By default, Microsoft BitLocker protected OS drives can be accessed by sniffing the LPC bus, retrieving the volume master key when it’s returned by the TPM, and using the retrieved VMK to decrypt the protected drive.
Extracting BitLocker keys from a TPM
Extracting BitLocker keys from a TPM
Comments
Post a Comment