Skip to content

Scanning standalone .efi file #1300

Answered by frinzell
miakushka asked this question in Q&A
Discussion options

You must be logged in to vote

Thank you!

No scanner for .efi files specifically but the blockedlist.json does list some GUIDs and hashes that may help.

There are two that may help for FW volumes:
scan_blocked.py - can scan for some known binaries within EFI FW volumes.
scan_image.py - can create a sort of fingerprint of a known good FW volume to compare against other volumes.

Hope this helps!

edit: clarified support

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@miakushka
Comment options

@miakushka
Comment options

Answer selected by miakushka
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants