ElcomSoft Desktop Forensic Bundle

Four tools, one case. Know which one to reach for first.

Elcomsoft Quick Triage, Elcomsoft System Recovery, Elcomsoft Forensic Disk Decryptor and Elcomsoft Distributed Password Recovery each solve a different stage of a desktop case. Answer a few questions about the machine in front of you and get an ordered, reasoned recommendation — plus the evidentiary best practices to keep it defensible.

Case Advisor

Tell us about the machine in front of you

Four questions map directly onto the two things that actually decide tool order: is the machine on or off, and is there a key or not. Adjust any of them — the recommended pipeline below updates immediately.

Machine state at the scene
Are encrypted volumes, containers or VMs involved?
Is a decryption key or password available?
Only matters if encryption is involved — leave as-is otherwise.
What do you ultimately need out of this case?
Select as many as apply — a single case often needs more than one.
Recommended pipeline
Three Stages, One Pipeline

Acquire, decrypt, recover

Read top to bottom it looks like three stages — but most cases end early. A live, unlocked machine with no encryption closes out after stage one. A container with a key in hand closes out after stage two. Only a case with no key and no shortcuts reaches the GPU-accelerated stage three.

1

Acquisition

Is the machine on or off?

On, unlocked → Elcomsoft Quick Triage
Off / no login → Elcomsoft System Recovery
2

Decryption

Is there a key, or not?

Key in hand → Elcomsoft Forensic Disk Decryptor decrypts or mounts
No key → Elcomsoft Forensic Disk Decryptor extracts metadata
3

Recovery

What's left to attack?

Container metadata, Windows hashes, VM metadata, or documents/archives/vaults → Elcomsoft Distributed Password Recovery

Elcomsoft System Recovery and Elcomsoft Quick Triage both collect artifacts, and that's deliberate, not redundant. Elcomsoft System Recovery works from outside a booted OS — machine off, or no working credentials. Elcomsoft Quick Triage works from inside a live session — machine on and unlocked. The choice is made by how the machine was found, not by which tool happens to be on the shelf.

The Toolset

What each tool actually does

Four purpose-built stages of the same job, designed to hand off to each other without reformatting anything in between.

Quick Reference

Situation at the scene → tool → output

The same logic the case advisor above runs on, condensed to a lookup table for when you already know the situation.

Situation at the sceneReach forWhat you get out
Evidentiary Integrity

Fast doesn't mean undisciplined

Whichever tool is running, the same evidence-handling principles apply from first contact — triage does not get a pass on custody discipline just because it's quick.

Chain of custody, start to finish

Encryption and admissibility

Further reading

    Own the whole pipeline: Elcomsoft Desktop Forensic Bundle

    See bundle details ↗