bf3c5a6b-8fac-470b-a458-c84e7fed7dc7

bf3c5a6b-8fac-470b-a458-c84e7fed7dc7 :inline

This was provided by Intel Corporation and revoked Jul-20

  • UUID: bf3c5a6b-8fac-470b-a458-c84e7fed7dc7
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\ } }
        
not set
Use CasePrivilegesOperating System
Persistence64-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • CVE-2020-10713
  • CVE-2020-14308
  • CVE-2020-14309
  • CVE-2020-14310
  • CVE-2020-14311
  • CVE-2020-15705
  • CVE-2020-15706
  • CVE-2020-15707
  • PropertyValue
    Filename
    MD5
    SHA1
    SHA256BAE97EFC507382C0BDF7B1E74DBC38C0E31BF65186B7989CD9C7AF29DA27F656
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA2563A4F74BEAFAE2B9383AD8215D233A6CF3D057FB3C7E213E897BEEF4255FAEE9D
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31