logo

GreatXML: Exploiting the WinRE trust boundary behind BitLocker

ID: 930fdecd-e2eb-5552-92fb-a5668b109a0c

STIX ID: report--930fdecd-e2eb-5552-92fb-a5668b109a0c

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

Nightmare Eclipse (aka Chaotic Eclipse) published a zero-day named GreatXML (June 10, 2026) that allows an attacker with local administrator access to bypass BitLocker by abusing the Windows Recovery Environment, Microsoft Defender Offline scan, and Windows Setup unattend files to execute commands as SYSTEM; the report includes technical analysis, replication steps, IOCs for detection, and corresponding ThreatLocker community policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.