71999c6f-6195-4944-ad16-105579c98549

bootmgfw.efi :inline

This was provided by Microsoft and revoked May-23

  • UUID: 71999c6f-6195-4944-ad16-105579c98549
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\bootmgfw.efi } }
        
not set
Use CasePrivilegesOperating System
Persistence32-bit ARM
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • Black Lotus Microsoft Windows 8.1
  • PropertyValue
    Filenamebootmgfw.efi
    MD5
    SHA1
    SHA25650A8B3CD4F80C8C27FA47242869FDE8B6B7709A8AD1AF0EF0A726D20623007D8
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA256CB6722995D4821AEAA9871C1B9782A02ED2F3D2BC6C1AAFD3E6B7673A210A8FB
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31