Encryption has become one of the biggest challenges facing digital forensic investigators today. As devices and apps make encrypting data easier than ever, critical evidence increasingly slips beyond the reach of investigators.
According to surveys, around 55-60% of cases now involve some form of encryption. This is radically transforming the investigator‘s toolkit. Specialized decryption tools are now mandatory to recover encrypted data and passwords in a legally sound manner.
As a forensic computing expert with over 15 years of experience, I‘ve seen first-hand how encryption stymies even veteran investigators. High profile cases like the San Bernardino shooting have hinged on access to encrypted data. The stakes don‘t get higher than when people‘s lives are on the line.
That‘s why tools that can rapidly decrypt data while leaving no trace have become so vital. They empower investigators with crucial capabilities once limited to elite agencies.
In this guide, I‘ll share my insights into the decryption tools that should be in every professional‘s toolkit in the encryption era. I‘ll provide tips to help you evaluate options and combine solutions that best fit your needs.
The Encryption Threat to Digital Forensics
Encryption uses clever math to scramble data into a format that is unreadable without the correct cryptographic key. It provides privacy and security for legitimate uses.
But in the hands of criminals who encrypt devices and communications, it poses a dire threat to justice and public safety.
Investigations are increasingly hitting this encryption wall. It prevents access to vital electronic evidence from cipher text and passwords locked behind encryption.
Some examples of encrypted data jeopardizing major cases include:
-
The San Bernardino Shooting (2015): The shooter‘s iPhone was encrypted, delaying FBI access to critical data.
-
The Pensacola Naval Base Shooting (2019): The killer‘s iPhones were locked, with data permanently inaccessible after 10 wrong passcode attempts.
-
Ransomware Attacks: Critical files and drives are encrypted by ransomware, bringing networks and businesses to their knees.
Encrypted data is meaningless without the right decryption key. And modern encryption uses long keys that even supercomputers can take centuries to break through brute force.
Why Forensic Investigators Need Decryption Tools
Manual decryption is almost impossible for all but trivial passwords and keys. That‘s why investigators need robust decryption tools delivering:
Speed: Tools decrypt data hundreds or thousands of times faster than manual techniques. This rapid access to evidence can make or break time-sensitive cases.
Usability:Technical expertise in cryptography and programming languages is not required. The tools handle the intricate decryption work.
Stealth: Tools running in forensic mode leave no trace of decryption activity. This prevents alerting suspects by triggering antitamper defenses.
Versatility: A single toolkit efficiently handles various encryption types from password-protected files to encrypted iOS and Android phones.
Future-proofing: Regular updates ensure support keeps pace with new operating systems, apps and encryption schemes.
Together these capabilities unlock unprecedented access to encrypted data for investigators without tipping off the owners. Next, we‘ll explore leading solutions delivering these benefits.
Top Commercial Forensic Decryption Systems
Government agencies and private investigators overwhelmingly favor robust commercial solutions that integrate decryption alongside other forensic capabilities.
Here are two industry-leading tools that come highly recommended based on hands-on experience and feedback from fellow investigators.
1. Passware Kit Forensic
Passware Kit Forensic is one of the most widely used commercial decryption platforms globally. Since 2002, they have provided decryption capabilities to law enforcement, government, and corporate clients in 100+ countries.

According to Passware, their software has helped investigators gain access to 50k+ mobile devices and 10 million encrypted files. 2,000+ public safety agencies rely on their tools.
The highlights of Passware Kit include:
-
Full Disk Decryption: Decrypts major disk encryption including BitLocker, FileVault 2, and VeraCrypt.
-
iOS and Android decryption: Performs physical acquisition from locked mobile devices. WhatsApp and cloud extraction available.
-
140+ File Types: Decrypts popular file formats including MS Office docs, archives, email, and databases.
-
GPU acceleration: Leverages GPU power to radically speed up processing and password recovery.
-
Cloud extraction: Recovers artifacts from major cloud services including Facebook and Gmail.
-
Secure delete: Wipes selected files and their slack space to prevent recovery.
With its vast capabilities and scalability, Passware Kit should be strongly considered by investigators regularly tackling encryption.
2. Elcomsoft Forensic Disk Decryptor
Where Passware Kit takes an expansive approach, Elcomsoft Forensic Disk Decryptor (EFDD) focuses on swiftly decrypting storage volumes and drives.
It achieves real-time, read-only access to encrypted volumes, allowing investigators to immediately mount them as drives and peruse the decrypted contents using forensic tools.
The maker, Elcomsoft, has provided leading password cracking and mobile forensic tools since 2002.
Here are some of EFDD‘s benefits:
- Real-time access: Volumes mounts instantly after decryption as virtual drives.
- No traces: Leaves no evidence of tampering detectable by forensics.
- Broad support:Handles BitLocker, FileVault 2, PGP, and TrueCrypt encryption.
- Volume keys: Retrieves encryption keys to save time.
- EnCase integration: Creates EnCase-compatible forensic images.
- Performance: Optimized to use available resources for faster processing.
EFDD is purpose-built to address encrypted storage volumes speedily and thoroughly. Paired with a toolkit like Passware, investigators wield tremendous firepower against encryption.
Best Free and Open Source Decryption Tools
While commercial solutions provide the most polished end-to-end capabilities, free open source tools can still be enormously useful.
These tools benefit from worldwide community testing and development. And they avoid the premium pricing of commercial software, making them accessible for all investigators.
The following are some of my favorite free decryption tools.
Mobile Verification Toolkit (MVT)
MVT focuses on detecting state-sponsored mobile spyware and malware like Pegasus. It was built by Amnesty International‘s Security Lab in 2021.
The tool scans Android and iOS devices for signs of compromise like jailbreaking. It also analyzes installed apps, processes, network connections, and system logs for malicious activities.

