THREATOPS
THREAT OPSThreat News › UEFI Bootkit Hunting: In-Depth Search for Unique Code Behavior

UEFI Bootkit Hunting: In-Depth Search for Unique Code Behavior

infobinarlyPublished 2025-03-13

In this blog post, the Binarly REsearch team introduces a novel methodology for detecting UEFI bootkits by analyzing their unique code behaviors. By starting from an in-depth analysis of known bootkits, we identify features that can be used for generically detecting bootkits and build rules that we used for hunting new unknown bootkits. Then, we show how these rules can be even further improved, b

Original source: https://www.binarly.io/blog/uefi-bootkit-hunting-in-depth-search-for-unique-code-behavior