BigHugger
sk Skill · mukul975

hunting-bootkits-in-efi-system-partition

Baseline the EFI System Partition and hunt malicious EFI binaries such as ESPecter, BlackLotus, Bootkitty, and Glupteba by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and flagging anomalous non-EFI files or out-of-band bootloader changes. Use during proactive threat hunts for firmware/bootkit persistence (MITRE ATT&CK T1542.003) or when investigating suspected UEFI-level compromise that…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythonmeasured-bootyarathreat-huntingsecure-bootfirmware-forensicsefi-system-partitionuefibootkit
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python