Arsenna Posted November 17, 2018 Posted November 17, 2018 Situation: A client has called me that they will bring in their desktop pc secured with bootlocker and a Windows 10 login (he says It's NOT a Microsoft account). He has his bootlocker password but not his recovery key. He somehow managed to mess up his Windows 10 login password. Question: Is there a way to run windows 10 password removal software such as hirens or offline NT after entering the bootlocker password but before booting windows? Thanks!
thimon Posted November 18, 2018 Posted November 18, 2018 Bitlocker? Sounds very suspicious. I’d say no
elsiegee40 Posted November 18, 2018 Posted November 18, 2018 Hello and welcome to EduGeek I am afraid that as a first time poster to EduGeek your question immediately raises the suspicions of the many IT staff on this forum working hard to keep their organisation’s data and equipment secure. Even if members of this forum know the answer to your question, they cannot answer it and maintain the integrity of their, or anyone else’s network. 1
Blue_Cookeh Posted November 18, 2018 Posted November 18, 2018 If they have the BitLocker key that suggests they perhaps own the device, or that it is compromised anyway? Anyway, I don't care about answering the question - the info can be found anywhere online. You can boot into a WinPE instance and use manage-bde to unlock the drive and decrypt it. This will allow you to use the standard tools like Hiren's to remove the password.
Arsenna Posted November 18, 2018 Author Posted November 18, 2018 Thanks @Blue_Cookeh I can assure you all this is his PC, username contains his organization's name and he has the 10+ character complex bitlocker password. If he didn't lose his recovery key as I had warned against over a year ago we wouldn't have any issues today. I appreciate that someone looked at my question in full instead of thinking 'crack into encrypted device? Must be stolen.' Thanks for the software advice I'll give it a crack this afternoon!
chazzy2501 Posted November 22, 2018 Posted November 22, 2018 you should be able to plug that drive into another PC and it'll prompt for the bitlocker password, then at least you can access their files. Luckily as we now know that bitlocker (on windows 10) uses the hardware encryption on harddisk or SSD these are probably broken (samsung and Crucial) the data could be recovered without the key or password. The drives can be made to decrypt themselves
Arsenna Posted December 7, 2018 Author Posted December 7, 2018 I just wanted to report back for anyone else in the same boat. After adding all modules that sounded relevant to Bitlocker, and their pre-requisite modules, and language packs (as found referenced on this pagehttps://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference) to a customized ISO of WinPE, I was able to run manage-bde with unlock pw, and then decrypt the drive with manage-bde off. Frankly I don't understand why the default Bitlocker recovery can't decrypt a drive from the password considering Microsoft themselves offer this public package capable of the procedure. It really offers no additional security. Thanks to everyone in this thread who offered their advice!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now