Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Promo2day Review Passware Kit Forensic 2020 Review
#1
[Image: uWmqg2Y.png]

Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer. The software recognizes 280+ file types and works in batch mode recovering passwords.

Homepage

https://www.passware.com/

Product page:

https://www.passware.com/kit-forensic/

Download Free Trial:

https://www.passware.com/try-free/

Link to the retail version will be sent to you after purchase together with the license key

Limitations of the demo version:

The demo version allows each of the attacks to work for up to 1 minute. For those passwords that can be recovered instantly, Passware Kit Demo displays the first 3 characters. Otherwise, Passware Kit Demo recovers passwords which are not longer than 3 characters. This feature does not work for all file types.
The demo version helps you to evaluate the product and check if your files are supported.

Minimum system requirements:

Microsoft Windows Vista, Server 2003/2008/2012, or Windows 7/8.x/10 (64-bit only) installed and configured on your system
1 GHz processor (2.4 GHz recommended)
512 MB of RAM (1 GB recommended)
150 MB of free hard disk space (more if you use custom dictionaries)
Passware software supports PC platforms only. However, it can recover passwords for some FileMaker files created on Macintosh. You can run Passware products on a Virtual PC or Parallels Desktop to unprotect your files. For Windows Key, a Windows Setup CD (32-bit or 64-bit) is required, as well as a burning CD-RW drive in order to record a password reset CD instead of the USB disk.

Current version:

2020.1.1

Release date : December 27, 2019

[Image: kYdhjEn.png]

Passware Kit Editions:

[Image: 6YddoGQ.png]
[Image: 7dDXdlI.png]

User Interface:

[Image: d7h4OrP.png]

Tools menu:

[Image: WSFuU06.png]

Help Menu:

[Image: pGqZFhl.png]

Features:

Detect encrypted files and containers

Find all encrypted or password-protected documents, archives, and other files. Sort by decryption complexity. Passware Kit Forensic detects 280+ file types.

[Image: DYTXKIq.png]

Extract encryption keys and passwords from memory images

Quickly scan memory images and hibernation files. Extract encryption keys for FileVault2, TrueCrypt, VeraCrypt, and BitLocker for instant decryption of disks and containers. Build password dictionaries or extract account passwords for Windows and Mac.

[Image: JvbKzNC.png]

Use hardware acceleration and distributed password recovery

Increase password recovery speed up to 400 times by using a single GPU (Graphics Processing Unit) card, and up to 3,200 times by using 8 GPUs in a single computer. Distribute password recovery tasks over a network of Windows or Linux computers, as well as Amazon EC2, for linear scalability.

[Image: q2SNYwD.png]

Passware Kit Forensic supports 280+ files

Passware Kit Forensic features instant decryption of BitLocker, TrueCrypt, FileVault2, and PGP hard disk images, accelerated password recovery for MS Office documents, and instant recovery of website passwords.

[Image: EVumJZt.png]

For the full list of file types; check here:

https://www.passware.com/kit-forensic/filetypes/

Hardware Acceleration of Password Recovery Attacks (in Passwords/second):

[Image: h511ahA.png]

Network Distributed Password Recovery: Passware Kit Agent:

[Image: b2DYJVM.png]

Passware Kit Agent is a network distributed password recovery worker for Passware Kit Forensic. It runs on Windows (64-bit only), Linux (64-bit only), and Amazon EC2, and has linear performance scalability. Each computer running Passware Kit Agent simultaneously supports multiple CPUs, GPUs, and TPR accelerators. Passware Kit Forensic comes with 5 agents included with ability to purchase more separately as needed.

New Features:

Passware Kit 2020 v1 introduces a built-in Dictionary Manager, support for VeraCrypt GPT system encryption, and optimized decryption process for hard drives.
The new version also extracts passwords from Windows 10/8 standalone systems protected with Windows Hello: PIN and Picture password.

Dictionary Manager
5 times faster on dictionary compilation
A new “Mixed order” option for “Join Attacks” group
Support for VeraCrypt GPT system encryption
Faster memory image analysis for VeraCrypt decryption
Instant BitLocker decryption with a known VMK
FileVault2: password hint extraction and support for recovery keys
Passwords extraction from Windows systems protected with PIN/Picture password

Dictionary Manager

[Image: oIztZbd.png]

Passware introduces a new built-in tool for managing dictionaries and wordlists used by the Dictionary attack. The tool allows users to compile custom dictionaries easily, sort, export, and import existing dictionaries, as well as edit, merge, and delete unnecessary dictionaries.

The Dictionary Manager also features a search option to locate a specific word in a dictionary file, and batch file processing.

Dictionary compilation is now up to 5x faster

We have updated the dictionary compilation algorithm, and it now works up to 5 times faster than before! For example, a 5 GB text file is now compiled by Passware Kit in less than 2 minutes. Multiple dictionaries can also be compiled in batch mode in the new Dictionary Manager.

A new “Mixed order” option for “Join Attacks” group

When joining attacks to recover different parts of a password, users can specify the order of attacks in the group: original, original and reverse, and mixed.

Support for VeraCrypt GPT system encryption

Passware Kit is now able to detect system partitions of Guid Partition Table (GPT) disks encrypted with VeraCrypt and further decrypt these by analyzing a corresponding memory image. Brute-force password recovery for such partitions is also supported.

Faster memory analysis process for VeraCrypt decryption

Passware Kit automatically detects the operating system by analyzing a memory image and runs only OS-specific processes for VeraCrypt key extraction, thereby reducing the time spent on decryption.

Instant BitLocker decryption with a known VMK

If a Volume Master Key is known or has been recovered previously, Passware Kit decrypts the given BitLocker volume instantly – no need to analyze the memory image again.

FileVault2: password hint extraction and support for recovery keys

Passware Kit now instantly extracts and displays password hints for FileVault2 accounts and recovers a system recovery key, if one exists. In case the recovery key is known, Passware Kit instantly decrypts the FileVault2 volume.

Passwords extraction from Windows systems protected with PIN/Picture password

Passware Kit adds support for Windows 10 and 8 standalone systems protected with Windows Hello: PIN or Picture password. It recovers the user PIN or Picture password and extracts passwords and other data from the registry.

Passware Kit Forensic 2020.1.1 changelog:

Bugfixes:
Dictionary Manager improvements
Resolved occasional error in Dictionary Manager during dictionary compilation
Some UI changes for Windows Hello passwords extraction
Resolved "Previous passwords" attack for some PGP WDE images
Resolved issue with BitLocker VMK Key not being saved after Passware Kit relaunch
No need to launch password recovery for LiveID accounts with PIN protection

Purchase and SMS subscription:

You can complete your purchase here:

https://www.passware.com/buy-all/

Software Maintenance and Support (SMS)

Protect your Passware investment by ensuring you have constant access to technical support and the latest product enhancements. Renewing your Software Maintenance and Support (SMS) makes certain you have the latest Passware Kit features – we issue four major releases and multiple minor updates each year.

https://www.passware.com/kit-forensic/sms/

SMS Subscription Benefits

Always up to date with automatic software updates
Special offers from Passware partners
Four major releases per yearDownload software anytime
Multiple minor updates and bug fixes
Additional dictionaries

Automatic updates enabled:

[Image: vCvctfp.png]

Start using Passware:

After Encryption Analyzer has listed the encrypted items, you can sort them according to their decryption complexity by clicking the “Recovery Complexity” column. The files are now sorted from “Instant Unprotection” all the way through to the “Brute-force – Slow” strategy. Now, you can start the password recovery process directly from Encryption Analyzer. Simply; select the files that you want to decrypt and click the “Recover Passwords” button, which initiates a batch password recovery process for each of the files.

[Image: YqCqD7L.gif]

You can also find images of hard disks encrypted with TrueCrypt, VeraCrypt, PGP, BitLocker, LUKS, etc. All you have to do is to make sure that the option “Scan for encrypted containers and disk images” is enabled

[Image: 7nLINPu.png]

The built-in incremental search option can be used to narrow down the set of files to work with. After the analyzer completed  the encrypted evidence, you can find and display files by name, encryption type, or decryption complexity.

[Image: 3HXJx3q.png]

Full Disk Encryption:

Passware Kit  Forensic decrypt hard disks encrypted with BitLocker, TrueCrypt, VeraCrypt, LUKS, FileVault2, McAfee EPE, DriveCrypt, and PGP. The program scans the physical memory image file  which was acquired while the encrypted disk was mounted, even if the target computer was locked then extracts all the encryption keys, and decrypts the given volume.

[Image: yvrtK0X.png]

Password Recovery Options:

You can use predefined settings, advanced customized settings or the run wizard and follow simple steps to start the recovery process. The recovery time depends on the password length and complexity

[Image: WFNxB30.png]

[Image: G5Io1Ci.png]

Export and import scan results

Using the built-in portable USB version, you can check any computer without installation to identify all encrypted items then export the results along with any files relevant to your work computer to perform batch decryption. You can easily save the scan results using the “Copy to Folder” option

Memory Analysis

[Image: cDG7HZx.png]

Passware Kit extracts multiple evidence types from memory images and hibernation files in a single streamlined process. The following data can be extracted: encryption keys for BitLocker, TrueCrypt, PGP, FileVault2, and other FDE; passwords for Windows and Mac users; passwords for websites; and many more

Windows Password Recovery:

[Image: STq0xj6.png]

With Passware Kit, you can reset a password for any local or Active Directory Administrator account. All versions of Windows and all Service Packs are supported. All passwords are reset instantly. The process is very easy and completed in two steps. First; create a password reset CD or USB image using windows password button on the main screen and burn it on a disk. Second; reset the password with the bootable CD or USB disk. That’s all!

Recover passwords for mobile and cloud backups and images:

The program can easily recover passwords from mobile and cloud backup and images. To start the password-recovery process, click Mobile and cloud on the Start Page, choose either the iPhone Backup or Android Backup option and locate your file. A brute-force password recovery process will start.

[Image: PiJm10Y.png]

Recover passwords for websites, email and network connections:

You can use this tool to recover lost passwords from websites, emails and network connections

[Image: DtwF3Ru.png]

Recover password from password managers:

For example; 1password, lastpass, keepass

[Image: 7nK5pAB.png]

Standalone system:

You can use passware to extract passwords of standalone system from external registry files

Passware Kit is the fastest decryption tool available,

This is because it applies all available computational resources for maximum efficiency. Passware Kit uses multiple CPUs, NVIDIA, and AMD GPUs; Decryptum and multiple computers (for both Passware Kit Forensic and Passware Kit Business). GPU (Graphics Processing Unit) cards accelerate password recovery up to 400 times versus CPU-only systems. Passware Kit supports all types of NVIDIA (GTX, Tesla) and AMD GPUs. Up to 12 GPUs are supported per host computer.

Password recovery performance:

[Image: 5mJLRtG.png]

[Image: dQwffR6.png]

Working with Passware Kit Portable


This is a very useful tool that will let you find encrypted files and recover lost passwords on other computers without installing the software. The Portable Version can be installed on any removable device, i.e., a USB drive or a CD (USB recommended), and then used directly from this device on a target computer. Passware Kit Portable does not modify settings or files on a target computer (registry records, patched or unprotected files, etc.). The process is very easy. Simply prepare a portable version on a CD or USB disk then run on the target computer

Program Options:

General:

[Image: JqNl5rg.png]

Folders:

[Image: HDeaeaE.png]

Updates:

[Image: DuniwEr.png]

Logs:

[Image: oeRbTZW.png]

Customer Experience:

[Image: A3IZM4R.png]

System Info:

[Image: Xc99yzO.png]

Password Exchange:

[Image: ddOxEPt.png]

[Image: zVHo30U.png]

Conclusion:

Passware Kit Forensic Lab is a complete encrypted evidence discovery and password cracking package for a forensic laboratory. It has many features and tools which will help you to easily decrypt windows, mobile, cloud images and backups and recover admin password. It supports 280 file types and is very fast. Passware Kit Forensic comes with 5 agents included
Reply
#2
Thanks Tarek, it’s really not easy to do such cool reviews.
Reply
#3
Thank you Tarek for another excellent and detailed review!
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Promo2day Review Passware Kit Forensic: encrypted electronic evidence discovery and decryption tarekma7 4 5,913 05-12-2022 , 08:03 PM
Last Post: tarekma7
  Promo2day Review Passware Kit Forensic 9.1 UPDATE: The complete electronic evidence discovery solution tarekma7 20 13,688 02-11-2020 , 01:43 PM
Last Post: ImnotwiththeFBI
  Snagit 2020 Review tarekma7 5 6,904 01-04-2020 , 01:42 PM
Last Post: baziroll
  Passware Kit Forensic tarekma7 11 10,585 05-25-2017 , 01:10 PM
Last Post: Mohammad
  Passware Kit Standard 2016 V.4 asus73 6 5,045 11-11-2016 , 11:07 PM
Last Post: baziroll



Users browsing this thread: 1 Guest(s)