Identifying TrueCrypt Artifacts in RAM with Volatility 2.1
If you are not a member of the Volatility Users mailing list, you probably missed a recent thread discussing how to identify TrueCrypt artifacts in physical memory with Volatility 2.1. Lucky for you, “Bridgey the Geek” created a document that summarized the thread and his observations. If you are interested in TrueCrypt, you may also want to check out the research we did in 2007 to extract the TrueCrypt master key.