Someone wrote in [info]jessekornblum,
Re: nvalid module [cryptoscan.py]
Hi,

I have been evaluating Volatility Framework and the cryptoscan plugin is a great development considering that it reveals the truecrypt passphrase.

Just would like to find out under what conditions would the cryptoscan plugin works? I have tested on a target system with a hidden volume created by truecrypt v6.2a. The acquired memory image is then loaded in Volatility with the cryptoscan plugin but there are no passphrases detected.


Advertisement


(Read 13 comments)

Post a comment in response:

From:
Help
Identity URL: 
Username:
Password:
Don't have an account? Create one now.
Subject:
No HTML allowed in subject
   Help
Message:

 
Notice! This user has turned on the option that logs IP addresses of anonymous posters. Help
Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…