Agent skill

Implementing Disk Encryption With Bitlocker

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft.

Apache-2.0Auto-check passedSecurity

Install Implementing Disk Encryption With Bitlocker

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-disk-encryption-with-bitlocker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-disk-encryption-with-bitlocker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-disk-encryption-with-bitlocker .claude/skills/implementing-disk-encryption-with-bitlocker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-disk-encryption-with-bitlocker
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
438 words
Files
8 (incl. scripts, references, assets)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft.

  • Works in 6 steps: Verify TPM and System Requirements → Configure BitLocker GPO Settings → Enable BitLocker - Command Line → …
  • Deploying encryption for compliance requirements
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Disk Encryption With Bitlocker is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Privacy and GDPR. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Deploying encryption for compliance requirements
  • Securing mobile workstations
  • Implementing data protection controls across the enterprise

Example prompts

  • “Use the implementing-disk-encryption-with-bitlocker skill to implement full disk encryption using Microsoft BitLocker on Windows endpoints to…”
  • “/implementing-disk-encryption-with-bitlocker”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Verify TPM and System Requirements
  2. Configure BitLocker GPO Settings
  3. Enable BitLocker - Command Line
  4. Deploy via Intune (Enterprise)
  5. Manage Recovery Keys
  6. Monitor Encryption Status

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Disk Encryption With Bitlocker loads about 2.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 438 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 438 words, ~2,212 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-disk-encryption-with-bitlocker/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-disk-encryption-with-bitlocker
description
Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection.
domain
cybersecurity
subdomain
endpoint-security
tags
endpoint, encryption, BitLocker, TPM, data-protection, windows-security
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, PR.PS-02, DE.CM-01, PR.IR-01
mitre_attack
T1055, T1547, T1059, T1036, T1573

Implementing Disk Encryption with BitLocker

When to Use

Use this skill when:

  • Encrypting Windows endpoints to protect data at rest for compliance (PCI DSS, HIPAA, GDPR)
  • Deploying BitLocker across enterprise fleet via Intune, SCCM, or GPO
  • Configuring TPM-based encryption with PIN or USB startup key for enhanced security
  • Managing BitLocker recovery keys in Active Directory or Azure AD

Do not use this skill for Linux disk encryption (use LUKS/dm-crypt) or macOS (use FileVault).

Prerequisites

  • Windows 10/11 Pro, Enterprise, or Education edition
  • TPM 2.0 chip (recommended; TPM 1.2 supported with limitations)
  • UEFI firmware with Secure Boot enabled (recommended)
  • Separate system partition (200 MB minimum, created automatically by Windows installer)
  • Active Directory or Azure AD for recovery key escrow

Workflow

Step 1: Verify TPM and System Requirements
powershell
# Check TPM status
Get-Tpm
# ManufacturerId, ManufacturerVersion, TpmPresent, TpmReady, TpmEnabled

# Check TPM version (2.0 required for best compatibility)
(Get-WmiObject -Namespace "root\cimv2\security\microsofttpm" -Class Win32_Tpm).SpecVersion

# Check UEFI/Secure Boot
Confirm-SecureBootUEFI
# Returns True if Secure Boot is enabled

# Check BitLocker readiness
$vol = Get-BitLockerVolume -MountPoint "C:"
$vol.VolumeStatus  # Should be "FullyDecrypted"
$vol.ProtectionStatus  # Should be "Off"
Step 2: Configure BitLocker GPO Settings
Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption

Operating System Drives:
  - Require additional authentication at startup: Enabled
    - Allow BitLocker without compatible TPM: Disabled (enforce TPM)
    - Configure TPM startup: Allow TPM
    - Configure TPM startup PIN: Allow startup PIN with TPM
    - Configure TPM startup key: Allow startup key with TPM

  - Choose how BitLocker-protected OS drives can be recovered: Enabled
    - Allow data recovery agent: True
    - Configure storage of recovery information to AD DS: Enabled
    - Save recovery info to AD DS for OS drives: Store recovery passwords and key packages
    - Do not enable BitLocker until recovery information is stored: Enabled

  - Choose drive encryption method and cipher strength:
    - OS drives: XTS-AES 256-bit (Windows 10 1511+)
    - Fixed drives: XTS-AES 256-bit
    - Removable drives: AES-CBC 256-bit (for cross-platform compatibility)

Fixed Data Drives:
  - Choose how BitLocker-protected fixed drives can be recovered: Enabled
    - Store recovery passwords in AD DS: Enabled

