12-30-2023, 01:24 AM
(This post was last modified: 12-30-2023, 01:27 AM by MikhailPole.)
(12-09-2020, 11:15 PM)Banaanhangwagen Wrote: 1) and 2) ok
3) and 4) In order to avoid further headache, you need to take your image with a mac.
Since you have access to Macquisition, boot your host with it, and connect the guest with TDM to this host. It will appear as "disk2 - Target Disk Mode - Thunderbolt".
Since this disk is encrypted with T2, you do not need to image this one, but the "virtual APFS container disk3".
5) finally, the image you just took should be encrypted with APFS Filevault; follow these steps to extract the hash (and not fvdetools)
Hi, I am in very bad situation, so I should to ask you for help and hope you still there. I lost access to my MacBook pro with t2 because forgot password for login and recovery key for file vault encryption. On my storage too much important data for me. I have question about first step. If I under recover system on Mac makes image with dd should I do it for all my 1 tb or only for apfs volume? Because also on Mac I have ubuntu volume. Also question how much approx.. takes step with decryption of file vault hash?