Firmware Acquisition · Platform Security · Offline Analysis

GGSec Firmware Toolkit

Security evidence below the operating system

GGFW is GGSEC's read-only firmware acquisition and platform-security framework for Windows and UEFI environments. It combines live hardware evidence, verified SPI and GPU firmware acquisition, offline binary analysis and configuration correlation in one reproducible workflow.

Version

v0.11.1 Beta

Operation

Read-only

Environments

Windows + UEFI
Watch the walkthrough

GGFW in action

A short walkthrough of the read-only firmware acquisition and platform-security workflow — from live evidence collection to offline image analysis.

Three operating modes

One workflow across live systems and offline images

Unlike a simple configuration checker, GGFW records the detected platform profile, confidence level, raw evidence and interpretation path behind every security verdict.

Live Windows Assessment

Collect chipset, CPU, PCI, SPI, SMM, memory, Secure Boot and platform-lock evidence through the signed GGFW Windows driver.

  • Platform information
  • Platform-security checks
  • Secure Boot variable evidence
  • Live-to-image access comparison

Pre-OS UEFI Environment

Boot GGFW independently of the installed operating system to inspect the platform, acquire firmware evidence and store timestamped reports on USB media.

  • BOOTX64.EFI workflow
  • BIOS-region acquisition
  • GPU device enumeration
  • Pre-OS platform assessment

Offline Firmware Analysis

Analyse previously acquired SPI, BIOS, update and Option ROM images without accessing the source hardware.

  • SPI and BIOS-region images
  • Intel descriptor and FPT structures
  • UEFI volumes, NVRAM and FIT
  • GPU Option ROM chains
Evidence-driven platform security

Validate protections, then correlate the evidence

ggfw --platform-security
GGSec Firmware Toolkit v0.11.1 Beta Module: platform security checks [FAIL] common.bios_wp BLE=0 · SMM_BWP=0 · PR coverage incomplete [OK] common.spi_lock FLOCKDN=1 · controller configuration locked [OK] common.smrr range=0xDF800000-0xDFFFFFFF · valid=1 [FAIL] common.memconfig required locks: 0xFFF · locked: 0xFFD Security posture: FAIL PASS=7 · FAIL=6 · WARN=2 · PARTIAL=1

Controller lockdown alone does not prove BIOS write protection. GGFW correlates the complete protection state before issuing a verdict.

Core capabilities

From raw flash image to structured evidence

Platform Discovery

Automatic discovery of CPU, host bridge, PCH/eSPI and SPI-controller access model with explicit confidence grading.

  • EXACT / FAMILY / GENERIC / UNKNOWN confidence
  • PCI, CPUID and chipset evidence
  • JEDEC vendor and flash capacity

Verified Firmware Acquisition

Full and ranged SPI acquisition with automatic flash-size detection, resume support, read-back verification and SHA-256 evidence.

  • No erase or programming functionality
  • Progress and throughput monitoring
  • Windows hardware sequencing and UEFI acquisition

Platform Security Assessment

BIOS/SPI protection, SMM and CPU trust controls, PCH configuration, DMA evidence and Secure Boot configuration evidence.

  • PASS, FAIL, WARN, INFO, N/A, ERROR and PARTIAL states
  • Unsupported and not-applicable conditions stay explicit

Offline Firmware Analysis

Classify images and inspect Intel platform structures, UEFI volumes, NVRAM, FIT, microcode and integrity evidence.

  • Structural integrity is reported separately from cryptographic authenticity
  • Per-region and per-partition hashes

GPU Firmware

Enumerate display devices, acquire PCI Option ROMs, validate PC-AT and EFI/GOP image chains and extract embedded GPU firmware from larger images.

  • Two independent reads before saving
  • 55 AA, PCIR, VID:DID and checksum validation

Live/Image Correlation

Compare active SPI-controller access evidence with descriptor configuration stored inside the acquired firmware image.

  • MATCH does not automatically mean SECURE
  • VERIFIED does not automatically mean PROTECTED

Firmware Implant Triage

Heuristic PE/DXE/PEI module analysis across nested and compressed UEFI volumes to surface implants and dual-use persistence hiding among legitimate firmware.

