See it in action
A full offline engagement on a real notebook BIOS
Complete, unedited console output from a single GGFW --engagement run (v0.11.1) against a 16 MiB HP / InsydeH2O SPI image — Intel Flash Descriptor decode, ME/CSE FPT partition table, UEFI firmware-volume inventory, PE/DXE implant triage, offline dispatch reconstruction, and NVRAM & YARA export. It surfaces a CRITICAL SPI descriptor access-control weakness (the Host/BIOS master can write non-BIOS flash regions) and one high-interest module — an Absolute anti-theft persistence agent carrying a CreateRemoteThread host-injection primitive: a legitimate OEM feature that behaves, technically, like an implant.
ggfw --engagement hp_f1.BIN --offline-only --yara tools\yara
$ ./ggfw --engagement "analysis/dumps/hp_f1.BIN" --offline-only --yara tools\yara
[INFO] GUID DB: source=LVFS/bundled records=12652
GGSec Firmware Toolkit v0.11.1 Beta
Engagement package: analysis/out\engagement_hp_f1
Dump: analysis/dumps/hp_f1.BIN
Running offline analyze (pe_hits + nvram + yara)...
[N/A] Coreboot artifact export: FMAP/CBFS not recognized
GGSec Firmware Toolkit v0.11.1 Beta
(c) 2026 GG Advanced IT Security
Firmware dumping, extraction and platform security analysis
Module: offline SPI image analysis
Scan timestamp: 2026-08-02 20:23:51 UTC
File: analysis/dumps/hp_f1.BIN
Size: 16777216 bytes (16.00 MiB)
SHA-256: cbb6a90f247132b09509dab7025982d7e67b3073eb7c62b2523c9850cf9becb3
[OK] Intel Flash Descriptor signature at 0x10: 5A A5 F0 0F
FLMAP0=0x03040003 FLMAP1=0x12100206 FLMAP2=0x00210120 FRBA=0x0040 FMBA=0x0060
Intel Flash Descriptor map decode
FLMAP0=0x03040003 FCBA=0x0030 NC(raw=0, count=1) FRBA=0x0040 NR(raw=3, count=4)
FLMAP1=0x12100206 FMBA=0x0060 NM(raw=2, count=3) FISBA=0x0100 ISL(raw=18)
FLMAP2=0x00210120 FMSBA=0x0200 MSL(raw=1) FPSBA=0x0210 PSL(raw=0)
[INFO] FLMAP strap-field names can vary across Intel descriptor generations; raw values are retained for review.
SPI Flash Descriptor access control
FMBA=0x0060
BIOS/Host CPU: raw=0x0A0B0000 offset=0x0060 requester_id=0x0000 read={Descriptor,BIOS,GbE} (0x0B) write={BIOS,GbE} (0x0A)
expanded read={Descriptor,BIOS,GbE} write={BIOS,GbE}
Intel ME: raw=0x0C0D0000 offset=0x0064 requester_id=0x0000 read={Descriptor,ME,GbE} (0x0D) write={ME,GbE} (0x0C)
expanded read={Descriptor,ME,GbE} write={ME,GbE}
GbE: raw=0x08080118 offset=0x0068 requester_id=0x0118 read={GbE} (0x08) write={GbE} (0x08)
expanded read={GbE} write={GbE}
[OK] Host CPU/BIOS master cannot write the Flash Descriptor region
[FAIL] Host CPU/BIOS master has write access to enabled non-BIOS region(s): active_write={BIOS,GbE} (0x0A) raw_write={BIOS,GbE} (0x0A)
[FAIL] common.spi_desc equivalent - descriptor permissions are permissive for Host CPU/BIOS master
SPI regions from descriptor
Descriptor: raw=0x00000000 0x00000000-0x00000FFF (4 KiB)
BIOS : raw=0x0FFF0B00 0x00B00000-0x00FFFFFF (5120 KiB)
