Analytics BIOC
Informational
✕
BitLocker key retrieval
An identity retrieved a BitLocker Key.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
Attacker's goals:
BitLocker keys are used for mitigating unauthorized data access on lost or stolen computers by encrypting all user files and system files on the operating system drive. An attacker that retrieves this key, can potentially access the data that should be encrypted.
Investigative actions:
Check what key was retrieved. Check for a possible compromised device. Check whether the user is permitted to perform such actions.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day