Elcomsoft System Recovery
$500.00
Elcomsoft System Recovery resets forgotten passwords with a new password supplied by you, allowing for immediate login without the time-consuming password
Description
Elcomsoft System Recovery reset or recover passwords to local Windows accounts and Microsoft Account in all versions of Windows. Assign administrative privileges to any user account, reset expired passwords or export password hashes for offline recovery. Create forensic disk images. Supplied with bootable Windows PE environment.
- Perform forensically sound extractions
- Reset passwords to Windows accounts
- Extract encryption metadata from TrueCrypt, VeraCrypt, Bitlocker, FileVault (HFS+/APFS), PGP Disk, LUKS and LUKS2 encrypted disks
- Create forensic disk images
- Recover passwords to local accounts, Microsoft Accounts and Wi-Fi networks
- Customized Windows PE environment with broad hardware compatibility and genuinely native FAT and NTFS support
Supports: Windows 7, 8, 8.1, Windows 10, Windows 11; Windows Vista, Windows XP, Windows 2000, Windows NT; all relevant Windows Server versions including Windows Server 2025; 32-bit and 64-bit systems; Windows PE with 32-bit and 64-bit UEFI and legacy BIOS configurations; familiar Windows GUI; SAM/SYSTEM and Active Directory.
password recovery tool New features
Windows Server 2025 Support
Elcomsoft System Recovery now supports the latest Windows Server 2025. Investigators can now access and analyze Active Directory database (ntds.dit), enabling access to user credentials and directory data from the new OS. In addition, BitLocker keys discovered in the Windows Server 2025 Active Directory database can now be exported.
SRUM Database Support
The Forensic Tools section now includes support for the Windows System Resource Usage Monitor (SRUM) database, providing direct access to detailed records of application launches, network activity, and system resource usage. The tool parses the binary SRUM database and presents the data in a human-readable form for viewing or exporting.
Expanded Password Recovery Capabilities
Several attacks are now available for recovering passwords to user accounts, including Brute Force, Dictionary, Mask, Word, Combined Dictionary, Rule-Based Dictionary (Hybrid), and Group attacks. The newly implemented “group” attack automatically runs a sequence of targeted mini attacks against the most common password types, including those already recovered from the system.
Forensically Sound Extractions, Verifiable Disk Imaging
When accessing a locked system during an in-field investigation, speed is often the most important factor. However, maintaining digital chain of custody is crucial when producing court admissible evidence. Elcomsoft System Recovery contains features to help establish and maintain digital chain of custody throughout the investigation.
In order to preserve digital evidence, the chain of custody begins from the first point of data collection. Elcomsoft System Recovery employs a forensically sound workflow to ensure that digital evidence collected during the investigation remains court admissible. The workflow implements read-only, write-blocking access to the target computer, and saves collected evidence in the form of digitally signed, verifiable disk images, making Elcomsoft System Recovery a viable alternative to hardware-based write blocking disk imaging devices while offering real-time access to crucial evidence.

You must be logged in to post a review.

Reviews
There are no reviews yet.