Password Recovery User Guide
Password Recovery User Guide
USER GUIDE
Version 1.3
Copyright© 2017 Guidance Software, Inc. All rights reserved.
EnCase®, EnScript®, Tableau®, FastBloc®, Guidance Software® and EnCE® are registered trademarks or trademarks owned by
Guidance Software in the United States and other jurisdictions and may not be used without prior written permission. All other
marks and brands may be claimed as the property of their respective owners. Products and corporate names appearing in this
work may or may not be registered trademarks or copyrights of their respective companies, and are used only for identification
or explanation into the owners' benefit, without intent to infringe. Any use and duplication of this work is subject to the terms of
the license agreement between you and Guidance Software, Inc. Except as stated in the license agreement or as otherwise
permitted under Sections 107 or 108 of the 1976 United States Copyright Act, no part of this work may be reproduced, stored in a
retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or
otherwise. Product manuals and documentation are specific to the software versions for which they are written. For previous or
outdated versions of this work, please contact Guidance Software, Inc. at http://www.guidancesoftware.com. Information
contained in this work is furnished for informational use only, and is subject to change at any time without notice.
CONTENTS
CHAPTER 1 Overview 5
Overview 7
The Tableau Password Recovery System 7
The Tableau Password Recovery Software 7
Supported File Types 10
- iii -
Installing the Password Recovery Assistant 26
Verifying the Installation 27
Verifying Access to the Passware Decryption Server's Shared Folder 28
Installing Passware Kit Agent 29
Installing Passware Kit Agent 29
Configuring Passware Kit Agent 30
Verifying the Connection to the Passware Decryption Server 32
Verifying the Passware Kit Agent Hardware 33
Restoring Tableau Password Recovery to Factory Settings 34
CHAPTER 4 Support 47
Overview 49
Find Support Online 49
Access the Customer Community 50
View Customer Forums 51
Browse the Knowledge Base 51
Log and Track Issues 51
Register your Product 51
Register your Account 51
Contact Guidance Software 52
Contact Sales 52
Contact Customer Service 52
Contact Technical Support 53
Chat with a Technical Services Engineer 54
Index 55
- iv -
CHAPTER 1 Overview 5
CHAPTER 1
OVERVIEW
In this chapter
Overview 7
Overview
Tableau Password Recovery (TPR) recovers passwords of protected (encrypted) files,
partitions, or entire drive volumes that are part of your case or investigation. It is an integrated
solution that uses Passware Kit Forensic software and Tableau Accelerator 2 (TACC2) hardware
on a dedicated system to unlock password protected files.
TPR can also integrate directly with EnCase Forensic, EnCase Basic, EnCase Endpoint Security,
EnCase eDiscovery, and EnCase Endpoint Investigator. If your investigation includes a number
of files that are password protected, you can send one or more of these files, or their entire
Logical Evidence File (LEF), to the TPR server. After the passwords are recovered, the
passwords are returned to your EnCase Examiner computer, where they can be viewed along
with the original, encrypted files.
The TACC2 is an integrated circuit board that was purpose-built for accelerating password
decryption algorithms. Using the TACC2 hardware, TPR can decrypt passwords hundreds of
times faster than the process would take when using general purpose CPUs.
To further speed up the decryption process, you can add more TPR systems to your
configuration. Each additional TPR increases the speed of decryption linearly.
Note: If you are updating your TPR or TPR cluster to version 1.3, click here to
download the v1.3 installer and update instructions. To get full support for version
1.3, go to www.passware.com to update your licensed copy of PKF.
EnCase.
EnCase
*Passware Kit Provides Passware license information to the Password Recov-
Examiner
Forensic ery Assistant.
computer
Passware Primary Acts as a proxy and communicates with the Password Recovery
Decryption TPR sys- Assistant on the EnCase Examiner computer, and the Passware
Server tem agents on secondary TPR systems to decrypt passwords.
*You must purchase a Passware Kit Forensic license in addition to TPR if you do not
already own a copy.
The following diagrams show the relationship between the components in each configuration.
10 Tableau Password Recovery User Guide Version 1.3
l Android Image
l Apple FileVault 2
l Apple iOS Backup
l Apple OS X Keychain
l MS Office 2007, 2010, 2013, 2016
l PGP Disk 6
l PGP Self-Decrypting Archive (SDA)
l PGP Private Keyring
l PGP Whole Disk Encryption (WDE)
l RAR 3.x, 4.x, 5.x
l ZIP
l TrueCrypt
CHAPTER 2
INSTALLATION AND CONFIGURATION
In this chapter
Overview 13
Product Licensing 13
Installation Files 14
Overview
This chapter contains information on installing and configuring TPR. This includes installing and
configuring some or all of the following components, depending on your desired
configuration.
Refer to The Tableau Password Recovery Software for more information on the components
used in the standard TPR configurations. This guide currently only describes how to configure
and use TPR when TPR is integrated with EnCase.
Product Licensing
Before installing the TPR system and software, you need to obtain the product license keys for
Microsoft Windows and Passware.
If you cannot find your Passware Kit Forensic license, you can request a product key from
Passware Support at http://www.lostpassword.com/support/lost.htm. Enter Passware Kit
Forensic as your Product Name and enter the order number you received from the vendor
(Guidance Software, Passware, or an authorized Passware reseller) as your Order Reference
Number.
1. Install the server rack rails to the sides of the TPR system and mount it into a rack or cab-
inet.
2. Connect power, network, and a monitor and keyboard.
3. Power on TPR.
4. Follow the steps of the Windows setup procedure, during which you need to enter the
Windows License Key.
5. Configure the TPR network settings according to the network requirements. TPR can
operate using standard network configuration (such as a manual or dynamic IP address)
and either a Microsoft workgroup or domain.
1. Click the Windows Start button, right click This PC, and click Properties.
2. Under Windows activation, select Change product key.
3. Enter the product key.
Installation Files
Files for the installable TPR software components are located under
C:\Windows\TPR\Installers on the TPR system.
The following table includes the installation program for each component.
4. Click Next. When the installation completes, Passware Kit Forensic opens.
16 Tableau Password Recovery User Guide Version 1.3
Note: The TACC acceleration units are not available until Passware Kit Forensic is
running as administrator.
o The Advanced Sharing dialog displays. Click Permissions to determine who has
access to the folder.
CHAPTER 2 Installation and Configuration 19
o The Permissions dialog displays. Click Add to add the EnCase user.
20 Tableau Password Recovery User Guide Version 1.3
o The Select Users or Groups dialog displays. Enter the name of your EnCase user. If
necessary, click Check Names to search through the list of Windows users. When
you finish, click OK.
CHAPTER 2 Installation and Configuration 21
o On the Permissions dialog, check Full Control, then click Apply. When you finish,
click OK.
22 Tableau Password Recovery User Guide Version 1.3
1. Click Browse to select the Passware Decryption Server shared folder you created earlier. A
list of folders displays.
CHAPTER 2 Installation and Configuration 25
2. Select your shared folder from the list, then click OK. The dialog closes.
26 Tableau Password Recovery User Guide Version 1.3
3. Click Stop Server, then click Start Server to restart the Passware Decryption Server.
Before running the Password Recovery Assistant installation program, install Passware Kit
Forensic and the Microsoft .NET framework on the EnCase Examiner computer.
Select the following link to download the Microsoft .NET 4.5 installation program:
https://www.microsoft.com/en-us/download/details.aspx?id=30653.
Follow the steps of the installation program, which detects if the Microsoft .NET framework is
already installed.
3. Enter the EnCase installation directory as the Destination Location, then click Next.
4. The program installs the EnCase plugin.
4. Right click a document in your case or evidence folder. You should also see an option for
the Password Recovery Assistant.
28 Tableau Password Recovery User Guide Version 1.3
1. Log on to the EnCase Examiner computer with the Windows credentials you granted
access to the shared folder.
2. Click the Windows Start button, then click Computer.
3. In the tools menu, click Map Network Drive.
4. In the Drive box, click the drive letter you want to use. You cannot select a drive letter
already in use by your computer.
5. In the Folder box, enter both the name of the Password Recovery server and the shared
folder you created. The format is \\ComputerName\ShareName. For example, if the
name of the TPR system is pass0123 and the folder is DSShared, enter
\\pass0123\DSShared.
CHAPTER 2 Installation and Configuration 29
6. If you are not logged on to the EnCase Examiner computer with the Windows credentials
you granted to the shared folder, click Connect using different credentials, then enter
the appropriate username and password.
7. Click Finish.
The Passware Kit Agent receives decryption requests from the Passware Decryption Server. It
runs a parallel set of decryption algorithms for each file you submit for password recovery.
3. When the installation completes, check Run Passware Kit Agent and click Finish.
30 Tableau Password Recovery User Guide Version 1.3
Note: The TACC acceleration units are not available until Passware Kit Agent is
running as administrator.
2. The Passware Kit Agent attempts to connect to the Passware Decryption Sever. If it can-
not connect via auto discovery, click Manual connection and enter the hostname or IP
address of the Passware Decryption Server, then click Connect.
32 Tableau Password Recovery User Guide Version 1.3
When the Passware Kit Agent connects to the Passware Decryption Server, the status at the
bottom of the Settings dialog changes to Connected and idle.
2. Under Acceleration Units, check GPU device and Tableau TACC hardware accelerator(s)
for best performance.
Overview 39
Overview
This chapter describes how to use TPR to unlock files, partitions, and drive volumes (all of
which is simply referred to as "files" in this section), and recover passwords from EnCase.
1. Select the files you want to unlock from your EnCase investigation or case.
2. Invoke the Password Recovery Assistant to forward the request to Passware Kit Forensic
and the Decryption Server.
