BitLocker Dump Filter
Caveat: When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Code Integrity validated to FIPS 140-3 under Cert. #5406 operating in approved mode or Secure Kernel Code Integrity validated to FIPS 140-3 under Cert. #5407 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Certificate
| Certificate number | 5409 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-30 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | MultiChipStand |
| Vendor | Microsoft Corporation · website |
Module description
The BitLocker Dump Filter module is a multi-chip standalone software-hybrid cryptographic module that protects crash dump files on BitLocker-encrypted computers. The module is part of the system dump stack. When the dump stack is called during a crash, the module ensures that all data is encrypted before being written to storage as a dump file.
Security level exceptions
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A4008 |
| AES-CBC | A4009 |
| AES-XTS Testing Revision 2.0 | A4008 |
| AES-XTS Testing Revision 2.0 | A4009 |
| RSA SigVer (FIPS186-4) | A4008 |
| RSA SigVer (FIPS186-4) | A4009 |
| SHA2-256 | A4008 |
| SHA2-256 | A4009 |
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-31 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-09-01: first observed by this tracker, status active
- Validation dates on record: 2026-08-31