfully give you access to data locked by various types of encryption and it even gathers information from the volatile memory or the hibernation files. Luckily, it comes with extensive help documentation that does not leave any question unanswered. Besides, its developers provide excellent support in case you need it. Finally, you should know that the program has a reasonable price compared with other similar products and can be tried at no cost.

Pedro Castro
Editor rating:

Review summary


  • Supports various types of encryption
  • Provides on-the-fly access to encrypted data
  • Catches data from the RAM and the hibernation files
  • Supports various decryption methods
  • Wizard-like interface


  • Not intended for the common user
Info updated on: