3 ms·
> [0]: https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bo https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bo... So how do you remove it?
by moremetadata 4y ago
> [0]: https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bo https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bo...
So how do you remove it?
- mavhc 4y agoBitlocker? If you're Admin in Windows you can just unencrypt your drive
- jeroenhd 4y agoDisable-Bitlocker should do the trick: https://learn.microsoft.com/en-us/powershell/module/bitlocker/disable-bitlocker?view=windowsserver2022-ps https://learn.microsoft.com/en-us/powershell/module/bitlocke... Obviously requires admin permissions on a running host, but if you're injecting into the bootloader you're already admin (or you can get it easily).
- moremetadata 4y agoSo doesnt things like windows defender offline scans and other offline scans where the HD bitlocker codes is typed in manually not detect the rootkit? Half the problem I find with these security products is knowing what their actual abilities are and inabilities. I've assumed wrongly in the past that some security products are doing things when in fact they are not, and thats obviously an area for exploitation.