  • W+X, entropy, host-OS API/DLL and injection-primitive scoring
  • Interesting-module extraction (.HIT) + YARA integration
  • Heuristic triage, reported separately from any verdict

Deep NVRAM & Variable Store

Parse and export EDK2 VSS/VSS2, AMI NVAR (dual-bank dedupe), Phoenix EVSA and Insyde FDC recovery stores, with Secure Boot variable evidence and primary-vs-recovery diff.

  • Per-variable SHA-256 and attribute policy
  • Live Secure Boot vs offline store correlation

Runtime ME / HECI

Query the Intel Management Engine version at runtime over HECI (MKHI GET_FW_VERSION), with offline ME/CSE version candidates from the SPI image as fallback.

  • HECI device inventory and Host Firmware Status
  • Advisory SA-era hints only — never an auto-confirmed CVE

Engagement Package

One command produces a client-ready evidence bundle: offline analysis, PE hits, NVRAM export, Secure Boot correlation, S3 boot script, MEI, and an executive SUMMARY + hashed MANIFEST.

  • Optional golden-vs-suspect image diff
  • Reproducible, timestamped, SHA-256 artifacts
See it in action

A full offline engagement on a real notebook BIOS

Complete, unedited console output from a single GGFW --engagement run (v0.11.1) against a 16 MiB HP / InsydeH2O SPI image — Intel Flash Descriptor decode, ME/CSE FPT partition table, UEFI firmware-volume inventory, PE/DXE implant triage, offline dispatch reconstruction, and NVRAM & YARA export. It surfaces a CRITICAL SPI descriptor access-control weakness (the Host/BIOS master can write non-BIOS flash regions) and one high-interest module — an Absolute anti-theft persistence agent carrying a CreateRemoteThread host-injection primitive: a legitimate OEM feature that behaves, technically, like an implant.

