DEF CON 34 – Darren McDonald – BitLocker/full-disk-encryption suspend or bypass on a thin client / kiosk asset
This rule detects modifications to BitLocker registry keys associated with encryption settings, such as enabling/disabling device encryption or modifying startup requirements. These actions could be used by an adversary to weaken, bypass, or disable full-disk encryption to facilitate data theft or gain persistent access.
Microsoft Sentinel (KQL)

