<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>BitLocker — PoC Archive</title><link>https://poc.intelseclab.com/tags/bitlocker/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/bitlocker/index.xml" rel="self" type="application/rss+xml"/><item><title>GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</guid><description>High severity — binary · N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27). Status: Unpatched. Affects: Windows Recovery Environment (WinRE) — Microsoft Defender Offline Scan launch path (ReAgent.xml scheduled operation). Tags: windows, bitlocker, winre, defender, offline-scan, trust-boundary-bypass, zero-day, unpatched, physical-access, local.</description><category>binary</category><category>High</category><category>windows</category><category>bitlocker</category><category>winre</category><category>defender</category><category>offline-scan</category><category>trust-boundary-bypass</category><category>zero-day</category><category>unpatched</category><category>physical-access</category><category>local</category></item><item><title>YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)</title><link>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</guid><description>Medium severity (CVSS 6.1) — misc · CVE-2026-45585. Status: Researched. Affects: Windows BitLocker / WinRE (autofstx.exe). Tags: BitLocker, bypass, physical-access, WinRE, TPM, autofstx, NTFS-transactions, FsTx, Windows-11, Windows-Server-2022, zero-day, full-disk-access.</description><category>misc</category><category>Medium</category><category>BitLocker</category><category>bypass</category><category>physical-access</category><category>WinRE</category><category>TPM</category><category>autofstx</category><category>NTFS-transactions</category><category>FsTx</category><category>Windows-11</category><category>Windows-Server-2022</category><category>zero-day</category><category>full-disk-access</category></item></channel></rss>