如何通过VBS/C#/API等脚本无用户交互修改BitLocker密码
无交互修改BitLocker密码实现方案
前置注意事项
- 脚本必须以管理员权限运行,否则无法访问BitLocker相关接口
- 仅支持修改已经启用BitLocker加密、且已存在密码类型密钥保护器的分区
- 明文存储密码存在安全风险,部署时建议对密码字段做加密处理
方案1:PowerShell 脚本(无需编译,易部署)
直接调用BitLocker官方WMI接口实现,代码如下:
# 配置项:修改为目标分区和需要设置的新密码 $driveLetter = "C:" $newPassword = ConvertTo-SecureString "自定义新密码123!@#" -AsPlainText -Force # 读取目标分区的BitLocker对象 $volume = Get-WmiObject -Namespace root\cimv2\Security\MicrosoftVolumeEncryption -Class Win32_EncryptableVolume -Filter "DriveLetter='$driveLetter'" # 筛选密码类型的密钥保护器(类型值为2) $protectors = $volume.GetKeyProtectors() if ($protectors.ReturnValue -eq 0) { foreach ($pid in $protectors.KeyProtectorID) { $typeResult = $volume.GetKeyProtectorType($pid) if ($typeResult.KeyProtectorType -eq 2) { # 执行密码修改 $changeResult = $volume.ChangePassword($pid, [System.Runtime.InteropServices.Marshal]::PtrToStringAuto([System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($newPassword))) if ($changeResult.ReturnValue -eq 0) { Write-Host "C盘BitLocker密码修改成功" } else { Write-Host "修改失败,错误码:$($changeResult.ReturnValue)" } } } }
方案2:C# 实现代码
需要引用System.Management程序集,编译后可直接运行:
using System; using System.Management; class BitLockerTool { static void Main(string[] args) { string targetDrive = "C:"; string newPassword = "自定义新密码123!@#"; string wmiPath = @"root\cimv2\Security\MicrosoftVolumeEncryption"; try { ManagementObjectSearcher searcher = new ManagementObjectSearcher(wmiPath, $"SELECT * FROM Win32_EncryptableVolume WHERE DriveLetter='{targetDrive}'"); foreach (ManagementObject volume in searcher.Get()) { // 获取所有密钥保护器ID ManagementBaseObject protectorRes = volume.InvokeMethod("GetKeyProtectors", null, null); string[] protectorIds = (string[])protectorRes["KeyProtectorID"]; foreach (string pid in protectorIds) { // 筛选密码类型保护器 ManagementBaseObject typeParam = volume.GetMethodParameters("GetKeyProtectorType"); typeParam["KeyProtectorID"] = pid; ManagementBaseObject typeRes = volume.InvokeMethod("GetKeyProtectorType", typeParam, null); if ((uint)typeRes["KeyProtectorType"] == 2) { // 执行密码修改 ManagementBaseObject changeParam = volume.GetMethodParameters("ChangePassword"); changeParam["KeyProtectorID"] = pid; changeParam["NewPassword"] = newPassword; ManagementBaseObject changeRes = volume.InvokeMethod("ChangePassword", changeParam, null); uint returnCode = (uint)changeRes["ReturnValue"]; Console.WriteLine(returnCode == 0 ? "密码修改成功" : $"修改失败,错误码:{returnCode}"); } } } } catch (Exception ex) { Console.WriteLine($"运行错误:{ex.Message}"); } } }
命令行编译指令:csc /reference:System.Management.dll BitLockerTool.cs
方案3:VBS 脚本实现
driveLetter = "C:" newPassword = "自定义新密码123!@#" ' 连接BitLocker WMI命名空间 Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2\Security\MicrosoftVolumeEncryption") Set colVolumes = objWMIService.ExecQuery("SELECT * FROM Win32_EncryptableVolume WHERE DriveLetter='" & driveLetter & "'") For Each objVolume In colVolumes Set protectorRes = objVolume.GetKeyProtectors() If protectorRes.ReturnValue = 0 Then arrPIDs = protectorRes.KeyProtectorID For Each pid In arrPIDs ' 判断是否为密码类型保护器 Set typeParam = objVolume.Methods_("GetKeyProtectorType").InParameters.SpawnInstance_() typeParam.KeyProtectorID = pid Set typeRes = objVolume.ExecMethod_("GetKeyProtectorType", typeParam) If typeRes.KeyProtectorType = 2 Then ' 执行修改 Set changeParam = objVolume.Methods_("ChangePassword").InParameters.SpawnInstance_() changeParam.KeyProtectorID = pid changeParam.NewPassword = newPassword Set changeRes = objVolume.ExecMethod_("ChangePassword", changeParam) If changeRes.ReturnValue = 0 Then WScript.Echo "密码修改成功" Else WScript.Echo "修改失败,错误码:" & changeRes.ReturnValue End If End If Next End If Next
运行指令:cscript bitlocker_change.vbs
内容的提问来源于stack exchange,提问作者חזי אברהם
相关产品推荐
相关产品推荐

