CrowdStrike Outage Recovery with BitLocker

preview_player
Показать описание
Рекомендации по теме
Комментарии
Автор

How to Fix without Bitlocker Key

1. Create a Bootable USB OS:
o Download a Windows OS ISO file from the official Microsoft website.
o Use a tool like Rufus to create a bootable USB drive or work with your SCCM guy to make one for you.
A. Insert a USB drive with at least 8 GB of space into your computer.
B. Open Rufus and select the USB drive.
C. Click on the 'Select' button and choose the downloaded Windows ISO file.
D. Ensure the partition scheme is set to 'MBR' and the target system is 'BIOS (or UEFI-CSM)'.
E. Click 'Start' to begin the process.
o Once the bootable USB is created, safely eject it.

2. Boot from the USB Drive:
o Insert the bootable USB drive into the locked machine.
o Power on the machine and enter the BIOS settings by pressing the appropriate key (usually F2, F10, F12, or Del).
o Navigate to the storage settings and ensure that ACHI is enabled:
A. Go to the 'Advanced' or 'Main' tab in the BIOS menu.
B. Find 'SATA Mode' or 'Storage Configuration' and set it to 'ACHI'.
o Save the changes and exit the BIOS.
o Restart the machine and press the boot menu key (usually F12 or Esc) during startup.
o Select the USB drive from the boot menu to boot from it.

3. Access Command Prompt:
o Once the Windows setup screen appears, press Shift + F10 or F8 or Fnc+F8 (depends on your device) to open the Command Prompt.

4. Enable Safe Mode:
o In the Command Prompt, type the following command and press Enter:
bcdedit /set {default} safeboot minimal
o This command configures the system to boot into Safe Mode.

5. Log into the Machine:
o Close the Command Prompt and continue to boot into Windows.
o Select 'Safe Mode' from the boot options.
o Log in using a local Administrator account.

6. Delete CrowdStrike File:
o Open File Explorer and navigate to the following directory:
o
o Locate the file named and delete it.

7.Disable Safe Mode:
oOpen the Command Prompt again by pressing Shift + F10.
o Enter the following command to disable Safe Mode:
bcdedit /deletevalue {default} safeboot

8. Reboot the Machine:
o Close the Command Prompt and restart your computer.
o Your machine should now boot normally without requiring a Bitlocker key or encountering the BSOD.

RichardMcIntosh-pf
Автор

You know that Microsoft is pushing bitlocker and it will be enabled by default on windows install process.

MrMgrPL
Автор

Typical Microsoft 💩 crap. 😂 I still do my data entry on Win7 worskstations. Hell even an old copy of Linux or Novell is better.

RalphSmith-cjhe
Автор

Cool. A manual workaround. Now imagine having 10000 PCs you need to fix...

raylopez
Автор

OK, I know this makes me a bad person, but I Fu**ing told you so, said every security engineer ever.

theITGuy-nont
Автор

Set up a PXE boot server, reimage every machine and if you have all data on shares/in AD profiles you should be good to go.

TobiasTimpe
Автор

Go to safe mode open file and delete
The file from driver

mr.xofficials
Автор

We've found a workaround for all our devices, including bitlocker as well. You can bypass the recovery key part too

GodlyTank