Difference between revisions of "BitLocker Disk Encryption"
From Forensics Wiki
m (BitLocker moved to BitLocker Disk Encryption) |
|||
| Line 1: | Line 1: | ||
| − | BitLocker is a [[Microsoft]] [[Full Volume Encryption]] solution first included with the Enterprise and Ultimate editions of [[Windows|Windows Vista]]. | + | '''BitLocker Disk Encryption''' is a [[Microsoft]] [[Full Volume Encryption]] solution first included with the Enterprise and Ultimate editions of [[Windows|Windows Vista]]. |
== Indicator == | == Indicator == | ||
| Line 12: | Line 12: | ||
== See Also == | == See Also == | ||
| + | [[BitLocker To Go]] | ||
[[Defeating Whole Disk Encryption]] | [[Defeating Whole Disk Encryption]] | ||
== External Links == | == External Links == | ||
| − | * Conducting forensic analysis on BitLocker protected volumes was discussed in the paper [http://jessekornblum.com/ | + | * Conducting forensic analysis on BitLocker protected volumes was discussed in the paper [http://jessekornblum.com/publications/di09.html Implementing BitLocker for Forensic Analysis]. |
* [http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption Wikipedia entry on BitLocker] | * [http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption Wikipedia entry on BitLocker] | ||
* [http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true Microsoft's Step by Step Guide] | * [http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true Microsoft's Step by Step Guide] | ||
Revision as of 21:00, 12 February 2009
BitLocker Disk Encryption is a Microsoft Full Volume Encryption solution first included with the Enterprise and Ultimate editions of Windows Vista.
Contents |
Indicator
Drives protected with BitLocker will have a different signature than the standard NTFS header. Instead, they have in their first sector:EB 52 90 2D 46 56 45 2D 46 53 2Dor, in ASCII,
eR -FVE-FS-
Algorithm
The program uses either 128 or 256 AES with an elephant diffuser. See the links section for full details.
Recovery Keys
See Also
BitLocker To Go Defeating Whole Disk Encryption
External Links
- Conducting forensic analysis on BitLocker protected volumes was discussed in the paper Implementing BitLocker for Forensic Analysis.
- Wikipedia entry on BitLocker
- Microsoft's Step by Step Guide
- Microsoft Technical Overview
- Microsoft FAQ
- Microsoft Description of the Encryption Algorithm
- Cold Boot Attacks, Full Disk Encryption, and BitLocker