The Crypt Sector feature allows you to safely manipulate which sectors are encrypted on the disk. Note that there is no check to ensure that you are using the correct key for the machine; use of the wrong key could corrupt data.
Make sure that you have:
The DETech WinPE Recovery CD/DVD boot disk
The daily authorization code
Note
You can download the Code of the Day tool from the Trellix website.
Recovery information file (.xml) or authentication token
The disk maintains a list of regions of the disk which are encrypted, and regions of the disk which are not; this list is called the crypt list.
This option uses the crypt list to validate the ranges you submit to make sure that you cannot inadvertently encrypt sectors that are already encrypted, or decrypt sectors that are currently not encrypted. This option also supports power fail protection.
The Crypt Sector option cannot be used if Drive Encryption Trellix Drive Encryption - SaaS has become corrupt on the disk, or the crypt state has been corrupted. The Force Crypt Sectors option can be used in such cases, but this provides no protection and must therefore be used with extreme caution.
Changing the encryption state of areas of the disk with this feature modifies the disk crypt list, which persists until the next policy enforcement. For example, if you use this feature to decrypt a specific partition, the next time you boot the machine to windows and the policy is enforced, Drive Encryption Trellix Drive Encryption - SaaS re-encrypts the partition according to the policy applied.
Note
DETech now displays the Disk Crypt List and Edit Disk Crypt State information in decimal instead of hexadecimal format.
Drive Encryption can be manually removed by decrypting the entire disk using this feature, and then performing a Restore MBR operation that replaces the MBR with the Windows MBR, thus deactivating Drive Encryption.
Caution
It is entirely the responsibility of the qualified system administrators and security managers to take appropriate precautions before performing this task. DETech provides very low level control of the disk and administrative error when using this tool can result in the loss of data. We recommend that only experienced administrators work with DETech.
Make a sector level backup of the drive being processed.
Boot the system with the DETech WinPE Recovery CD/DVD to load the Drive Encryption interface.
At the command prompt, enter these commands to open the DETech window:
cd\cd Program Files\Drive EncryptionEETech.exeorEEOpalTech.exeIf necessary, click Set Boot Disk, then select the required boot disk.
Enter the daily authorization code, then confirm the authorization status.
Authenticate with Token or Recovery Information File (.xml), then confirm the authentication status.
Click Set Algorithm, then select the required algorithm from the Select Algorithm page.
Click Crypt Sectors, select the disk from the Select Disk list, then type the Start Sector and the Number of Sectors.
Click Encrypt/Decrypt to encrypt or decrypt a range of sectors.