BitLocker key retrieval
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Abuse Elevation Control Mechanism (T1548)
Severity
Informational
Description
An identity retrieved a BitLocker Key.
Attacker's Goals
BitLocker keys are used for mitigating unauthorized data access on lost or stolen computers by encrypting all user files and system files on the operating system drive.
An attacker that retrieves this key, can potentially access the data that should be encrypted.
Investigative actions
Check what key was retrieved.
Check for a possible compromised device.
Check whether the user is permitted to perform such actions.
Was this helpful?
