Skip to content
JustMike edited this page Aug 29, 2025 · 3 revisions

Demonstration of realistic, software-only BitLocker bypasses by exploiting Bitpixie using the code found in the associated git repository.

See also the accompanying Compass Security blog post Bypassing BitLocker Encryption: Bitpixie PoC and WinPE Edition.

Linux

bitpixie-linux.webm

WinPE

bitpixie-winpe.webm

Note

The WinPE-based exploitation strategy is less reliable than its Linux-based counterpart.

Exploitation Log

Hardware Boot.wim version / size / construction Reboot mechanism (direct / recovery environment) Comments
Lenovo Thinkpad X1 Carbon Gen 11 21HMCTO1WW Windows 10 1709, 312MB, Windows Setup removed, details Direct See video above
HP ProBook 440 G9 default that comes with git clone & make ?? Struggled with too big offset (integer overflow). Had to obtain BCD via USB as cmd was disabled in advanced start options

Clone this wiki locally