Removable Data Drives:
  - Control use of BitLocker on removable drives: Enabled
  - Configure use of passwords for removable drives: Require complexity
Step 3: Enable BitLocker - Command Line
powershell
# Enable BitLocker with TPM-only protector (transparent to user)
Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 `
  -TpmProtector -SkipHardwareTest

# Enable BitLocker with TPM + PIN (recommended for laptops)
$pin = ConvertTo-SecureString "123456" -AsPlainText -Force
Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 `
  -TpmAndPinProtector -Pin $pin

# Add recovery password protector
Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector

# Backup recovery key to Active Directory
Backup-BitLockerKeyProtector -MountPoint "C:" `
  -KeyProtectorId (Get-BitLockerVolume -MountPoint "C:").KeyProtector[1].KeyProtectorId

# Encrypt fixed data drives
Enable-BitLocker -MountPoint "D:" -EncryptionMethod XtsAes256 `
  -RecoveryPasswordProtector -AutoUnlockEnabled
Step 4: Deploy via Intune (Enterprise)
Intune → Endpoint Security → Disk encryption → Create Profile

Platform: Windows 10 and later
Profile: BitLocker

Settings:
  BitLocker base settings:
    - Encryption for operating system drives: Require
    - Encryption for fixed data drives: Require
    - Encryption for removable data drives: Require

  Operating system drive settings:
    - Additional authentication at startup: Require
    - TPM startup: Allowed
    - TPM startup PIN: Required (for high-security endpoints)
    - Encryption method: XTS-AES 256-bit
    - Recovery: Escrow to Azure AD

  Fixed drive settings:
    - Encryption method: XTS-AES 256-bit
    - Recovery: Escrow to Azure AD

  Assign to: All managed Windows devices (or specific groups)
Step 5: Manage Recovery Keys
powershell
# View recovery key on local system
(Get-BitLockerVolume -MountPoint "C:").KeyProtector |
  Where-Object {$_.KeyProtectorType -eq "RecoveryPassword"} |
  Select-Object KeyProtectorId, RecoveryPassword

# Retrieve recovery key from Active Directory (requires RSAT)
Get-ADObject -Filter {objectClass -eq "msFVE-RecoveryInformation"} `
  -SearchBase "CN=COMPUTER01,OU=Workstations,DC=corp,DC=example,DC=com" `
  -Properties msFVE-RecoveryPassword |
  Select-Object -ExpandProperty msFVE-RecoveryPassword

# Retrieve recovery key from Azure AD
# Azure Portal → Azure AD → Devices → [device] → BitLocker keys
# Or via Microsoft Graph API:
# GET /devices/{id}/bitlockerRecoveryKeys
Step 6: Monitor Encryption Status
powershell
# Check encryption status across fleet
manage-bde -status C:

# Expected output for encrypted drive:
#   Conversion Status: Fully Encrypted
#   Percentage Encrypted: 100.0%
#   Encryption Method: XTS-AES 256
#   Protection Status: Protection On
#   Key Protectors: TPM, Numerical Password

# PowerShell compliance check
$vol = Get-BitLockerVolume -MountPoint "C:"
if ($vol.ProtectionStatus -eq "On" -and $vol.VolumeStatus -eq "FullyEncrypted") {
    Write-Host "COMPLIANT: BitLocker enabled and fully encrypted"
} else {
    Write-Host "NON-COMPLIANT: BitLocker status - Protection: $($vol.ProtectionStatus), Volume: $($vol.VolumeStatus)"
}

Key Concepts

TermDefinition
TPM (Trusted Platform Module)Hardware security chip that stores BitLocker encryption keys and provides measured boot integrity
XTS-AES 256Encryption cipher used by BitLocker; XTS mode provides better protection for disk encryption than CBC
Recovery Key48-digit numerical password used to unlock BitLocker-encrypted drive when TPM authentication fails
Key ProtectorMethod used to unlock BitLocker (TPM, TPM+PIN, recovery password, startup key, smart card)
Used Space Only EncryptionEncrypts only sectors containing data; faster initial encryption but may leave remnant data in free space
Full Disk EncryptionEncrypts entire volume including free space; slower but more secure for drives that previously contained data
Show full SKILL.md (179 more words)Show less

Tools & Systems

  • BitLocker (built-in): Windows full disk encryption feature
  • manage-bde.exe: Command-line BitLocker management tool
  • BitLocker Recovery Password Viewer: RSAT tool for viewing recovery keys in Active Directory
  • MBAM (Microsoft BitLocker Administration and Monitoring): Enterprise BitLocker management (legacy, replaced by Intune)
  • Microsoft Intune: Cloud-based BitLocker policy deployment and recovery key management

