logo

From BitLocker-Suspended to Virtual Machine

ID: fcdb6220-d966-5594-b5b7-a1dbcb4e097e

STIX ID: report--fcdb6220-d966-5594-b5b7-a1dbcb4e097e

Feed Name: SensePost Blog

Date Published: 2023-03-28

Date Updated: 2026-04-30

...
...

This report outlines a red-team technique for turning a BitLocker-suspended Windows laptop into a virtual machine to facilitate stealthier operations. By decrypting the drive with Windows Setup (manage-bde), imaging it (dd), and converting to VMDK for VirtualBox, the operator preserves system and user certificates, enables snapshots, and simplifies tooling while avoiding direct tampering on the physical device. It highlights operational safeguards such as disabling NAT to prevent EDR callouts and mitigating domain machine password updates that could invalidate snapshots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.