Recording of my TROOPERS26 talk, KDS Root Keys: All Secrets Finally Revealed:

TROOPERS26 – Heidelberg The talk dives into online and offline attacks against virtually every use case of KDS Root Keys, including:

  • Decryption of volumes with BitLocker SID Protector enabled.
  • Exporting RSA private keys from group-protected PFX files.
  • Extracting DNSSEC signing keys (ZSK and KSK) from Active Directory.
  • Recovering ASP.NET Core database connection strings.
  • Bulk export of Windows LAPS and DSRM passwords.
  • Generation of gMSA and dMSA passwords offline.

The talk also covers a newly discovered universal attack against DPAPI-NG SID protectors, allowing any application-encrypted secret to be unlocked without application-specific decryptors.

TROOPERS26 slide deck