EfiGuard is an open-source UEFI bootkit proof of concept for Windows that executes before the operating system kernel and patches the boot chain to disable PatchGuard and Driver Signature Enforcement. By intervening at boot time from the UEFI environment, it weakens core kernel integrity protections before Windows fully initializes, enabling subsequent unsigned or otherwise unauthorized kernel-mode activity.
EfiGuard is commonly described as a portable UEFI bootkit and has been referenced alongside other public bootkit proof-of-concept projects that demonstrated post-2012 abuse of modern UEFI-based Windows systems. Its design uses a custom boot component and UEFI driver to alter the Windows startup sequence, after which Windows continues booting with PatchGuard and DSE disabled. This makes it relevant both as a research tool for studying Windows kernel protections and as a code base that can be repurposed by threat actors.
The malware targets Windows systems that boot via UEFI. Public reporting has linked modified and recompiled EfiGuard components to real-world malware activity, including Glupteba bootkit persistence, where derivatives were used to replace boot components on the EFI System Partition and establish pre-OS persistence. In that context, EfiGuard-derived code was used to facilitate stealthy persistence and support later unsigned kernel activity. EfiGuard itself is best understood as a bootkit-focused proof of concept rather than an attributed espionage or crimeware family, but its functionality directly supports defense evasion and persistence at a highly privileged stage of system startup.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Due to the concerning nature of the requirements surrounding the HVBPs, even its own makers alert users to the necessity of using the provided scripts to re-enable all the security features once they're done playing.
Буткиты EfiGuard. Эти инструменты показывает, как можно деактивировать PG и DSE на этапе загрузки, до старта ядра Win - это делается через UEFI.
Further analysis confirmed that it is a UEFI bootkit named Bootkitty... The bootkit is an advanced rootkit that is capable of replacing the boot loader and of patching the kernel ahead of its execution.
“The installer has a function main_writeEfiGuard that writes files in the ESP… bootmgfw.efi is renamed… embedded\bootmgfw.efi is written… embedded\EfiGuardDxe.efi is written…” | “We will focus on… a Unified Extensible Firmware Interface (UEFI) bootkit. This bootkit can intervene and control the OS boot process… create a stealthy persistence…”
Further analysis confirmed that it is a UEFI bootkit named Bootkitty... The bootkit is an advanced rootkit that is capable of replacing the boot loader and of patching the kernel ahead of its execution.
“The installer has a function main_writeEfiGuard that writes files in the ESP… bootmgfw.efi is renamed… embedded\bootmgfw.efi is written… embedded\EfiGuardDxe.efi is written…” | “We will focus on… a Unified Extensible Firmware Interface (UEFI) bootkit. This bootkit can intervene and control the OS boot process… create a stealthy persistence…”
One needs to disable almost every Windows low-level security feature — an exceedingly poor idea on its own — as well as install a scene-made hypervisor (HV) ... Even the HVBP itself evolved somewhat, as the first version even required users to disable Secure Boot entirely and use EfiGuard to tweak the boot process.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EfiGuard is described as a bootkit/tool that can disable PatchGuard and Driver Signature Enforcement during the UEFI boot phase before the Windows kernel starts.
A publicly known UEFI bootkit proof of concept mentioned as part of the evolution of UEFI bootkits targeting Windows systems.
Open-source UEFI bootkit (driver + loader) repurposed by Glupteba: replaces Windows Boot Manager with a custom loader that loads a UEFI driver to patch the boot chain and disable PatchGuard and DSE at boot time, enabling stealthy persistence and facilitating unsigned kernel driver loading.
Proof-of-concept UEFI bootkit referenced as background context (not described as used in the ESPecter campaign).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.