
BSOD_bitlocker_recover
Carves BitLocker Volume Master Keys (VMKs) from memory dumps, disk images, and unallocated space for forensic decryption of encrypted volumes.
data-recoverydigital-forensicsdisk-forensics+3
26

Carves BitLocker Volume Master Keys (VMKs) from memory dumps, disk images, and unallocated space for forensic decryption of encrypted volumes.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.