Elcomsoft System Recovery 8.38: Built-In BitLocker TPM Exploit Library, Browser Artefact Extraction, and Imaging Checksums

Elcomsoft System Recovery, a bootable digital triage tool, now offers to build you a second USB flash drive for a BitLocker exploit during installation. Version 8.38 supports two exploits this way, YellowKey and GreatXML. The release also adds checksum logging for disk images and updates the imaging library.

What this actually does

Elcomsoft System Recovery's installer can now build you a second bootable USB drive, separate from Elcomsoft System Recovery's own boot media, preloaded with the BitLocker TPM exploit of your choice, YellowKey or GreatXML. This turns a manual job of looking for and downloading the exploit, formatting a drive, setting it up as bootable media, into a couple of clicks during setup.

Call it preliminary support: the drive is ready to go, but running the exploit itself still follows the instructions published by its developers; we provide a copy with each exploit. Success also depends on the target machine's TPM and firmware.

Background

Windows can bind a BitLocker volume to the TPM alone, which the weakest protection setting but still default on many end-user desktops and laptops; corporate laptops are typically configured with TPM+PIN, and those exploits are not applicable. TPM stands for Trusted Platform Module, a security chip (or firmware equivalent on newer machines) that holds the encryption key and releases it to the CPU automatically at boot. In TPM-only configuration the PC boots straight to the login screen with no extra prompt for the user.

Browser extraction, imaging checksums, and more

This update adds the ability to extract browser artefacts from popular web browsers, including saved passwords, payment card data, form autofill data, download history, bookmarks, and browsing history. The new tool supports Google Chrome, other Chromium-based browsers, Microsoft Edge, Mozilla Firefox, and more.

Every disk image Elcomsoft System Recovery creates now gets a checksum, logged with the image path and capture time. Previously this meant running a separate hashing utility after the fact. In addition, Elcomsoft System Recovery 8.38 updates the underlying disk imaging library. This is a bugfix, not a feature; if you were seeing instability during imaging on earlier builds, this release addresses it.

Elcomsoft System Recovery 8.38 is available for immediate download.

About Elcomsoft System Recovery

Elcomsoft System Recovery is a portable field analysis tool for computer forensics. Built as a forensically sound computer analysis tool, it lets investigators make real-time decisions in the field. The Windows-based bootable environment gives quick access to digital evidence, with support for all Windows native file systems and a wide range of computer hardware.

Designed for field deployment, Elcomsoft System Recovery comes as a pre-configured tool built on top of the supplied Windows PE environment. It includes disk imaging and system management tools, plus a two-panel file manager for navigating the file system. The goal is rapid data collection and secure disk imaging without turning triage into a multi-tool exercise.

Elcomsoft System Recovery 8.38 release notes:

  • New feature: extracts passwords, download history, stored payment cards, bookmarks, forms, and browsing history from a range of web browsers
  • BitLocker: installer can now create a separate USB drive preloaded with a BitLocker TPM exploit, YellowKey or GreatXML
  • Disk imaging: added checksum logging for captured disk images
  • Bugfix: updated the disk imaging library

Siehe auch