The complete electronic evidence discovery solution

Passware Kit Forensic is the complete electronic evidence discovery solution that reports all the password-protected items on a computer and decrypts them. The software recognizes 280+ file types and works in batch mode recovering their passwords.

Password recovery for 280+ file types

MS Office, PDF, Zip and RAR, Quickbooks, FileMaker, Lotus Notes, Bitcoin wallets, Apple iTunes Backup, Mac OS X Keychain and many other popular applications.

Live Memory analysis

Analyzes live memory images, hibernation files and extracts encryption keys for FileVault2, TrueCrypt, VeraCrypt, BitLocker, logins for Windows & Mac accounts from memory images & hibernation files.

Cloud Data Acquisition

Acquires backups and data from cloud services (Apple iCloud, MS OneDrive, and Dropbox).

Mobile Forensics

Recovers passwords for Apple iPhone/iPad and Android backups as well as Android images and extracts data from images on Windows phones. Integrated with Oxygen Forensic Suite.

Hardware Acceleration

Accelerated password recovery with multiple computers, NVIDIA and AMD GPUs, Tableau Password Recovery, and Rainbow Tables.

Intelligent Detection

Detects all encrypted files and hard disk images and reports the type of encryption and the complexity of the decryption.

Linux Agent Ready

Run a portable Passware Kit Agent from a bootable Linux USB drive.

Decryption of FDE

Decrypts or recovers passwords for BitLocker, FileVault2, APFS, TrueCrypt, VeraCrypt, LUKS, McAfee, Apple DMG, Symantec and PGP disk images.

Detect encrypted files and containers

Find all the encrypted or password-protected documents, archives and other files. Sort by decryption complexity. Passware Kit Forensic detects 280+ file types.

Extract encryption keys and passwords from memory images

Quickly scan memory images and hibernation files. Extract encryption keys for FileVault 2, TrueCrypt, VeraCrypt and BitLocker for instant decryption of encrypted disks and containers. Build possible passwords dictionaries or extract account passwords for Windows and Mac.

Use hardware acceleration and distributed password recovery

Increase password recovery speed up to 400 times by using a single GPU (Graphics Processing Unit) card, and up to 3,200 times by using 8 GPUs in a single computer. Distribute password recovery tasks over a network of Windows or Linux computers for linear scalability.

Hardware Acceleration of Password Recovery Attacks

File Type Encryption CPU Speed
i5-4570
NVIDIA Speed
GTX 1080
AMD Speed
R9 Nano
MS Office 2013 or higher AES-256 78 10,378 5,157
TrueCrypt System (1-cascade) 591 565,823 300,463
RAR5 AES-256 98 47,329 31,303
iTunes Backup AES-256 2,006 153,978 92,467
BitLocker BitLocker 7 1,481 836
(passwords/second)

Network Distributed Password Recovery: Passware Kit Agent

Passware Kit Agent is a network distributed password recovery worker for Passware Kit Forensic. It runs on Windows (64-bit only) and Linux (64-bit only) and has linear performance scalability. Each computer running Passware Kit Agent supports multiple CPUs, GPUs, and TPR accelerators simultaneously. Passware Kit Forensic comes with 5 agents included with ability to purchase more separately as needed.