MVT currently provides the most robust open source capabilities to:
- Detect mobile device jailbreaks that weaken security.
- Identify malicious processes from spyware.
- Review sensitive device logs for signs of compromise.
- Check network traffic for unauthorized connections.
For cases involving mobile devices, MVT should be a standard part of the investigator‘s toolkit.
Paladin Forensic Suite

Paladin delivers an arsenal of free forensic tools bundled in a bootable Linux environment. Once booted, users gain access to powerful utilities for analysis and decryption without any installation.
Highlights of Paladin‘s 100+ included tools:
- Write blockers to prevent disk tampering.
- Disk cloning and imaging for analysis.
- File carving to reconstruct deleted files.
- Password cracking for document files.
- Autopsy suite for digital forensics.
- Web browser tools for gathering history and caches.
Paladin Suite allows utilizing many commercial-grade forensic capabilities without the licensing costs. The bootable design bypasses any encryption or password protections on the host system.
John the Ripper Password Cracker
John the Ripper (JtR) is likely the most widely used free password cracking tool. Initially released in 1996, it continues to be maintained and updated.
JtR can crack many encrypted password hashes through brute force, dictionary, and rule-based attacks. It can also detect weak passwords.

Some noteworthy features include:
- Cracks ~200 hash types including LM, NT, md5, sha-512.
- Mangles wordlists and mutates passwords for more guesses.
- OpenCL GPU acceleration support.
- Incremental attacking continuously tries new passwords.
- Distributed cracking with multiple systems.
For pure password recovery and hash cracking, JtR provides professional-grade capabilities. Its free status makes it accessible to all investigators for evaluative and small-scale use.
Tips for Choosing the Right Decryption Tools
With varied tools at their disposal from comprehensive commercial kits to specialized open source software, investigators must identify the ideal options for their needs.
Here are tips for selecting suitable decryption tools:
-
Evaluate support for the encrypted devices, operating systems, and data types involved in your typical investigations.
-
Opt for tools with GPU support for 5-20X faster cracking speeds compared to just CPUs. Highly recommended.
-
Verify the tool leaves no detectable trace of tampering after use. Stealth is vital.
-
Prioritize ease of use as technically complex tools increase mistakes. Look for clear wizards and guides.
-
For smartphones, choose tools providing deep mobile forensic capabilities beyond just data extraction.
-
For reviving encrypted volumes, pick a dedicated solution like Elcomsoft EFDD optimized for this task.
-
Open source tools are great for evaluation. But verify they can update support for new threats.
-
Layer tools so your capabilities scale across devices, data types, use cases and budgets.
Final Thoughts from a Seasoned Investigator
Encryption has permanently changed digital forensics. As devices securing themselves by default with encryption proliferate, the likelihood of facing encrypted data has never been higher.
Robust and rapid decryption capabilities are now mandatory for forensic investigators that don‘t want to get left behind. Commercial solutions like Passware Kit form the backbone to deal with encryption at scale. Free software like MVT plug capability gaps around niche threats like mobile spyware.
But ultimately, there is no one-size-fits-all solution. Savvy investigators combine tools to match diverse needs and budgets. They think in layers, with each tool providing a set of capabilities to move the ball forward.
The suggestions provided are based on extensive field experience. I hope this guide better equips my fellow investigators to meet the encryption challenge. The right tools are out there – finding the optimal mix for your needs takes thought and experimentation. But the payoff for you and your cases will be immense.
Stay safe out there and happy hunting!