hunting-bootkits-in-efi-system-partition
mukul975/Anthropic-Cybersecurity-Skills
This skill proactively hunts for advanced firmware threats, including UEFI bootkits (e.g., BlackLotus, ESPecter), residing in the EFI System Partition (ESP). It establishes a cryptographic baseline, verifies bootloader signatures, scans for out-of-band changes, and uses YARA rules to detect persistence mechanisms related to pre-OS compromise (MITRE ATT&CK T1542.003). Ideal for forensic investigations and security hardening.