analyzing-uefi-bootkit-persistence

mukul975/analyzing-uefi-bootkit-persistence · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Analyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 5.6 KB
  • 📁scripts
  • ⚙️agent.py 21.8 KB
  • 📄LICENSE 11.0 KB

Related

  1. auditing-uefi-firmware-with-chipsec · mukul975 bundle
    Assess platform firmware security using Intel CHIPSEC: verify SPI flash write protection, BIOS lock, SMM/SMRR, Secure Boot variables, dump SPI flash, and triage UEFI variables for firmware-level threats.
    24.6k
    repo stars
  2. analyzing-bootkit-and-rootkit-samples · mukul975 bundle
    Analyzes bootkit and rootkit malware that infects MBR, VBR, or UEFI firmware for pre-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection.
    24.6k
    repo stars
  3. hunting-bootkits-in-efi-system-partition · mukul975 bundle
    Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
    24.6k
    repo stars
  4. detecting-secure-boot-bypass · mukul975 bundle
    Detect bootkits such as BlackLotus and Bootkitty and verify Secure Boot bypass via DBX and binary checks.
    24.6k
    repo stars
  5. conducting-memory-forensics-with-volatility · mukul975 bundle
    Analyze RAM dumps with Volatility 3 to detect malware, process injection, network connections, and credential theft during incident response.
    24.6k
    repo stars
  6. analyzing-memory-dumps-with-volatility · mukul975 bundle
    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
    24.6k
    repo stars

Frequently asked questions

How do I install the analyzing-uefi-bootkit-persistence skill?

Run npx skillmds add mukul975/analyzing-uefi-bootkit-persistence in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the analyzing-uefi-bootkit-persistence skill do?

Analyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification. It is listed under Security, Coding & Dev Tools, Research & Search, Incident Response, Penetration Testing, Vulnerability Scanning on SkillMD.

Is analyzing-uefi-bootkit-persistence safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: FAIL. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with analyzing-uefi-bootkit-persistence?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is analyzing-uefi-bootkit-persistence free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published analyzing-uefi-bootkit-persistence?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.