Slide 6
Slide 6 text
FIRMWARE SCANNERS
•Several vendors provide an UEFI firmware scanner
•AV/EDR: CrowdStrike, Microsoft, ESET, Kaspersky
•firmware security: Eclypsium, Binarly
•The scanner behavior
1. acquiring a firmware image inside a SPI flash memory
2. parsing and scanning the image with signatures
RECON2022 6