BitUnlocker: Leverage Windows Recovery to Extract BitLocker Secrets

Alon Leviev, Netanel Ben Simon

DEF CON 33 · Day 1 · Main Stage

BitLocker is Microsoft's flagship full-disk encryption feature, and for years it has been the frontline defense against physical theft attacks — the scenario where an adversary steals your laptop and

AI review

WinRE as a TPM-unsealing attack surface for BitLocker VMK extraction — full demo, no PIN required, five minutes of physical access, complete disk decryption — and the architectural root cause survives patching.

Watch on YouTube