logo

Wake up and Smell the BitLocker Keys

ID: 38be2d94-aebe-5f87-9633-d05f1f307c04

STIX ID: report--38be2d94-aebe-5f87-9633-d05f1f307c04

Feed Name: NVISO Labs

Threat Score
70/100

Date Published: 2024-11-26

Date Updated: 2026-04-28

Author: Jonathan Prince

...
...

This report demonstrates a practical local hardware attack against TPM-backed BitLocker on enterprise laptops: by connecting a logic analyzer to the TPM/SPI bus, an attacker can capture the TPM response that contains the VMK, use the extracted VMK to decrypt the FVEK, and therefore mount the BitLocker volume. The write-up details required low-cost tooling, connection and capture procedures, how to identify the VMK in traffic, a decryption example using dislocker, the attack's feasibility and impact, and recommends enforcing pre-boot authentication (PIN or USB key) to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.