https://github.com/p0dalirius/extractbitlockerkeys
A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.
https://github.com/p0dalirius/extractbitlockerkeys
active-directory bitlocker domain post-exploitation recovery
Last synced: about 1 year ago
JSON representation
A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.
- Host: GitHub
- URL: https://github.com/p0dalirius/extractbitlockerkeys
- Owner: p0dalirius
- Created: 2023-09-19T07:28:11.000Z (almost 3 years ago)
- Default Branch: main
- Last Pushed: 2025-01-31T09:39:55.000Z (over 1 year ago)
- Last Synced: 2025-04-08T20:17:02.257Z (over 1 year ago)
- Topics: active-directory, bitlocker, domain, post-exploitation, recovery
- Language: Python
- Homepage: https://podalirius.net/
- Size: 10.1 MB
- Stars: 368
- Watchers: 6
- Forks: 54
- Open Issues: 2
-
Metadata Files:
- Readme: README.md
- Funding: .github/FUNDING.yml
Awesome Lists containing this project
README

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.
## Features
- [x] Automatically gets the list of all computers from the domain controller's LDAP.
- [x] Multithreaded connections to extract Bitlocker keys from LDAP.
- [x] Iterate on LDAP result pages to get every computer of the domain, no matter the size.
> [!WARNING]
> Please do not store this backup in an online SMB share of the domain. You should prefer to print it and store it physically in a locked safe.
- [x] Export results in JSON with Computer FQDN, Domain, Recovery Key, Volume GUID, Created At and Organizational Units.
- [x] Export results in XLSX with Computer FQDN, Domain, Recovery Key, Volume GUID, Created At and Organizational Units.
- [x] Export results in SQLITE3 with Computer FQDN, Domain, Recovery Key, Volume GUID, Created At and Organizational Units.
---
## Demonstration from Linux in Python
To extract Bitlocker recovery keys from all the computers of the domain `domain.local` you can use this command:
```
./ExtractBitlockerKeys.py -d 'domain.local' -u 'Administrator' -p 'Podalirius123!' --dc-ip 192.168.1.101
```
You will get the following output:

---
## Demonstration from Windows in Powershell
To extract Bitlocker recovery keys from all the computers of the domain `domain.local` you can use this command:
```
.\ExtractBitlockerKeys.ps1 -dcip 192.168.1.101 -ExportToCSV ./keys.csv -ExportToJSON ./keys.json
```
You will get the following output:

---
## Usage
```
$ ./ExtractBitlockerKeys.py -h
ExtractBitlockerKeys.py v1.1 - by Remi GASCOU (Podalirius)
usage: ExtractBitlockerKeys.py [-h] [-v] [-q] [-t THREADS] [--export-xlsx EXPORT_XLSX] [--export-json EXPORT_JSON] [--export-sqlite EXPORT_SQLITE] --dc-ip ip address [-d DOMAIN] [-u USER]
[--no-pass | -p PASSWORD | -H [LMHASH:]NTHASH | --aes-key hex key] [-k]
options:
-h, --help show this help message and exit
-v, --verbose Verbose mode. (default: False)
-q, --quiet Show no information at all.
-t THREADS, --threads THREADS
Number of threads (default: 4).
Output files:
--export-xlsx EXPORT_XLSX
Output XLSX file to store the results in.
--export-json EXPORT_JSON
Output JSON file to store the results in.
--export-sqlite EXPORT_SQLITE
Output SQLITE3 file to store the results in.
Authentication & connection:
--dc-ip ip address IP Address of the domain controller or KDC (Key Distribution Center) for Kerberos. If omitted it will use the domain part (FQDN) specified in the identity parameter
-d DOMAIN, --domain DOMAIN
(FQDN) domain to authenticate to
-u USER, --user USER user to authenticate with
Credentials:
--no-pass Don't ask for password (useful for -k)
-p PASSWORD, --password PASSWORD
Password to authenticate with
-H [LMHASH:]NTHASH, --hashes [LMHASH:]NTHASH
NT/LM hashes, format is LMhash:NThash
--aes-key hex key AES key to use for Kerberos Authentication (128 or 256 bits)
-k, --kerberos Use Kerberos authentication. Grabs credentials from .ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the command line.
```
## Contributing
Pull requests are welcome. Feel free to open an issue if you want to add other features.
## References
- [https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-keypackage](https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-keypackage?wt.mc_id=SEC-MVP-5005286)
- [https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-recoveryguid](https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-recoveryguid?wt.mc_id=SEC-MVP-5005286)
- [https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-recoverypassword](https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-recoverypassword?wt.mc_id=SEC-MVP-5005286)
- [https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-volumeguid](https://learn.microsoft.com/en-us/windows/win32/adschema/a-msfve-volumeguid?wt.mc_id=SEC-MVP-5005286)