UEFI启动根kit分析
原名:analyzing-uefi-bootkit-persistence
分析UEFI启动型持久化技术,包括SPI闪存植入和ESP分区修改。
- 分类
- 学习研究
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.6 / 5
内容概览
- A compromised system re-establishes C2 communication after OS reinstallation or disk replacement - Secure Boot has been tampered with, disabled, or shows unexpected Machine Owner Key (MOK) enrollment - Firmware integrity verification fails against vendor-provided baselines - Memory forensics reveals rootkit components loading during early boot phase - Investigating advanced persistent threat (APT) campaigns known to deploy UEFI implants - Auditing firmware security posture for enterprise endpoint hardening Do not use for standard MBR-based bootkits on legacy BIOS systems without UEFI; use MBR/VBR bootkit analysis instead. - chipsec framework for SPI flash dumping, UEFI variable inspection, and firmware security modules - UEFITool / UEFIExtract for firmware volume parsing and DXE driver extraction - Python 3.8+ with struct, hashlib, subprocess, and os modules - Bootable Linux live USB f…