McAfee Endpoint Encryption

66 views
Skip to first unread message

Mike McC (GM)

unread,
Mar 1, 2010, 3:52:07 PM3/1/10
to Data Recovery
Does anyone know of any software that can recover data on a drive that has McAfee Endpoint Encryption?
 

Mike McCauley

Certified Data Recovery Expert

UltraTech Resources

16401 Swingley Ridge Road, Suite 250
Chesterfield, MO 63017

 

Adrian

unread,
Mar 3, 2010, 4:57:02 AM3/3/10
to DataRecoveryCertification
You will never recover encrypted data sorry to say :(

On Mar 2, 7:52 am, "Mike McC \(GM\)" <stew...@gmail.com> wrote:
> Does anyone know of any software that can recover data on a drive that has McAfee Endpoint Encryption?
>
> Mike McCauley
>
> Certified Data Recovery Expert
>
> UltraTech Resources
>
> 16401 Swingley Ridge Road, Suite 250
> Chesterfield, MO 63017
>

> Phone:              636-594-2004        636-594-2004ext 102www.datarecoverystl.com

Tim Farren

unread,
Mar 3, 2010, 7:42:53 AM3/3/10
to datarecovery...@googlegroups.com
Really? Not even with knowledge of the password?

Tim Farren
Farren Technology Group, Inc.
(904) 233-1982 Cell
(904) 233-5876 Office

> --
> You received this message because you are subscribed to the Google
> Groups "DataRecoveryCertification" group.
> To post to this group, send email to datarecovery...@googlegroups.com
> .
> To unsubscribe from this group, send email to datarecoverycertif...@googlegroups.com
> .
> For more options, visit this group at http://groups.google.com/group/datarecoverycertification?hl=en
> .
>

Madmex

unread,
Mar 3, 2010, 10:33:20 AM3/3/10
to datarecovery...@googlegroups.com
Recovery takes two different meanings here depending on what the end goal is. 

In the idea of physical data recovery, we really don't care if the data is encrypted, decrypted, HFS, XFS, ZFS, or XYZ.  Bits are bits, and recovery of the data to another disk or image file is considered successful when the transfer completes, well, successfully.

In terms of products like PointSec, McAfee Endpoint, Credant, even Microsoft EFS etc.. All of these products encrypt the data on the disk, either in whole or in part, which brings us to phase two, reading "legible" data and extracting files for the customer.  Well, that's when you get into the "software translation" bit.. since you now need a utility that can read that file system, and in some cases the specific kinds of files right?

Disk encryption is the same thing.. once you recover the drive (the one's and zero's so to speak), it will be time to decrypt the data and get the files that were the end goal of the data recovery, and that person might not be you... Your goal was to just get them back a disk image they could take back to their decryption key admin.

So, based on my definitions above, I will have to respectfully disagree.  DATA recovery in terms of bits  is possible on an encrypted disk.  FILE recovery is not, unless you have the appropriate decryption mechanism and password.

Karlo Arozqueta
Vicious Data Recovery Services

Tim Farren

unread,
Mar 3, 2010, 10:35:27 AM3/3/10
to datarecovery...@googlegroups.com
Karlo, well said. 


Tim Farren
Farren Technology Group, Inc.

Casper Madsen

unread,
Mar 3, 2010, 10:37:55 AM3/3/10
to datarecovery...@googlegroups.com
I agree with Madmex. That said I wasn't able to find any programs with a google search. Sorry

2010/3/3 Tim Farren <t...@farrentech.com>



--
Med venlig hilsen
Casper Madsen

Bud

unread,
Mar 4, 2010, 9:37:48 AM3/4/10
to DataRecoveryCertification
McAfee isn't supported by Encase for decryption. We've had several
disks with encryption through for recovery. As a general rule if it is
full disk encryption with preboot authentication, if you attempt to
boot to the disk and do not get a prompted to enter the user and
password for the decryption, then it is pretty much game over. This
indicates the kernel code for the Encryption software is corrupt. If
the customer created a kernel recovery disk, most of the encyption
vendors offer an emergency recovery or emergency unencrypt disk.
These all count on the encyption portion of the disk being intact, or
replacing that code with teh backup specific for that disk.