Common Pitfalls

  • Not escrowing recovery keys before encryption: If recovery keys are not saved to AD/Azure AD before encryption, they may be permanently lost if the TPM fails.
  • Using TPM-only without PIN: TPM-only mode is transparent but vulnerable to cold boot attacks and evil maid attacks. Add a startup PIN for laptops leaving the office.
  • Encrypting used space only on repurposed drives: If a drive previously contained sensitive data, "used space only" encryption leaves deleted data unencrypted in free space. Use full disk encryption for repurposed drives.
  • Forgetting removable drives: USB drives and external disks are common data loss vectors. Enforce BitLocker To Go for removable media.
  • No pre-provisioning for SCCM deployments: Pre-provision BitLocker during OSD task sequence to encrypt before OS deployment, avoiding the lengthy post-deployment encryption process.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-disk-encryption-with-bitlocker of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Disk Encryption With Bitlocker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Disk Encryption With Bitlocker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Disk Encryption With Bitlocker this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Architecting Securitytelagod/code-abyss244—~712Automated safety check: PassMIT
Breach Response Playbookmukul975/Privacy-Data-Protection-Skills295—~3.1kAutomated safety check: PassApache-2.0
Security Engineertheneoai/awesome-skills183—~2.1kAutomated safety check: PassMIT
Qe Security Complianceproffesor-for-testing/agentic-qe494—~1.4kAutomated safety check: NotesMIT
Expert SecurityReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT

Similar skills

  • Architecting Security

    telagod/code-abyss

    安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust…

    244 GitHub stars~712 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Breach Response Playbook

    mukul975/Privacy-Data-Protection-Skills

    Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation…

    295 GitHub stars~3.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Security Engineer

    theneoai/awesome-skills

    Elite Security Engineer skill with deep expertise in application security, cloud security architecture, penetration testing, Zero Trust implementation, threat modeling (STRIDE), and compliance…

    183 GitHub stars~2.1k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Qe Security Compliance

    proffesor-for-testing/agentic-qe

    Security auditing, vulnerability scanning, and compliance validation for OWASP, SOC2, GDPR, and other standards.

    494 GitHub stars~1.4k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Expert Security

    ReJeCtAll/ExpertTeam-Codex

    安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~780 tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    849 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Disk Encryption With Bitlocker

What does Implementing Disk Encryption With Bitlocker do?

Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Implementing Disk Encryption With Bitlocker is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft.

When should I use Implementing Disk Encryption With Bitlocker?

Implementing Disk Encryption With Bitlocker fits situations like: deploying encryption for compliance requirements; securing mobile workstations; implementing data protection controls across the enterprise.

How do I install Implementing Disk Encryption With Bitlocker in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-disk-encryption-with-bitlocker -a claude-code`. Or copy the skill folder (skills/implementing-disk-encryption-with-bitlocker in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-disk-encryption-with-bitlocker in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Disk Encryption With Bitlocker in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-disk-encryption-with-bitlocker -a codex`. Or copy the skill folder (skills/implementing-disk-encryption-with-bitlocker in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-disk-encryption-with-bitlocker in your project. Codex loads it when a task matches its description.

Can I use Implementing Disk Encryption With Bitlocker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-disk-encryption-with-bitlocker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-disk-encryption-with-bitlocker, .gemini/skills/implementing-disk-encryption-with-bitlocker, .github/skills/implementing-disk-encryption-with-bitlocker and .opencode/skills/implementing-disk-encryption-with-bitlocker in your project.

What does Implementing Disk Encryption With Bitlocker need to run?

Going by SKILL.md and its folder, Implementing Disk Encryption With Bitlocker needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Disk Encryption With Bitlocker access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Disk Encryption With Bitlocker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Disk Encryption With Bitlocker use?

Implementing Disk Encryption With Bitlocker is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Disk Encryption With Bitlocker use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Disk Encryption With Bitlocker?

Skills that share tags, products or a category with Implementing Disk Encryption With Bitlocker: Architecting Security (telagod/code-abyss, 244 stars), Breach Response Playbook (mukul975/Privacy-Data-Protection-Skills, 295 stars), Security Engineer (theneoai/awesome-skills, 183 stars) and Qe Security Compliance (proffesor-for-testing/agentic-qe, 494 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Disk Encryption With Bitlocker?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.