BitLocker Bypass Research
Personal security research project — bypassing BitLocker full disk encryption using CVE-2023-21563 (BitPixie).
What This Is
In October 2025, I did a physical laptop recovery assessment on a corporate laptop with BitLocker enabled. The employee forgot their password and the recovery key wasn't available. I used a known vulnerability (CVE-2023-21563) to extract the Volume Master Key from memory, bypass BitLocker, and recover full access to the system.
What Was Used
- CVE-2023-21563 — BitLocker bypass via PXE soft reboot (BitPixie framework)
- CVE-2024-1086 — Linux kernel netfilter use-after-free; used only to escape Secure Boot's kernel lockdown mode for raw memory access (not the core exploit, substitutable, and skipped entirely by the WinPE variant)
- dislocker / libbde-utils — BitLocker analysis tools
- chntpw — Windows password reset
- dd — Forensic disk imaging
What's In This Repo
- METHODOLOGY.md — Step-by-step walkthrough of how the bypass works (2025, onboard-NIC / local-account laptop)
- MODERN-HARDWARE-NOTES.md — 2026 re-run on newer hardware: USB-NIC PXE chipset gotcha, Intel VMD hiding the NVMe (and the portable-VMK fix), Entra/Azure-AD local login, the login-screen SYSTEM shell (Utilman/sethc), and defensive mitigations
- REPORT.md — Engagement summary, findings, evidence, and recommendations
- evidence/screenshots/ — Photos taken during the process
Disclaimer
This was an authorized assessment on hardware I had permission to test. Don't use any of this on systems you don't own or have written permission to test.