> >>>> <http://102www.datarecoverystl.com>102www.datarecoverystl.com


>
> >>> --
> >>> You received this message because you are subscribed to the Google Groups
> >>> "DataRecoveryCertification" group.
> >>> To post to this group, send email to
> >>> <datarecovery...@googlegroups.com>
> >>> datarecovery...@googlegroups.com.
> >>> To unsubscribe from this group, send email to

> >>> <datarecoverycertification%2Bunsu...@googlegroups.com>


> >>> datarecoverycertif...@googlegroups.com.
> >>> For more options, visit this group at
> >>> <http://groups.google.com/group/datarecoverycertification?hl=en>
> >>>http://groups.google.com/group/datarecoverycertification?hl=en.
>
> >> --
> >> You received this message because you are subscribed to the Google Groups
> >> "DataRecoveryCertification" group.
> >> To post to this group, send email to
> >> <datarecovery...@googlegroups.com>
> >> datarecovery...@googlegroups.com.
> >> To unsubscribe from this group, send email to

> >> <datarecoverycertification%2Bunsu...@googlegroups.com>


> >> datarecoverycertif...@googlegroups.com.
> >> For more options, visit this group at
> >> <http://groups.google.com/group/datarecoverycertification?hl=en>
> >>http://groups.google.com/group/datarecoverycertification?hl=en.
>
> >  --
> > You received this message because you are subscribed to the Google Groups
> > "DataRecoveryCertification" group.
> > To post to this group, send email to
> > datarecovery...@googlegroups.com.
> > To unsubscribe from this group, send email to
> > datarecoverycertif...@googlegroups.com.
> > For more options, visit this group at
> >http://groups.google.com/group/datarecoverycertification?hl=en.
>
> >  --
> > You received this message because you are subscribed to the Google Groups
> > "DataRecoveryCertification" group.
> > To post to this group, send email to
> > datarecovery...@googlegroups.com.
> > To unsubscribe from this group, send email to

> > datarecoverycertif...@googlegroups.com<datarecoverycertification%2Bunsu...@googlegroups.com>

Mike McC (GM)

unread,
Mar 4, 2010, 9:42:53 AM3/4/10
to DataRecoveryCertification
Thanks Bud,
That explained a lot. Good stuff to know.

mike

--------------------------------------------------
From: "Bud" <b...@reclamere.com>
Sent: Thursday, March 04, 2010 8:37 AM
To: "DataRecoveryCertification" <datarecovery...@googlegroups.com>
Subject: Re: McAfee Endpoint Encryption

Jim Murray

unread,
Mar 13, 2010, 9:26:57 AM3/13/10
to datarecovery...@googlegroups.com
Bud,
 
This is not entirely true.  If you purchased the Encase Decryption Suite, Encase does have the ability to decrypt a Mcafee encrypted drive as well as Utimaco, Bitlocker, PGP and others.  There is an additional cost for the Encase Decryption Suite, but it does support Mcafee.
 
Jim 

"Always be alert...America needs more lerts"
Kidd - The Fool's Run - John Sandford

Bud

unread,
Mar 14, 2010, 10:22:00 AM3/14/10
to DataRecoveryCertification
We have the EDS module, but according to Encase, the McAfee endpoint
is not supported. http://www.encaseenterprise.com/products/ef_modules.asp
We have used it on Utimaco/Sophos and PCGuardian/GuardianEdge but
never on McAfee.
The module manual does list McAfee safeboot as supported - which isn't
mentioned in the Matrix or the page above... good marketing!
I have a McAfee Endpoint encrypted drive in for a customer right now,
so I may have to try it again to test it once more. Normally for this
curomer we just recover the encrypted drive and return to them for
decryption.

