Hunting Bootkits In Efi System Partition

by mukul975 mukul975/hunting-bootkits-in-efi-system-partition multi-file Updated


Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.

SKILL.md

Related

  1. Analyzing Uefi Bootkit Persistence · mukul975 bundle
    Analyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification.
    24.6k
    repo stars
  2. Detecting Secure Boot Bypass · mukul975 bundle
    Detect bootkits such as BlackLotus and Bootkitty and verify Secure Boot bypass via DBX and binary checks.
    24.6k
    repo stars
  3. Performing Malware Ioc Extraction · mukul975 bundle
    Analyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
    24.6k
    repo stars
  4. Analyzing Bootkit And Rootkit Samples · mukul975 bundle
    Analyzes bootkit and rootkit malware that infects MBR, VBR, or UEFI firmware for pre-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection.
    24.6k
    repo stars
  5. Auditing Uefi Firmware With Chipsec · mukul975 bundle
    Assess platform firmware security using Intel CHIPSEC: verify SPI flash write protection, BIOS lock, SMM/SMRR, Secure Boot variables, dump SPI flash, and triage UEFI variables for firmware-level threats.
    24.6k
    repo stars
  6. Hunting For Persistence Mechanisms In Windows · mukul975 bundle
    Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
    24.6k
    repo stars

Frequently asked questions

How do I install the Hunting Bootkits In Efi System Partition skill?

Run npx skillmds add mukul975/hunting-bootkits-in-efi-system-partition in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Hunting Bootkits In Efi System Partition skill do?

Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files. It is listed under Security, Coding & Dev Tools, Incident Response, Vulnerability Scanning on SkillMD.

Is Hunting Bootkits In Efi System Partition safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Hunting Bootkits In Efi System Partition?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Hunting Bootkits In Efi System Partition free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Hunting Bootkits In Efi System Partition?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.