From the course: Incident Response: Evidence Collection in Windows

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

BitLocker implementation and recovery password

BitLocker implementation and recovery password

From the course: Incident Response: Evidence Collection in Windows

Start my 1-month free trial

BitLocker implementation and recovery password

- [Instructor] Now, if you've determined that BitLocker is being run on a machine, because you've done the manage-bde, the drive letter, dash status, and it returns the fact that that drive is being used with BitLocker, you then can try to attempt to get the recovery password, and the implementation of BitLocker being used. That would be either a password and a USB key, or a password and a TPM, or trusted platform module. To do this, you'll simply type in manage-bde, the drive letter you're trying to ensure you get the information from, and then -protectors, -get. And then you'll hit enter. Now, as I showed you before, this system does not have BitLocker enabled, so there's no key protectors found that would be displayed. This is because the system that we're using here is a Windows 10 Home user machine. Now, if you want to determine what version of the system you're running, you can use the system information command, or…

Contents