Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Learn BitLocker recovery-key verification with a safe metadata fixture. bitlocker.img is not a real volume. Match a candidate key SHA-256 against the recorded digest, then recover the protected payload.
Candidate recovery keys are in evidence/wordlist.txt
Match sha256sum output to recovery_key_sha256 in bitlocker.img
Decode protected_payload_b64 with base64 -d