3. Monitor the progress of the password recovery.
4. Retrieve the output of the recovery process.
5. View the unlocked files and recovered passwords, along with the original, encrypted files.
Note: If the Protected File Analysis option was used during processing, the
Protection complexity column displays information about whether the file is
protected and the complexity of its encryption.
2. Right click the selected files, then select Password Recovery Assistant.
40 Tableau Password Recovery User Guide Version 1.3
o Password Recovery System URL is the URL of the Passware Decryption Server.
The format is http://<server_name>>:8000. Enter the host name or IP
address of the TPR system, followed by the Decryption Server's port number
(8000 by default).
o Dictionary Location allows you to specify a folder containing an encase-
4passware.xml file. You can create this file by using the Passware Export fea-
ture on the EnCase Tools menu. This option is available after the evidence has
been indexed, or after running Analyze EFS. You can create your own dictionary
or download a dictionary from the Internet. To add a custom dictionary, use the
Extra Data option in the Passware Export feature and browse to the location of
your custom dictionary.
o Attack Type specifies the thoroughness of the decryption process.
4. Click OK to submit your request to the Passware Decryption Server. The files are sub-
mitted and the Display Status screen displays.
o The Display Status screen provides information about each of the files you select
for password recovery. Full Path is the original location of the file.
o Press Refresh to retrieve the latest status information.
o To cancel password recovery for one or more files, check the box to the left of the
filename, then click Cancel Selected.
5. When the decryption process completes, click Retrieve Results. The Retrieve Results dia-
log displays.
o Check Open folder location to open the EnCase export folder where the files
were copied.
o Check Add results to current case to add the recovered files and passwords to
your case.
In the example below, the document word.doc was selected for decryption from the
PasswareSamples LEF.
CHAPTER 3 Recovering Passwords 43
After the password recovery process completes, a new LEF is added to the case. To view the
LEF added to the case, click View > Evidence. The Evidence tab displays.
To display an unlocked file and its recovered password, click its LEF.
If Passware is able to decrypt the file type, a copy of the unlocked/decrypted file is also present
in the LEF.
44 Tableau Password Recovery User Guide Version 1.3
To display the original file, right click the unlocked file in the Evidence tab and select Go to file.
Overview 49
Overview
Guidance Software is committed to providing our customers with the best user experience
possible. There are a variety of ways for you to get the help you need, when you need it.
l Technical Support
l Customer Service
l Sales
SALES
Links under Sales enable you to:
TECHNICAL SUPPORT
Links under Technical Support enable you to:
CUSTOMER SERVICE
Links under Customer Service enable you to:
In these forums you can learn from community members, ask questions, and share your
expertise with others.
The knowledge base is part of the Customer Community and may be accessed by navigating to
www.guidancesoftware.com/community.
If you have trouble downloading updates after registering, contact Technical Support.
Provide all requested information. This helps us identify you as a registered owner of a
Guidance Software product.
After submitting your form, you will receive an email. Once you have verified your email
address, your account will be reviewed and approved within 24 business hours.
Once your registration is approved, you can access the Customer Community by navigating to
www.guidancesoftware.com and clicking Support > Technical Support >
Customer Community.
l Contact Sales
l Contact Customer Service
l Contact Technical Support
Contact Sales
BY TELEPHONE:
626-229-9191
888-999-9712
BY ONLINE REQUEST:
Navigate to www.guidancesoftware.com and click Support > Sales to request a demo, speak to
a member of our sales team, or request a quote.
BY TELEPHONE:
626-463-7964 (Monday through Friday, 7 am to 5 pm, Pacific Time)
866-229-9199
CHAPTER 4 Support 53
BY ONLINE REQUEST:
Navigate to www.guidancesoftware.com and click Support > Customer Service > Contact.
UNITED STATES:
Phone: +1 (866) 973-6577 or (626) 463-7977
Fax: +1 (626) 229-9199
1055 E. Colorado Blvd.
Pasadena, CA 91106
UNITED KINGDOM:
Phone: +44 (0) 1753-552252, Option 4
Fax: +44 (0) 1753-552232
Thames Central, 5th Floor
Hatfield Road
Slough, Berkshire UK SL1 1QE
l Australia
l Belgium
l China-North
l China-South
l Denmark
l Finland
l France
l Germany
l Hong Kong
l Italy
l Japan
l Malaysia
l Netherlands
l New Zealand
l Norway
l Poland
54 Tableau Password Recovery User Guide Version 1.3
l Singapore
l South Korea
l Spain
l Sweden
On the Customer Community home page, open the left sidebar with the ALT + S keyboard
command, or by clicking the arrow in the left margin.
A
I
Access the Customer Com-
munity 50 Installation and
Configuration 11
Activating the Windows
License 14 Installation Files 14
Supported Files 10
M
Product Licensing 13 V
Support 47