
Access to encrypted evidence
Passware decrypts storage media, containers, files and mobile devices – a tool that we at LanCologne regularly use in our own forensic investigations.
Encryption has long been the norm in criminal investigations
BitLocker on a laptop, FileVault on a Mac, a VeraCrypt container on an external hard drive, password-protected Office files and archives, encrypted backups, locked mobile phones: In almost every investigation, the first step in the analysis is to determine whether the seized data can be made readable at all.
This is precisely where Passware comes in. The company has been developing software for password recovery and the decryption of electronic evidence since 1998, and has offices in Mountain View (California) and Tallinn (Estonia). According to the manufacturer, the products are used by law enforcement and government agencies as well as by businesses.
We use Passware in our own investigations – and advise you on both practical use and choosing the right licence.
Typical use cases
- Access to encrypted storage media and containers when the password or recovery key is not available
- Opening password-protected individual files – Office documents, PDFs, archives, accounting and database files
- Analysis of password managers and key storage solutions to identify further points of access in the case
- Backing up and analysing the RAM of a running system before the device is switched off
- Unlocking and extracting data from mobile devices
- Access to cryptocurrency wallets as part of asset tracing investigations
- Lawful recovery of a company’s own data following the loss of login details

Passware Kit Mobile: Access via the manufacturer or by searching directly for the device model and chipset.
Passware Kit Forensic – the central working environment
Passware Kit Forensic is the core product and is described by the manufacturer as a comprehensive solution for locating and decrypting encrypted electronic evidence. The software automatically detects encrypted objects within a dataset, suggests the most promising course of action in each case, and processes entire exhibits in batches.
Range of functions
- Password recovery for over 420 file and object types
- Decryption of fully encrypted data storage media
- Live memory analysis to extract key data
- Batch processing of multiple files and media in a single run
- Automatic detection of encrypted objects and pre-selection of suitable attack vectors
- Resource Manager for controlling and monitoring computing resources
- Distributing the computing load across multiple systems using Passware Kit Agents
- Automatic updates; available for Windows and macOS
Supported objects (selection)
- Office and archives: Word, Excel, PowerPoint, Access, OneNote, Outlook, PDF, ZIP, RAR (2.0 to 7.x), 7-Zip, self-extracting archives
- Password manager: 1Password, KeePass, LastPass, Dashlane, Enpass, AxCrypt, macOS Keychain
- Accounting and databases: QuickBooks, Quicken, MS Money, MYOB, FileMaker Pro, Lotus applications
- Cryptocurrency wallets: Bitcoin Core, Electrum, Ethereum, Litecoin, Dogecoin, Dash
- Browser: Chrome, Firefox, Edge, Safari, Opera
- User accounts: Windows (NT to Windows 11), macOS, Unix/Linux
- Backups: Apple iTunes backups
Fully encrypted data storage devices
Passware Kit decrypts images of fully encrypted storage media and containers – including BitLocker and BitLocker To Go, Apple FileVault 2/APFS and Apple DMG, VeraCrypt and TrueCrypt, LUKS and LUKS 2, PGP WDE and Symantec Endpoint Encryption, McAfee Endpoint Encryption, DriveCrypt, Dell Data Protection, SanDisk PrivateAccess/SecureAccess and Steganos containers.
The state of the system at the time of seizure is crucial: if a memory dump is available that was created whilst the encrypted volume was mounted, Passware extracts the keys from it and decrypts the volume immediately – even if the system was locked. Hibernation files (hiberfil.sys) may also contain key material. If, on the other hand, the system is switched off and the volume is unmounted, the only option is the time-consuming method of a password attack.
This sequence immediately gives rise to a forensic recommendation: backing up the volatile memory on a running system should be the first step in any search, not the last.
Live Memory Analysis and Bootable Memory Imager
Passware Bootable Memory Imager boots from a USB drive in a UEFI-compatible manner and creates memory images of Windows, Linux and macOS computers; Macs with a T2 or M chip are excluded. The images are divided into 2-GB segments and saved alongside log files. The subsequent memory analysis scans the image for encryption keys and login credentials; memory images created by other tools can also be imported.
The manufacturer expressly points out that the procedure requires a hardware reset on the target system and that the presence of key material in the image cannot be guaranteed.
Passware Kit Mobile – Unlock and extract data from mobile devices
Passware Kit Mobile extracts and decrypts user data from mobile devices. According to the manufacturer, over 1,150 devices are supported: Apple devices as well as Android devices from brands including Samsung, Huawei, LG, Xiaomi, Lenovo, Nokia, Alcatel, Motorola, HTC, Meizu, Oppo, OnePlus, Sony, Vivo and ZTE.
- Bypassing or resetting pattern, PIN, password and alphanumeric lock codes
- Forensically sound full file system extraction
- Reading the iOS Keychain and passwords from 1Password and Dashlane
- Decryption of data from Second Space accounts, as well as from Signal and Wickr
- Accelerating code restoration with NVIDIA, AMD and Intel Arc graphics cards
- Multi-window mode for editing several devices at the same time
- Quarterly updates with devices added on an ongoing basis

Device search with a list of results and device specifications – in this case, the Huawei P30 with its platform and chipset.

Step-by-step guide for Apple devices: connection, recovery and DFU modes, data extraction, password recovery.

List of apps on an Android device: Device Code, Second Space, Signal, Android Wickr and 1Password – each with a complexity rating.

Results view: device code found, decrypted signal database with MD5 test value, details of passwords tested and elapsed time.
Device Decryption Add-on
This add-on extends Passware Kit to allow access to devices whose keys are hardware-bound:
- BitLocker volumes with TPM or fTPM
- Apple Macs with a T2 security chip (decryption of APFS images)
- Lenovo ThinkPads with TPM 2.0 (E, L, X, P and T series, manufactured between 2016 and 2020)
- Western Digital My Book and My Passport (2014 to 2024)
- Seagate and LaCie hard drives (2018 to 2022 models)
- Transcend SSDs with SM2320 controllers (2022 to 2025)
In addition, EFI firmware passwords on Macs can be recovered or reset. The add-on requires an active licence for Passware Kit Forensic or Ultimate; the manufacturer states that it supplies the software to law enforcement agencies and to businesses with a demonstrable need, and that each order is subject to manual verification.
Computing power and scalability
Password attacks involve computational work. Passware supports NVIDIA (GTX, Tesla), AMD and Intel Arc graphics cards with up to twelve GPUs per computer; the manufacturer states that this provides a speed boost of up to a factor of 1,200 compared with CPU-only operation. Rainbow tables are also available.
Two example figures from the manufacturer’s benchmark illustrate the difference: with BitLocker (AES-256) 7,312 passwords per second on an NVIDIA RTX 4090 compared with 7 passwords per second on the CPU; for macOS FileVault 2, 117,395 compared with 53 passwords per second.
Passware Kit Agents also allow the workload to be distributed across multiple Windows or Linux systems, as well as cloud instances on Amazon EC2 and Microsoft Azure. Each node utilises multiple CPUs and GPUs simultaneously; control and monitoring are handled via the integrated Resource Manager. Passware Kit Forensic includes five agents, whilst Passware Kit Ultimate includes ten.
Passware Kit Ultimate: Further Development and Certification
The complete package
Passware Kit Ultimate brings together the individual components: Passware Kit Forensic, Passware Kit Mobile, the Device Decryption Add-on, ten Passware Kit Agents and the Passware Kit Forensic Training. For workstations without an internet connection, the manufacturer also offers an Air-Gapped Edition.
Ongoing development
According to Passware, the company releases four major updates per year. Version 2026 v3, released on 23 July 2026, introduced, amongst other things, direct PIN recovery on TPM-protected BitLocker devices, support for the GNOME Keychain, enhanced Hashcat rules and a native beta version for Apple Silicon.
Training and Certification
With the Passware Certified Examiner (PCE), the manufacturer offers an English-language self-study course on the decryption of digital evidence: 16 video lessons totalling over ten hours, one year’s access, and a final exam comprising 63 questions with a pass mark of 80 per cent. The certificate is valid for two years.
How it fits into our toolkit
We use Passware as the tool for decryption, i.e. to access the data. The subsequent analysis of the content is carried out using the dedicated analysis tools provided by our other technology partners. This separation is deliberate: each step is carried out using the tool best suited to the task – thereby ensuring that each step remains individually traceable and documentable.
Manufacturer’s data sheets
Obtain Passware via LanCologne
You can obtain Passware licences via LanCologne. We can advise you on the most suitable edition, how it will work with your existing equipment and – if required – on its practical application in your current case.
Source & further information at:
Passware