ME : raw=0x0AFF0003 0x00003000-0x00AFFFFF (11252 KiB)
GbE : raw=0x00020001 0x00001000-0x00002FFF (8 KiB)
PDR : raw=0x00001FFF invalid/disabled
Intel ME marker
[OK] $FPT found at 0x003010
[INFO] Content-inferred Intel ME marker starts at 0x003010
Intel ME / CSE FPT partition table
FPT marker=0x003010 header_base=0x003000 ME_region_base=0x003000 entries=23 header=0x30 header_version=0x20 entry_version=0x10 checksum=OK confidence=medium
[WARN] FPT table parsed with structural warnings; treat affected entries as candidates
- FPT contains non-printable partition name(s)
raw-E0 15 00 20: offset=0x000003C0 absolute=0x000033C0 size=0x00000040 flags=0x00000783 bounds=OK probable_role=PSVN role_confidence=low
FOVD: offset=0x00000400 absolute=0x00003400 size=0x00000C00 flags=0x00000783 bounds=OK
MDES: offset=0x00001000 absolute=0x00004000 size=0x00001000 flags=0x00002383 bounds=OK
FCRS: offset=0x00002000 absolute=0x00005000 size=0x00001000 flags=0x00002383 bounds=OK
EFFS: offset=0x00003000 absolute=0x00006000 size=0x000DC000 flags=0x00002704 bounds=OK
BIAL: offset=0xFFFFFFFF absolute=indirect size=0x0000ADD0 flags=0x00000002 bounds=INDIRECT
BIEL: offset=0xFFFFFFFF absolute=indirect size=0x00003000 flags=0x00000002 bounds=INDIRECT
BIIS: offset=0xFFFFFFFF absolute=indirect size=0x00036000 flags=0x00000002 bounds=INDIRECT
NVCL: offset=0xFFFFFFFF absolute=indirect size=0x00010511 flags=0x00000002 bounds=INDIRECT
NVCM: offset=0xFFFFFFFF absolute=indirect size=0x0000493F flags=0x00000002 bounds=INDIRECT
NVCP: offset=0xFFFFFFFF absolute=indirect size=0x0000A553 flags=0x00000002 bounds=INDIRECT
NVJC: offset=0xFFFFFFFF absolute=indirect size=0x00004000 flags=0x00000002 bounds=INDIRECT
NVKR: offset=0xFFFFFFFF absolute=indirect size=0x0001257D flags=0x00000002 bounds=INDIRECT
NVOS: offset=0xFFFFFFFF absolute=indirect size=0x00034AB9 flags=0x00000002 bounds=INDIRECT
NVSH: offset=0xFFFFFFFF absolute=indirect size=0x00007609 flags=0x00000002 bounds=INDIRECT
NVTD: offset=0xFFFFFFFF absolute=indirect size=0x00001EAC flags=0x00000002 bounds=INDIRECT
PLDM: offset=0xFFFFFFFF absolute=indirect size=0x0000A000 flags=0x00000002 bounds=INDIRECT
GLUT: offset=0x000DF000 absolute=0x000E2000 size=0x00004000 flags=0x00002783 bounds=OK
LOCL: offset=0x000E3000 absolute=0x000E6000 size=0x00004000 flags=0x00002780 bounds=OK
WCOD: offset=0x000E7000 absolute=0x000EA000 size=0x00059000 flags=0x00002780 bounds=OK
MDMV: offset=0x00140000 absolute=0x00143000 size=0x00040000 flags=0x00002780 bounds=OK
FTPR: offset=0x00180000 absolute=0x00183000 size=0x000CA000 flags=0x00002780 bounds=OK
NFTP: offset=0x0024A000 absolute=0x0024D000 size=0x0025A000 flags=0x00002780 bounds=OK
[INFO] FPT offsets are interpreted relative to the descriptor-declared ME region when available.
[INFO] NV*/indirect FPT entries with offset=0xFFFFFFFF are non-resident/indirect entries; physical storage is typically resolved through EFFS/FDOC/runtime metadata.
Intel ME / CSE manifest/version analysis
[OK] Probable legacy ME/CSE version: 8.1.0.1265 source=FTPR/NFTP relative=0x24 method=legacy_redundant_partition_match confidence=medium-high
note: not signed-manifest parsed; validated by redundant partition match
Intel advisory reference (version lookup only):
[INFO] Version search URL: https://www.intel.com/content/www/us/en/security-center/advisory.html?version=8.1.0.1265
[INFO] This offline version candidate does not determine CVE exposure; confirm the exact platform and current Intel advisory applicability separately
[INFO] 15 additional heuristic candidate(s) hidden; rerun with --verbose to show them
Manifest signature anchors (preferred partitions, first 32 KiB):
[INFO] FTPR $MN2 abs=0x0018301C rel=0x1C version=n/a
[INFO] NFTP $MN2 abs=0x0024D01C rel=0x1C version=n/a
[INFO] Manifest anchors=2 (signature presence only; not cryptographic verification)
[INFO] ME/CSE SKU string candidates:
candidate 0: value=TXE source=FTPR offset=0x0018F252 confidence=low
Dump scope assessment
Scope: FULL SPI chip candidate (IFD present; all declared regions in image)
scope_id: full_spi_chip_candidate
Image size: 16777216 bytes (16.00 MiB)
IFD present: yes
Declared regions in-bounds: 4/4
Declared region span end: 0x01000000
Covers all declared regions: yes
ME region fully in image: yes
ME content: present
ME host-unreadable/blank: no
$FPT present: yes
UEFI FV payload: yes
[INFO] Image size covers all descriptor-declared regions (Descriptor/BIOS/ME/GbE/PDR as valid).
UEFI firmware volumes
FV base=0xB30000 sig=0xB30028 len=0x250000 end=0xD80000 hdr=0x48 checksum=OK bounds=OK structural=OK
FV content: files=1 invalid_headers=0 hint=DXE/application FV types={DXE_CORE:1}
FFS inventory: fs=FFSv1 supported=yes complete=yes files=1 valid=1 deleted=0 exec=0 pe32=0 te=0 bad_sum=0 bad_exec=0 opaque=0 nested_fv=1 expanded=1 nested_files=235 nested_exec=213
FV base=0xEE0000 sig=0xEE0028 len=0x40000 end=0xF20000 hdr=0x48 checksum=BAD bounds=OK structural=OK
FV base=0xF20000 sig=0xF20028 len=0x50000 end=0xF70000 hdr=0x48 checksum=BAD bounds=OK structural=BAD
FV base=0xF90000 sig=0xF90028 len=0x70000 end=0x1000000 hdr=0x48 checksum=OK bounds=OK structural=BAD
FV content: files=62 invalid_headers=0 hint=PEI/SEC FV types={SECURITY_CORE:1,PEI_CORE:1,PEIM:52,RAW:1,FREEFORM:5,PAD:2}
[OK] Inferred UEFI FV payload coverage: 0xB30000-0x1000000 (4 top-level FV headers)
[INFO] Descriptor BIOS region differs from content-inferred FV coverage: descriptor=0x00B00000-0x00FFFFFF fv_payload=0x00B30000-0x00FFFFFF
UEFI FV coverage analysis
Merged FV coverage:
0xB30000-0xD80000 size=0x250000
0xEE0000-0xF70000 size=0x90000
0xF90000-0x1000000 size=0x70000
FV gaps:
[INFO] Gap between top-level FVs: 0xD80000-0xEE0000 size=0x160000
[INFO] Gap between top-level FVs: 0xF70000-0xF90000 size=0x20000
Intel ME / CSE region coverage analysis
Descriptor-declared ME region: 0x00003000-0x00AFFFFF
First inferred UEFI FV starts at 0x00B30000
Physical FPT partition coverage:
0x000033C0-0x004A7000 size=0x4A3C40
FPT table metadata coverage:
0x00003010-0x00003320 size=0x310
Unidentified ME/CSE-region areas:
[INFO] 0x004A7000-0x00B00000 size=0x659000 (padding/OEM/reserved/EFFS-managed data candidate; marker_scan=none)
Region SHA-256 inventory
Descriptor (descriptor): range=0x00000000-0x00000FFF size=0x1000 sha256=34a52280d5f256bfaa75cc009ba21a68b3397baa78f5d63873cffcb9c59cd300
BIOS (descriptor): range=0x00B00000-0x00FFFFFF size=0x500000 sha256=0a8141aba2dc19965a570b738d0bd214626de0a115ad618a63cb63c57ba4bcda
ME (descriptor): range=0x00003000-0x00AFFFFF size=0xAFD000 sha256=2e261d4e480bb3f93422c2cc1beb63b54cd6e0c7acfa4f2df0b60257973aff50
GbE (descriptor): range=0x00001000-0x00002FFF size=0x2000 sha256=9d20f3df71adba32d397f94f177f785958f636ac9143ecc6c09868ef5a988bf8
UEFI FV payload (content-inferred): range=0x00B30000-0x00FFFFFF size=0x4D0000 sha256=c547209f04e4b815556dd3ce73e15b447526de81fc61d66a25fe31c9b50b2c62
UEFI PE/DXE module risk scan
[INFO] Heuristic offline PE/DXE anomaly scan for implant triage; not signature AV and not a clean/malware verdict
scanned: volumes=2 files=236 executables=213 pe_te=213 opaque_containers=0
findings: high=1 medium=1 low=0 info=0 interesting_modules=1 smm_modules=0
Interesting PE/DXE modules (triage priority)
[INFO] Ranked by host-API / W+X / packaging heuristics; extract with --extract-pe
[WARN] #1 score=53 guid=7FECA262-E72B-4262-B3F2-43A308318E73 type=APPLICATION pe=PE32+ sub=10 off=0x002E30C8
reasons=pe_suspicious_string,pe_host_injection_api
hot_imports=ascii:CreateRemoteThread
entropy=6.31 entry_rva=0x1B60
payload_sha256=c711349dacd9f4a8...
extract_hint=filename contains 7FECA262-E72B-4262-B3F2-43A308318E73
PE/DXE anomaly findings
[WARN] pe_host_injection_api guid=7FECA262-E72B-4262-B3F2-43A308318E73 type=APPLICATION pe=PE32+ off=0x002E30C8
ascii:CreateRemoteThread
[INFO] pe_suspicious_string guid=7FECA262-E72B-4262-B3F2-43A308318E73 type=APPLICATION pe=PE32+ off=0x002E30C8
ASCII marker "CreateRemoteThread" in PE body
[WARN] High-severity PE/DXE anomalies present - prioritize manual implant review
UEFI module dispatch reconstruction (offline partial order)
Modules=214 DEPEX=154 valid=154 malformed=0 limits=0 apriori_ignored_depex=0 hard_edges=182 apriori_files=0 apriori_entries=0 depex_interface_operands=86 timeline_stages=4
Mainline track: SEC -> PEI -> DXE
MM/SMM track: separate; its placement relative to arbitrary DXE/BDS modules is not proven offline
Boot-policy track: applications are candidates selected by BDS policy, not automatically dispatched stages
[INFO] Waves are earliest eligible groups from phase gates, Apriori and DEPEX BEFORE/AFTER; they are not measured boot timestamps.
[INFO] Boolean DEPEX GUID operands preserve OR/NOT ambiguity; provider modules are not guessed without call-site evidence.
mainline stage 0 (PEI wave 0) [UNORDERED ELIGIBLE SET] modules=3
PEIM PpisNeededByDxeCore [4D37DA42-3A0C-4EDA-B9EB-BC0E1DB4713B] @0xF028 certainty=eligible_set pred=0 succ=0 depex=boolean/valid
PEIM PchS3Peim [271DD6F2-54CB-45E6-8585-8C923C1AC706] @0x6EE490 certainty=eligible_set pred=0 succ=0 depex=boolean/valid
PEIM SmmRelocPeim [ABB74F50-FD2D-4072-A321-CAFC72977EFA] @0x714120 certainty=eligible_set pred=0 succ=0 depex=boolean/valid
mainline stage 1 (DXE wave 0) [UNORDERED ELIGIBLE SET] modules=2
DXE_CORE DxeMain [35B898CA-B6A9-49CE-8C72-904735CC49B7] @0x58 certainty=eligible_set pred=0 succ=182
DXE_CORE FvMainCompact [4A538818-5AE0-4EB2-B2EB-488B23657022] @0xB30048 certainty=eligible_set pred=0 succ=0
mainline stage 2 (DXE wave 1) [UNORDERED ELIGIBLE SET] modules=182
DXE_DRIVER Smbios [EAF59C0E-BD46-413A-9AE9-DD9F6D1A927D] @0x12138 certainty=eligible_set pred=1 succ=0 depex=boolean/valid
DXE_DRIVER HpQuickLookTrebuchet [FEA2BC49-33D1-4D3C-9B22-8B0D4A798109] @0x16CD8 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=4
DXE_DRIVER HpStringInterface [7367B3B6-DAAF-4A23-9287-373F47FA2BCB] @0x1D198 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=2
DXE_DRIVER CmosChecksum [ED31ED0E-E974-4565-9705-4CA960C5567C] @0x26928 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1
DXE_DRIVER MemoryOverwrite [53AC75F6-D2F2-4538-A0A3-029D5FA79DC7] @0x27080 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=2
DXE_DRIVER HpSmartAdapterStatus [2EA1CB9E-B051-44F3-844C-31E5265D2F8D] @0x27B50 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1
DXE_DRIVER HpThermalDiagnostic [A804C9DE-8CF4-483A-9D25-4874F6CDDDAB] @0x28378 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1
DXE_DRIVER OwnerShip [3B7F9DD6-BA6A-4479-AA17-E56C6E07E371] @0x29BA0 certainty=eligible_set pred=1 succ=0 implicit_dxe_arch_protocols=yes
DXE_DRIVER HpGraphicalFirmwareInterfaceStringsSubcomponent [8F2B9D3B-9AE8-4468-8F60-84A1D36564CC] @0x2A790 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1
DXE_DRIVER HpGraphicalFirmwareInterfaceFontSubcomponent [85D5DF6C-E3A1-11DB-9706-00E081611600] @0x30848 certainty=eligible_set pred=1 succ=0 depex=boolean/valid
DXE_DRIVER HpGraphicalFirmwareInterfaceFullFontSubcomponent [5D8AFDDF-5C95-4DA5-BB46-832F0D4BBC76] @0x3A488 certainty=eligible_set pred=1 succ=0 depex=boolean/valid
DXE_DRIVER HpGraphicalFirmwareInterface [85D5DF6C-E3A1-11DB-9706-00E08161165F] @0xBF4F0 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=6
... 170 additional same-stage modules; use --verbose or module-order.csv
boot_policy stage 0 (BDS/APP wave 0) [UNORDERED ELIGIBLE SET] modules=27
APPLICATION HpDiagsDriver [C998C52D-47D2-495E-AFF7-483A2A3D9DF1] @0x29C850 certainty=eligible_set pred=0 succ=0
APPLICATION AbsoluteDriver [7FECA262-E72B-4262-B3F2-43A308318E73] @0x2E30C8 certainty=eligible_set pred=0 succ=0
APPLICATION Dhcp6Dxe [ABAD63B0-8935-433B-9DD7-2EF141D96E23] @0x425F80 certainty=eligible_set pred=0 succ=0
APPLICATION Ip6Dxe [6D5BDEC4-D8EE-46F1-B058-88D5F1EBD3C8] @0x430DF0 certainty=eligible_set pred=0 succ=0
APPLICATION IpSecDxe [4EF2DFBF-1E17-48A0-A08E-76F7C5C76213] @0x44D760 certainty=eligible_set pred=0 succ=0
APPLICATION Mtftp6Dxe [8D2313D8-213E-4328-B8E2-E16DAB8D1EEF] @0x4D3590 certainty=eligible_set pred=0 succ=0
APPLICATION TcpDxe [273F74EA-68F5-4498-B8E4-7C3646DB59AA] @0x4DCD20 certainty=eligible_set pred=0 succ=0
APPLICATION Udp6Dxe [04F21AF5-D001-42E8-BC3E-32CFE6A4D309] @0x4EFF50 certainty=eligible_set pred=0 succ=0
APPLICATION MnpDxe [C326CB94-81A9-4977-99D8-0B6FDF0258BC] @0x4F9B60 certainty=eligible_set pred=0 succ=0
APPLICATION SnpDxe [614070E0-289D-4055-A41B-4F19953D0E21] @0x504230 certainty=eligible_set pred=0 succ=0
APPLICATION DpcDxe [4A40BB4C-5AA1-433B-AD5F-543C0F7940B4] @0x50B820 certainty=eligible_set pred=0 succ=0
APPLICATION UefiPxeBcDxe [F77C2C86-585F-46D0-AB78-8BB6A8EB40B8] @0x50C110 certainty=eligible_set pred=0 succ=0
... 15 additional same-stage modules; use --verbose or module-order.csv
[OK] All bounded DEPEX/order evidence parsed; runtime scheduler effects remain outside offline proof
UEFI host execution evidence (bounded offline)
complete=no call_complete=no export_complete=no producer_resolution_complete=no
inventories=2 physical_executables=213 quick_disasm_scans=212 call_sites=12639 interfaces=86 consumers=331
calls: direct_internal=8664 direct_external=158 unresolved_indirect=3817
interface consumers: positive=297 ambiguous=34 producers_resolved=0
exports: executables=0 unique_names=0
[INFO] Exports are executable identity evidence only and never protocol/PPI producer proof.
[REVIEW] call 1 executable=0 modules=1 rva=0x339 kind=indirect_register
[REVIEW] call 32 executable=0 modules=1 rva=0x708 kind=indirect_register
[REVIEW] call 40 executable=0 modules=1 rva=0xAA8 kind=indirect_register
[REVIEW] call 42 executable=0 modules=1 rva=0xC61 kind=indirect_register
[REVIEW] call 43 executable=0 modules=1 rva=0xCA1 kind=indirect_register
[REVIEW] call 91 executable=0 modules=1 rva=0x1A67 kind=indirect_register
[REVIEW] call 92 executable=0 modules=1 rva=0x1A92 kind=indirect_register
[REVIEW] call 122 executable=0 modules=1 rva=0x26E2 kind=indirect_register
[REVIEW] call 163 executable=0 modules=1 rva=0x2DAA kind=indirect_register
[REVIEW] call 280 executable=0 modules=1 rva=0x43AE kind=indirect_register
[REVIEW] call 281 executable=0 modules=1 rva=0x43D3 kind=indirect_register
[REVIEW] call 300 executable=0 modules=1 rva=0x4832 kind=indirect_register
[INFO] +3963 additional unresolved/external calls in uefi-execution.json
[REVIEW] interface-consumer module=101 protocol=1C0C34F6-D380-41FA-A049-8AD06C1A66AA certainty=ambiguous
[REVIEW] interface-consumer module=4 protocol=1E5668E2-8481-11D4-BCF1-0080C73C8881 certainty=ambiguous
[REVIEW] interface-consumer module=42 protocol=1E5668E2-8481-11D4-BCF1-0080C73C8881 certainty=ambiguous
[REVIEW] interface-consumer module=117 protocol=1E5668E2-8481-11D4-BCF1-0080C73C8881 certainty=ambiguous
[REVIEW] interface-consumer module=117 protocol=2F707EBB-4A1A-11D4-9A38-0090273FC14D certainty=ambiguous
[REVIEW] interface-consumer module=117 protocol=389F751F-1838-4388-8390-CD8154BD27F8 certainty=ambiguous
[REVIEW] interface-consumer module=191 protocol=389F751F-1838-4388-8390-CD8154BD27F8 certainty=ambiguous
[REVIEW] interface-consumer module=191 protocol=493B5BAC-BB9E-4BF5-8379-20E2ACA98541 certainty=ambiguous
[REVIEW] interface-consumer module=42 protocol=4CF5B200-68B8-4CA5-9EEC-B23E3F50029A certainty=ambiguous
[REVIEW] interface-consumer module=4 protocol=9042A9DE-23DC-4A38-96FB-7ADED080516A certainty=ambiguous
[REVIEW] interface-consumer module=14 protocol=9042A9DE-23DC-4A38-96FB-7ADED080516A certainty=ambiguous
[REVIEW] interface-consumer module=42 protocol=9042A9DE-23DC-4A38-96FB-7ADED080516A certainty=ambiguous
[INFO] +22 additional ambiguous consumers in uefi-execution.json
[WARN] dispatch module has no physical executable mapping: 0
[WARN] protocol/PPI producers unresolved: QuickDisasm exposes call edges but not service-call plus GUID-argument proof
PE/TE extract (YARA/AV triage)
[OK] extracted=1 skipped=212 hit_files=1 volumes=1 dir=analysis/out\engagement_hp_f1\pe_hits
[INFO] Interesting modules use .HIT extension under pe/ (easy filter)
manifest_csv=analysis/out\engagement_hp_f1\pe_hits/pe_extract_manifest.csv
manifest_json=analysis/out\engagement_hp_f1\pe_hits/pe_extract_manifest.json
[INFO] PE/TE modules extracted for offline YARA/AV triage; not an in-process signature engine
[WARN] HIT path=pe/002E30C8_7FECA262-E72B-4262-B3F2-43A308318E73_APPLICATION_PE32_.HIT score=53 guid=7FECA262-E72B-4262-B3F2-43A308318E73 kind=PE32+ str=CreateRemoteThread
[OK] YARA scan complete match_lines=1 report=analysis/out\engagement_hp_f1\pe_hits/yara_hits.txt
[WARN] YARA reported match lines - review analysis/out\engagement_hp_f1\pe_hits/yara_hits.txt
UEFI variable store analysis
[INFO] EfiSystemNvDataFvGuid volume not found by GUID scan
[INFO] Marker-only VSS/VSS2 candidate(s): 2 (markers are not validated variable records)
NVRAM variable export
[OK] exported vars written=0 skipped=0 dir=analysis/out\engagement_hp_f1\nvram
[INFO] No complete primary store for export
[INFO] No complete FDC/recovery store for export
manifest_csv=analysis/out\engagement_hp_f1\nvram/nvram_manifest.csv
manifest_json=analysis/out\engagement_hp_f1\nvram/nvram_manifest.json
[INFO] Diff example: fc /b primary\PK_*.bin recovery\PK_*.bin
AMI NVAR export
[OK] AMI NVAR records=0 written=0 skipped=0 deduped_mirrors=0 effective=0 nested_containers=0 named_exports~=0 banks=0
[OK] GUID resolve: full=0 (store_lookup=0 inline_or_prior=0) unresolved_idx=0 StdDefaults_resolved=0
dir=analysis/out\engagement_hp_f1\nvram/nvar
manifest_csv=analysis/out\engagement_hp_f1\nvram/nvar_manifest.csv
manifest_json=analysis/out\engagement_hp_f1\nvram/nvar_manifest.json
[INFO] No AMI NVAR records decoded (image may use VSS/EVSA only)
Phoenix EVSA variable export
[OK] EVSA stores=0 data_payloads_written=0 rows=0
dir=analysis/out\engagement_hp_f1\nvram/evsa
manifest_csv=analysis/out\engagement_hp_f1\nvram/evsa_manifest.csv
[INFO] No Phoenix EVSA store headers found (common on AMI/Insyde images)
[INFO] Secure Boot UTF-16 name hints exist, but no active record was validated
[INFO] Offline variable-store evidence cannot prove runtime Secure Boot enablement or select the active recovery copy
Firmware family
[OK] Primary=insyde_h2o confidence=medium
[INFO] InsydeH2O / OEM notebook UEFI candidate confidence=medium
[OK] VSS/VSS2 variable-store style present
Marker hits: Hewlett-Packard=14
[INFO] InsydeH2O verdict is heuristic; capsule/tool-specific structures require dedicated Insyde parsing
Summary
Dump scope: FULL SPI chip candidate (IFD present; all declared regions in image) [full_spi_chip_candidate]
This looks like a full raw Intel SPI image when descriptor, ME marker,
and UEFI firmware volumes are present. UEFI payload often starts after
descriptor/ME regions, so offset 0x0 is not expected to look like a PE/UEFI file.
[FAIL] SPI descriptor access-control summary: Host CPU/BIOS master has overly broad write permissions.
Security posture
Overall: CRITICAL (1 FAIL, 0 WARN, 0 INFO)
Critical findings:
- Host CPU/BIOS master write access spans non-BIOS SPI regions
Attack surface summary
- Host CPU can write BIOS region -> firmware modification risk depends on BIOS_CNTL/PRx/SMM protections at runtime
--- engagement correlate ---
match=0 hash_mismatch=0 attr_mismatch=0 live_only=0 dump_only=5 missing_both=4 live_error=0
--- engagement s3 ---
live_verdict=skipped entry_protection=skipped markers=0 tables=0 targets=0
--- engagement mei ---
heci_devices=0 mkhi=none registry_version=none dump_versions=3 compare=n/a advisory_hints=1
[OK] Engagement package: analysis/out\engagement_hp_f1
[OK] SUMMARY: analysis/out\engagement_hp_f1\SUMMARY.txt
[OK] SUMMARY.html (client annex): analysis/out\engagement_hp_f1\SUMMARY.html
[OK] MANIFEST: analysis/out\engagement_hp_f1\MANIFEST.txt
[OK] Annex: correlate/ s3/ mei/
Read-only, offline analysis of an already-acquired image — no hardware touched. Heuristic triage surfaces candidates in seconds; every verdict states its confidence and identification stays analyst-led. The same run also writes a client-ready engagement package (SUMMARY, MANIFEST, per-region SHA-256, NVRAM/PE exports).