Passware Kit Forensic

Passware Logo

Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer.
Available for Windows & Mac.

The software recognizes 300+ file types and works in batch mode to recover their passwords. Many types of files are decrypted instantly, while other passwords are recovered through Dictionary and Brute-force methods using GPU acceleration and distributed computing (for Windows, Linux, and Amazon EC2).

New in Passware Kit 2021 v3 (June 2021)

  • Passware Kit Forensic for Mac
  • Decryption of LUKS2 disks
  • Password recovery for Dashlane Desktop
  • Batch mode: improved performance for 1,000+ files
  • Passware Bootable Memory Imager supports UEFI 1.x
  • Passware Rainbow Tables for Windows
  • Keychain extraction improvements
  • Usability improvements

Key Product Features

Live memory analysis. Analyzes live memory images and hibernation files and extracts encryption keys for hard disks, logins for Windows & Mac accounts, and passwords for files and websites, all in a single streamlined process.

Mobile forensics. Recovers passwords for Apple iPhone/iPad and Android backups as well as Android images and extracts data from images on Windows phones.

Cloud data acquisition. Acquires backups and data from cloud services (Apple iCloud, MS OneDrive, and Dropbox). Extracts passwords from iCloud keychains.

Password recovery for 300+ file types. MS Office, PDF, Zip and RAR, QuickBooks, FileMaker, Lotus Notes, Bitcoin wallets, password managers, and many other applications.

Cross-platform Passware Kit Agents. Supports distributed password recovery with Agents for Windows, Linux, and Amazon EC2.

Encryption detection and analysis. Detects all encrypted files and hard disk images and reports the type of encryption and the complexity of the decryption.

Passware Bootable Memory Imager. A UEFI compatible tool that acquires memory images of Windows, Linux, and Mac computers. Passware Memory Imager works with Windows computers that have Secure Boot enabled.

Batch processing. Runs password recovery for groups of files without manual intervention.

Automatic updates. Includes automatic software updates with one year of Software Maintenance and Support (SMS) subscription.

Decryption of FDE. Decrypts or recovers passwords for APFS, Apple DMG, BitLocker, Dell, FileVault2, LUKS, McAfee, PGP, Symantec, TrueCrypt, and VeraCrypt disk images.

Hardware acceleration. Accelerated password recovery with multiple computers, NVIDIA and AMD GPUs, Decryptum, and Rainbow Tables.

Password Exchange. Password Exchange provides access to the list of passwords found by Passware Kit users worldwide, offering it as an advanced dictionary to improve chances of finding strong passwords.


Network Distributed Recovery

Passware Kit Agent is a network distributed password recovery worker for Passware Kit Forensic. It runs on Windows and Linux, 64- and 32-bit, has linear performance scalability. Each computer running Passware Kit Agent supports multiple CPUs, GPUs, and TPR accelerators simultaneously. Passware Kit Forensic comes with 5 agents included with ability to purchase more separately as needed. Learn more at

Request a Quote