01-19-2018, 08:32 AM
Approach should be identical to TrueCrypt - extracting the first bytes of the drive into a separate file, and pointing hashcat at it.
https://hashcat.net/forum/thread-7099.html
https://hashcat.net/forum/thread-7099.html
~