Four tools, one case. Know which one to reach for first.
Elcomsoft Quick Triage, Elcomsoft System Recovery, Elcomsoft Forensic Disk Decryptor and Elcomsoft Distributed Password Recovery each solve a different stage of a desktop case. Answer a few questions about the machine in front of you and get an ordered, reasoned recommendation — plus the evidentiary best practices to keep it defensible.
Tell us about the machine in front of you
Four questions map directly onto the two things that actually decide tool order: is the machine on or off, and is there a key or not. Adjust any of them — the recommended pipeline below updates immediately.
Acquire, decrypt, recover
Read top to bottom it looks like three stages — but most cases end early. A live, unlocked machine with no encryption closes out after stage one. A container with a key in hand closes out after stage two. Only a case with no key and no shortcuts reaches the GPU-accelerated stage three.
Acquisition
Is the machine on or off?
Decryption
Is there a key, or not?
Recovery
What's left to attack?
Elcomsoft System Recovery and Elcomsoft Quick Triage both collect artifacts, and that's deliberate, not redundant. Elcomsoft System Recovery works from outside a booted OS — machine off, or no working credentials. Elcomsoft Quick Triage works from inside a live session — machine on and unlocked. The choice is made by how the machine was found, not by which tool happens to be on the shelf.
What each tool actually does
Four purpose-built stages of the same job, designed to hand off to each other without reformatting anything in between.
Situation at the scene → tool → output
The same logic the case advisor above runs on, condensed to a lookup table for when you already know the situation.
| Situation at the scene | Reach for | What you get out |
|---|
Fast doesn't mean undisciplined
Whichever tool is running, the same evidence-handling principles apply from first contact — triage does not get a pass on custody discipline just because it's quick.