DETech is the name given to a family of tools that are used for rescue and disaster-recovery of Trellix Drive Encryption systems, which have an error that makes self or administrative recovery of the system impossible.
These are examples of reasons why rescue might be necessary:
The Drive Encryption Pre-Boot File System (PBFS) has become corrupted, preventing authentication in the normal fashion.
One or more sectors of the disk have failed, causing the OS to be unable to boot or the filesystem to be corrupted.
An unexpected external event resulted in the OS being unable to boot.
Several different functions are provided by the DETech family, with a number of tools that provide a mixture of functions for different applications. It is recommended that the expert tools listed below be used only by experienced Drive Encryption administrators. For emergency boot purposes, a rudimentary tool that provides only an emergency boot capability is provided to allow inexperienced users to perform the rescue.
These expert tools are provided for comprehensive rescue with WinPE environments, and can be used on UEFI booting systems.
DETech (WinPE 3.x, 4.x, 5.x, and 6.x)
DEOpalTech (WinPE 3.x, 4.x, 5.x, and 6.x)
DETech UEFI (WinPE 4.x, 5.x, and 6.x)
Note
For more information about WinPE 4, see KB77165.
These expert tools are provided for comprehensive rescue when booting from a USB memory stick:
DETech (UEFI) for software and Opal encryption on UEFI-based systems.
Note
On UEFI systems, SecureBoot should be disabled in order to use DETech (Standalone) from a USB memory stick.
DETech and DEOpalTech have similar functionality. However, because Opal disks are self-encrypting disks, Opal versions of DETech do not include certain features related to encrypting and decrypting data, such as Crypt Sectors and Force Crypt Sectors.
Note
For Drive Encryption, Opal disks are supported only using Advanced Host Controller Interface (AHCI) mode.
Feature | Function | DETech WinPE | DETech Standalone | DEOpalTech WinPE | DEOpalTech Standalone |
|---|---|---|---|---|---|
Emergency boot | Allows you to boot through to Windows by authenticating through DETech instead of the normal PBA. Once successfully booted into Windows, the PBFS is rebuilt and all user data is synchronized again from the server. This should be considered as the first-line rescue capability, resolving the majority of issues. | √ | √ | ||
Retrieve data | Allows you to authenticate (and therefore unlock) the disk within a PE environment and copy data off or onto the disk. Useful for pulling data off an encrypted drive without requiring to boot from the drive. | √ | √ | ||
Remove Drive Encryption | Allows you to remove Drive Encryption, from the disk after decrypting the disk. This feature should not be used instead of server-initiated removal via policy. Useful if ePO - On-prem policy enforcement fails. We recommend that you make a sector level copy of the disk before attempting this operation. | √ | √ | √ | √ |
Crypt Sectors | Allows you to manually encrypt or decrypt areas of the disk, ensuring that only areas that are currently not encrypted can be encrypted, and only areas that are currently encrypted can be decrypted. This option should be considered only if other rescue options have failed, and only once a sector level copy has been made. | √ | √ | √ | |
Force Crypt Sectors | Allows you to manually encrypt or decrypt areas of the disk, but does not prevent encrypted areas of the disk from being encrypted (leading to multiple-encryption), or decrypted areas of the disk from being decrypted (leading to multiple-decryption). This option allows multiple encryption or decryption to be performed, therefore it should be considered only as a last resort, and only once a sector level copy has been made. | √ | √ | √ | |
Repair disk information | Allows you to repair various pieces of Drive Encryption metadata in case of corruption; for example, repairing the Disk Information metadata. Useful in case of unknown corruption. We recommend making a sector level copy of the disk before attempting this operation. | √ | |||
View disk information | Allows you to read Drive Encryption metadata; for example, view the Disk Keycheck value, which can be used to locate a system key in the ePO - On-prem database. Useful when a system has been deleted from ePO - On-prem, making export of the recovery file impossible without knowing the Keycheck value. | √ | √ | √ | √ |