Security evidence below the operating system
GGFW is GGSEC's read-only firmware acquisition and platform-security framework for Windows and UEFI environments. It combines live hardware evidence, verified SPI and GPU firmware acquisition, offline binary analysis and configuration correlation in one reproducible workflow.
Unlike a simple configuration checker, GGFW records the detected platform profile, confidence level, raw evidence and interpretation path behind every security verdict.
Collect chipset, CPU, PCI, SPI, SMM, memory, Secure Boot and platform-lock evidence through the signed GGFW Windows driver.
Boot GGFW independently of the installed operating system to inspect the platform, acquire firmware evidence and store timestamped reports on USB media.
Analyse previously acquired SPI, BIOS, update and Option ROM images without accessing the source hardware.
Controller lockdown alone does not prove BIOS write protection. GGFW correlates the complete protection state before issuing a verdict.
Automatic discovery of CPU, host bridge, PCH/eSPI and SPI-controller access model with explicit confidence grading.
Full and ranged SPI acquisition with automatic flash-size detection, resume support, read-back verification and SHA-256 evidence.
BIOS/SPI protection, SMM and CPU trust controls, PCH configuration, DMA evidence and Secure Boot configuration evidence.
Classify images and inspect Intel platform structures, UEFI volumes, NVRAM, FIT, microcode and integrity evidence.
Enumerate display devices, acquire PCI Option ROMs, validate PC-AT and EFI/GOP image chains and extract embedded GPU firmware from larger images.
Compare active SPI-controller access evidence with descriptor configuration stored inside the acquired firmware image.
Heuristic PE/DXE/PEI module analysis across nested and compressed UEFI volumes to surface implants and dual-use persistence hiding among legitimate firmware.
Parse and export EDK2 VSS/VSS2, AMI NVAR (dual-bank dedupe), Phoenix EVSA and Insyde FDC recovery stores, with Secure Boot variable evidence and primary-vs-recovery diff.
Query the Intel Management Engine version at runtime over HECI (MKHI GET_FW_VERSION), with offline ME/CSE version candidates from the SPI image as fallback.
One command produces a client-ready evidence bundle: offline analysis, PE hits, NVRAM export, Secure Boot correlation, S3 boot script, MEI, and an executive SUMMARY + hashed MANIFEST.
Offline engagement against a real OEM notebook BIOS image. The PE/DXE triage flagged one high-interest module among 188 legitimate ones; analyst identification confirmed a firmware-resident anti-theft persistence agent (Absolute Computrace / LoJack) — a legitimate OEM feature that behaves, technically, like an implant.
Heuristic triage surfaced the module in seconds; identification is analyst-led. Image vendor anonymised — the component ships across many notebook brands.
GGFW provides read-only software-side evidence collection and correlation. In suspected firmware compromise cases, external hardware acquisition may still be required as the forensic reference method.
Learn why a software dump is useful for trusted systems and diagnostics, but should not be treated as final proof of firmware integrity on a potentially compromised host.
Read methodology note →No SPI erase, no SPI programming, no general-purpose MMIO write interface, no general-purpose PCI write interface and no public MSR write interface.
Driver operations are restricted to allowlisted reads and accessible only to Administrators and SYSTEM.
Read-back verification, SHA-256 artifact hashes, timestamped names, anonymous machine IDs and non-overwriting report output.
Clear module verdicts such as [FAIL] common.bios_wp, [OK] common.spi_lock and [N/A] common.smm_lock.
Stable module identifiers, schema-based results, evidence fields, confidence levels and machine-readable status values.
Timestamped reports, firmware dumps, SHA256 files, offline-analysis JSON and release manifests for repeatable review.
GGSEC performs acquisition, platform-security validation and analyst-led firmware investigation using GGFW and complementary laboratory tooling.