Defeating Bit Locker Encryption With Keys From RAM
Defeating Bit Locker Encryption With Keys From RAM
Defeating Bit Locker Encryption With Keys From RAM
Application Operating
Application Operating
Zeros
BitLocker Tool Marks
• Not perfect, but good enough
• Original
• Recovered
Finding Tool Marks
• Perl Script
• It’s not pretty, but it works
• Volatility Suite
• Supposed to be for Windows XP SP2 only
• But can treat any file as a flat file
• Use the Sliding Window Scanner
• If/When support is added for Vista,
• Use Pool Tag Scanner
Finding Tool Marks
• How did we do this?
– RTFM
• FIPS certifications are great!
• Ask developers for help
– WinHex
– IDA Pro
– Checked builds
– Debugging symbols Image courtesy of User:Icey on Wikipedia
and is public domain
jesse.kornblum@mantech.com
http://jessekornblum.com/
http://mantech.com/