n0fate / chainbreaker

Mac OS X Keychain Forensic Tool
GNU General Public License v2.0
816 stars 157 forks source link

So what if I'm a forensic investigator with suspect's drive... #1

Closed trusktr closed 9 years ago

trusktr commented 10 years ago

...and I don't have the suspect's password, and the system isn't live (it's just a disk dump)?

Will this tool have any chance of breaking the keychain? Could you give more detail on how?

n0fate commented 9 years ago

If your target isn't live and you don't know password, you can't decrypt user keychain. But you can decrypt a system keychain and extract WiFi SSID/password and SMB user/password information if you have disk dump.

trusktr commented 9 years ago

@n0fate Thanks!