From BitLocker-Suspended to Virtual Machine
ID: fcdb6220-d966-5594-b5b7-a1dbcb4e097e
STIX ID: report--fcdb6220-d966-5594-b5b7-a1dbcb4e097e
Feed Name: SensePost Blog
This report outlines a red-team technique for turning a BitLocker-suspended Windows laptop into a virtual machine to facilitate stealthier operations. By decrypting the drive with Windows Setup (manage-bde), imaging it (dd), and converting to VMDK for VirtualBox, the operator preserves system and user certificates, enables snapshots, and simplifies tooling while avoiding direct tampering on the physical device. It highlights operational safeguards such as disabling NAT to prevent EDR callouts and mitigating domain machine password updates that could invalidate snapshots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