> > > >>> <datarecoverycertification%2Bunsu...@googlegroups.com<datarecoverycertification%252Buns...@googlegroups.com>


>
> > > >>> datarecoverycertif...@googlegroups.com<datarecoverycertification%2Bunsu...@googlegroups.com>
> > .
> > > >>> For more options, visit this group at

> > > >>> <http://groups.google.com/group/datarecoverycertification?hl=en>
> > > >>>http://groups.google.com/group/datarecoverycertification?hl=en.
>
> > > >> --
> > > >> You received this message because you are subscribed to the Google
> > Groups
> > > >> "DataRecoveryCertification" group.
> > > >> To post to this group, send email to
> > > >> <datarecovery...@googlegroups.com>
> > > >> datarecovery...@googlegroups.com.
> > > >> To unsubscribe from this group, send email to

> > > >> <datarecoverycertification%2Bunsu...@googlegroups.com<datarecoverycertification%252Buns...@googlegroups.com>


>
> > > >> datarecoverycertif...@googlegroups.com<datarecoverycertification%2Bunsu...@googlegroups.com>
> > .
> > > >> For more options, visit this group at

> > > >> <http://groups.google.com/group/datarecoverycertification?hl=en>
> > > >>http://groups.google.com/group/datarecoverycertification?hl=en.
>
> > > >  --
> > > > You received this message because you are subscribed to the Google
> > Groups
> > > > "DataRecoveryCertification" group.
> > > > To post to this group, send email to
> > > > datarecovery...@googlegroups.com.
> > > > To unsubscribe from this group, send email to

> > > > datarecoverycertif...@googlegroups.com<datarecoverycertification%2Bunsu...@googlegroups.com>
> > .
> > > > For more options, visit this group at
> > > >http://groups.google.com/group/datarecoverycertification?hl=en.
>
> > > >  --
> > > > You received this message because you are subscribed to the Google
> > Groups
> > > > "DataRecoveryCertification" group.
> > > > To post to this group, send email to
> > > > datarecovery...@googlegroups.com.
> > > > To unsubscribe from this group, send email to
> > > > datarecoverycertif...@googlegroups.com<datarecoverycertification%2Bunsu...@googlegroups.com>

> > <datarecoverycertification%2Bunsu...@googlegroups.com<datarecoverycertification%252Buns...@googlegroups.com>


>
> >  > > .
> > > > For more options, visit this group at
> > > >http://groups.google.com/group/datarecoverycertification?hl=en.
>
> > > --
> > > Med venlig hilsen
> > > Casper Madsen
>
> > --
> > You received this message because you are subscribed to the Google Groups
> > "DataRecoveryCertification" group.
> > To post to this group, send email to
> > datarecovery...@googlegroups.com.
> > To unsubscribe from this group, send email to
> > datarecoverycertif...@googlegroups.com<datarecoverycertification%2Bunsu...@googlegroups.com>
> > .
> > For more options, visit this group at
> >http://groups.google.com/group/datarecoverycertification?hl=en.
>
> --

Jim Murray

unread,
Mar 15, 2010, 2:01:27 PM3/15/10
to datarecovery...@googlegroups.com
Ahh, I didnt see that before.  I think that it may be a case of poor content management on Guidance's part.  If you look at this link:
 
 
Which you can get to by browsing to the home page, select Products/Encase Forensic.  From that page, on the right hand side, expand the modules/add ons section and choose Encase Decryption Suite.
 
On this page it lists what appears to be a more updated list of all of the technologies that Encase supports.  It appears that your link is an older link as it has the old look and feel of the Guidance site.  Also if you go to http://www.encaseenterprise.com they now redirect you to the Guidance Software home page.
 
Jim
 

 
To unsubscribe from this group, send email to datarecoverycertif...@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages