<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post1665360859047961274..comments</id><updated>2011-05-31T02:26:44.407-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Additional Bitlocker Incident Response tips</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/1665360859047961274/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5571204221818872678</id><published>2009-06-09T23:07:13.797-07:00</published><updated>2009-06-09T23:07:13.797-07:00</updated><title type='text'>Thanks for sharing this informative and useful pos...</title><content type='html'>Thanks for sharing this informative and useful post with us. Good work.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/5571204221818872678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/5571204221818872678'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1244614033797#c5571204221818872678' title=''/><author><name>Computer Repair</name><uri>http://www.support1000.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1787317270'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8131509106954208720</id><published>2008-12-02T20:01:00.000-08:00</published><updated>2008-12-02T20:01:00.000-08:00</updated><title type='text'>Ummmm...just one small point...if you have logged ...</title><content type='html'>Ummmm...just one small point...if you have logged onto the machine enough to be able to run these commands and view the hard disks??? Who cares? You can access it already!?? Haven't you? Or can bitlocker be locked down to files and folders? I thought the whole point of bitlocker was that someone couldn't steal your PC and image it or remove the HD as THE WHOLE DISK was encrypted...&lt;BR/&gt;&lt;BR/&gt;If you can log into the PC then bitlocker is over. You now can access anything? Right??</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/8131509106954208720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/8131509106954208720'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1228276860000#c8131509106954208720' title=''/><author><name>Lee</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-993194541'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2789662705157727298</id><published>2008-05-20T15:54:00.000-07:00</published><updated>2008-05-20T15:54:00.000-07:00</updated><title type='text'>Troy:&lt;br&gt;&lt;br&gt;Because the BitLocker applet will cre...</title><content type='html'>Troy:&lt;BR/&gt;&lt;BR/&gt;Because the BitLocker applet will create a file that will take all of UAC - 10GB. That file will be skipped. This is done so the sectors will be "LOCKED" down</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/2789662705157727298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/2789662705157727298'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1211324040000#c2789662705157727298' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-303771161'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8390700946584774849</id><published>2008-05-19T20:14:00.000-07:00</published><updated>2008-05-19T20:14:00.000-07:00</updated><title type='text'>How is it that unallocated space is not decrypted ...</title><content type='html'>How is it that unallocated space is not decrypted when BitLocker encrypts at the sector level and has absolutely no idea of what sectors are in allocated clusters and those that are not?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/8390700946584774849'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/8390700946584774849'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1211253240000#c8390700946584774849' title=''/><author><name>Troy</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-413942200'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8488383888122269832</id><published>2008-04-25T18:59:00.002-07:00</published><updated>2008-04-25T18:59:00.002-07:00</updated><title type='text'>Sorry for the double post - dunn how that happened...</title><content type='html'>Sorry for the double post - dunn how that happened.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/8488383888122269832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/8488383888122269832'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1209175140002#c8488383888122269832' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1457673095'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6919031151632178839</id><published>2008-04-25T18:59:00.001-07:00</published><updated>2008-04-25T18:59:00.001-07:00</updated><title type='text'>Yes - if you are on a live vista machine, you coul...</title><content type='html'>Yes - if you are on a live vista machine, you could just acquire the data from there ( und the acquisition program from a removable disk). Not perfect forensically and you'll have to have admin rights - thanks to UAC.&lt;BR/&gt;&lt;BR/&gt;But your description of Vista/Bitlocker is right on and an excellen resource. &lt;BR/&gt;Thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/6919031151632178839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/6919031151632178839'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1209175140001#c6919031151632178839' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1264677502'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2817727742487341878</id><published>2008-04-25T18:59:00.000-07:00</published><updated>2008-04-25T18:59:00.000-07:00</updated><title type='text'>Yes - if you are on a live vista machine, you coul...</title><content type='html'>Yes - if you are on a live vista machine, you could just acquire the data from there ( und the acquisition program from a removable disk). Not perfect forensically and you'll have to have admin rights - thanks to UAC.&lt;BR/&gt;&lt;BR/&gt;But your description of Vista/Bitlocker is right on and an excellen resource. &lt;BR/&gt;Thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/2817727742487341878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/2817727742487341878'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1209175140000#c2817727742487341878' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1901147880'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5997381262057255612</id><published>2008-04-24T10:55:00.000-07:00</published><updated>2008-04-24T10:55:00.000-07:00</updated><title type='text'>Anonymous, thanks for your comments and observatio...</title><content type='html'>Anonymous, thanks for your comments and observations.&lt;BR/&gt;&lt;BR/&gt;A couple of comments: I never recommended REMOVING" Bitlocker since that will severely alter the data and there are other workarounds that will work and there is no reason to decrypt the volume since you can make a image of the decrypted data using other methods.&lt;BR/&gt;&lt;BR/&gt;I am not sure what you mean by "you can just analyze/preview the live system?" Are you saying thats all you can do? or are you saying that you can perform an analysis on the live running machine?&lt;BR/&gt;&lt;BR/&gt;I concur with your observations of unallocated space.&lt;BR/&gt;&lt;BR/&gt;Thanks again for your comments.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/5997381262057255612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/5997381262057255612'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1209059700000#c5997381262057255612' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9186148309861503402</id><published>2008-04-24T10:43:00.000-07:00</published><updated>2008-04-24T10:43:00.000-07:00</updated><title type='text'>You can just analyze/preview the live system. Also...</title><content type='html'>You can just analyze/preview the live system. Also, most BitLocker intallations just use the TPM and NOT the PIN/USB modes.&lt;BR/&gt;&lt;BR/&gt;Also, when BitLocker gets installed, all the unallocated space (minus 10 GB) gets filled with encrypted 'W'. So these sectors show that they have not been written to since that point!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/9186148309861503402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/9186148309861503402'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1209058980000#c9186148309861503402' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1948704822'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3321404495508624936</id><published>2008-04-24T10:34:00.000-07:00</published><updated>2008-04-24T10:34:00.000-07:00</updated><title type='text'>I meant that when bitlocker is REMOVED so that you...</title><content type='html'>I meant that when bitlocker is REMOVED so that you can forensically analyze the disk everything but unallocaed will get decrypted and the key blob deleted.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/3321404495508624936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/3321404495508624936'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1209058440000#c3321404495508624936' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1190391043'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3840531584730831268</id><published>2008-04-22T20:18:00.000-07:00</published><updated>2008-04-22T20:18:00.000-07:00</updated><title type='text'>You are correct, EnCase can handle Bitlocker as lo...</title><content type='html'>You are correct, EnCase can handle Bitlocker as long as you have the recovery password or key protector AND you must have the EDS module.&lt;BR/&gt;&lt;BR/&gt;When you disable bitlocker NOTHING gets decypted, not unallocated space or allocated space, everything remains encrypted. The only difference is that the key is stored on the drive so that you dont need to present the key from the USB in order to boot. The encryption keys are not wiped, enabling Bitlockler using the same methods I described, restored Bitlocker back to the previous state requiring the USB startup key or recovery password in order to boot the OS.&lt;BR/&gt;&lt;BR/&gt;I highly suggest using EnCase, if you have it and the EDS module, but the other techniques were presented as alternatives in case you do not.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/3840531584730831268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/3840531584730831268'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1208920680000#c3840531584730831268' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6266649268911361066</id><published>2008-04-22T12:47:00.000-07:00</published><updated>2008-04-22T12:47:00.000-07:00</updated><title type='text'>EnCase can handle BitLocker just fine.&lt;br&gt;&lt;br&gt;Also...</title><content type='html'>EnCase can handle BitLocker just fine.&lt;BR/&gt;&lt;BR/&gt;Also, when you disable BitLocker through Vista, the unallocated space will NOT get decrypted! Furthermore the encryption keys get wiped.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/6266649268911361066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1665360859047961274/comments/default/6266649268911361066'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html?showComment=1208893620000#c6266649268911361066' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/04/additional-bitlocker-incident-response.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1665360859047961274' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1665360859047961274' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1356030371'/></entry></feed>
