Jump to content

Recommended Posts

Posted

Situation: A client has called me that they will bring in their desktop pc secured with bootlocker and a Windows 10 login (he says It's NOT a Microsoft account). He has his bootlocker password but not his recovery key. He somehow managed to mess up his Windows 10 login password.

 

Question: Is there a way to run windows 10 password removal software such as hirens or offline NT after entering the bootlocker password but before booting windows?

 

Thanks!

Posted

:mod:

 

Hello and welcome to EduGeek

 

I am afraid that as a first time poster to EduGeek your question immediately raises the suspicions of the many IT staff on this forum working hard to keep their organisation’s data and equipment secure.

 

Even if members of this forum know the answer to your question, they cannot answer it and maintain the integrity of their, or anyone else’s network.

 

:mod:

  • Thanks 1
Posted

If they have the BitLocker key that suggests they perhaps own the device, or that it is compromised anyway?

 

Anyway, I don't care about answering the question - the info can be found anywhere online.

 

You can boot into a WinPE instance and use manage-bde to unlock the drive and decrypt it. This will allow you to use the standard tools like Hiren's to remove the password.

Posted

Thanks @Blue_Cookeh

 

I can assure you all this is his PC, username contains his organization's name and he has the 10+ character complex bitlocker password. If he didn't lose his recovery key as I had warned against over a year ago we wouldn't have any issues today. I appreciate that someone looked at my question in full instead of thinking 'crack into encrypted device? Must be stolen.'

 

Thanks for the software advice I'll give it a crack this afternoon!

Posted
you should be able to plug that drive into another PC and it'll prompt for the bitlocker password, then at least you can access their files. Luckily as we now know that bitlocker (on windows 10) uses the hardware encryption on harddisk or SSD these are probably broken (samsung and Crucial) the data could be recovered without the key or password. The drives can be made to decrypt themselves ;)
  • 2 weeks later...
Posted

I just wanted to report back for anyone else in the same boat.

 

After adding all modules that sounded relevant to Bitlocker, and their pre-requisite modules, and language packs (as found referenced on this pagehttps://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference) to a customized ISO of WinPE, I was able to run manage-bde with unlock pw, and then decrypt the drive with manage-bde off.

 

Frankly I don't understand why the default Bitlocker recovery can't decrypt a drive from the password considering Microsoft themselves offer this public package capable of the procedure. It really offers no additional security.

 

Thanks to everyone in this thread who offered their advice!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...