Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Press ROOT to Continue - Detecting OSX and Windows Bootkits with RDFU

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore a comprehensive analysis of UEFI-based rootkits and malware detection in this Black Hat USA 2013 conference talk. Delve into the Rootkit Detection Framework for UEFI (RDFU), a unified set of tools developed to combat emerging threats across various UEFI implementations. Examine a sample bootkit for Apple OSX, designed specifically for testing purposes, which demonstrates sophisticated infection techniques and functionalities such as FileVault password sniffing, privilege escalation, and file hiding. Learn about the UEFI conceptual overview, runtime services, and the inner workings of RDFU. Gain insights into bootkit workflows and process hiding techniques. Discover the potential applications of this open-source technology in addressing UEFI-based security challenges.

Syllabus

Intro
Our motivation
Booting with BIOS
UEFI Conceptual overview
UEFI images
UEFI Runtime services
How does RDFU work?
Bootkit workflow
Hiding processes

Taught by

Black Hat

Reviews

Start your review of Press ROOT to Continue - Detecting OSX and Windows Bootkits with RDFU

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.