51d3afbe-d378-492d-86fc-3afcf9396417

51d3afbe-d378-492d-86fc-3afcf9396417 :inline

This was provided by Now Computing LLC and revoked Jul-20

  • UUID: 51d3afbe-d378-492d-86fc-3afcf9396417
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\ } }
        
not set
Use CasePrivilegesOperating System
Persistence64-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • CVE-2020-10713
  • CVE-2020-14308
  • CVE-2020-14309
  • CVE-2020-14310
  • CVE-2020-14311
  • CVE-2020-15705
  • CVE-2020-15706
  • CVE-2020-15707
  • PropertyValue
    Filename
    MD5
    SHA1
    SHA2560FB12613BC1D4AB6FBB256574EBA9347AE3A87F96E4A3C259028B55CDE1D8053
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA256BC75F910FF320F5CB5999E66BBD4034F4AE537A42FDFEF35161C5348E366E216
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31