ggfw --engagement hp_f1.BIN --offline-only --yara tools\yara
$ ./ggfw --engagement "analysis/dumps/hp_f1.BIN" --offline-only --yara tools\yara [INFO] GUID DB: source=LVFS/bundled records=12652 GGSec Firmware Toolkit v0.11.1 Beta Engagement package: analysis/out\engagement_hp_f1 Dump: analysis/dumps/hp_f1.BIN Running offline analyze (pe_hits + nvram + yara)... [N/A] Coreboot artifact export: FMAP/CBFS not recognized GGSec Firmware Toolkit v0.11.1 Beta (c) 2026 GG Advanced IT Security Firmware dumping, extraction and platform security analysis Module: offline SPI image analysis Scan timestamp: 2026-08-02 20:23:51 UTC File: analysis/dumps/hp_f1.BIN Size: 16777216 bytes (16.00 MiB) SHA-256: cbb6a90f247132b09509dab7025982d7e67b3073eb7c62b2523c9850cf9becb3 [OK] Intel Flash Descriptor signature at 0x10: 5A A5 F0 0F FLMAP0=0x03040003 FLMAP1=0x12100206 FLMAP2=0x00210120 FRBA=0x0040 FMBA=0x0060 Intel Flash Descriptor map decode FLMAP0=0x03040003 FCBA=0x0030 NC(raw=0, count=1) FRBA=0x0040 NR(raw=3, count=4) FLMAP1=0x12100206 FMBA=0x0060 NM(raw=2, count=3) FISBA=0x0100 ISL(raw=18) FLMAP2=0x00210120 FMSBA=0x0200 MSL(raw=1) FPSBA=0x0210 PSL(raw=0) [INFO] FLMAP strap-field names can vary across Intel descriptor generations; raw values are retained for review. SPI Flash Descriptor access control FMBA=0x0060 BIOS/Host CPU: raw=0x0A0B0000 offset=0x0060 requester_id=0x0000 read={Descriptor,BIOS,GbE} (0x0B) write={BIOS,GbE} (0x0A) expanded read={Descriptor,BIOS,GbE} write={BIOS,GbE} Intel ME: raw=0x0C0D0000 offset=0x0064 requester_id=0x0000 read={Descriptor,ME,GbE} (0x0D) write={ME,GbE} (0x0C) expanded read={Descriptor,ME,GbE} write={ME,GbE} GbE: raw=0x08080118 offset=0x0068 requester_id=0x0118 read={GbE} (0x08) write={GbE} (0x08) expanded read={GbE} write={GbE} [OK] Host CPU/BIOS master cannot write the Flash Descriptor region [FAIL] Host CPU/BIOS master has write access to enabled non-BIOS region(s): active_write={BIOS,GbE} (0x0A) raw_write={BIOS,GbE} (0x0A) [FAIL] common.spi_desc equivalent - descriptor permissions are permissive for Host CPU/BIOS master SPI regions from descriptor Descriptor: raw=0x00000000 0x00000000-0x00000FFF (4 KiB) BIOS : raw=0x0FFF0B00 0x00B00000-0x00FFFFFF (5120 KiB) ME : raw=0x0AFF0003 0x00003000-0x00AFFFFF (11252 KiB) GbE : raw=0x00020001 0x00001000-0x00002FFF (8 KiB) PDR : raw=0x00001FFF invalid/disabled Intel ME marker [OK] $FPT found at 0x003010 [INFO] Content-inferred Intel ME marker starts at 0x003010 Intel ME / CSE FPT partition table FPT marker=0x003010 header_base=0x003000 ME_region_base=0x003000 entries=23 header=0x30 header_version=0x20 entry_version=0x10 checksum=OK confidence=medium [WARN] FPT table parsed with structural warnings; treat affected entries as candidates - FPT contains non-printable partition name(s) raw-E0 15 00 20: offset=0x000003C0 absolute=0x000033C0 size=0x00000040 flags=0x00000783 bounds=OK probable_role=PSVN role_confidence=low FOVD: offset=0x00000400 absolute=0x00003400 size=0x00000C00 flags=0x00000783 bounds=OK MDES: offset=0x00001000 absolute=0x00004000 size=0x00001000 flags=0x00002383 bounds=OK FCRS: offset=0x00002000 absolute=0x00005000 size=0x00001000 flags=0x00002383 bounds=OK EFFS: offset=0x00003000 absolute=0x00006000 size=0x000DC000 flags=0x00002704 bounds=OK BIAL: offset=0xFFFFFFFF absolute=indirect size=0x0000ADD0 flags=0x00000002 bounds=INDIRECT BIEL: offset=0xFFFFFFFF absolute=indirect size=0x00003000 flags=0x00000002 bounds=INDIRECT BIIS: offset=0xFFFFFFFF absolute=indirect size=0x00036000 flags=0x00000002 bounds=INDIRECT NVCL: offset=0xFFFFFFFF absolute=indirect size=0x00010511 flags=0x00000002 bounds=INDIRECT NVCM: offset=0xFFFFFFFF absolute=indirect size=0x0000493F flags=0x00000002 bounds=INDIRECT NVCP: offset=0xFFFFFFFF absolute=indirect size=0x0000A553 flags=0x00000002 bounds=INDIRECT NVJC: offset=0xFFFFFFFF absolute=indirect size=0x00004000 flags=0x00000002 bounds=INDIRECT NVKR: offset=0xFFFFFFFF absolute=indirect size=0x0001257D flags=0x00000002 bounds=INDIRECT NVOS: offset=0xFFFFFFFF absolute=indirect size=0x00034AB9 flags=0x00000002 bounds=INDIRECT NVSH: offset=0xFFFFFFFF absolute=indirect size=0x00007609 flags=0x00000002 bounds=INDIRECT NVTD: offset=0xFFFFFFFF absolute=indirect size=0x00001EAC flags=0x00000002 bounds=INDIRECT PLDM: offset=0xFFFFFFFF absolute=indirect size=0x0000A000 flags=0x00000002 bounds=INDIRECT GLUT: offset=0x000DF000 absolute=0x000E2000 size=0x00004000 flags=0x00002783 bounds=OK LOCL: offset=0x000E3000 absolute=0x000E6000 size=0x00004000 flags=0x00002780 bounds=OK WCOD: offset=0x000E7000 absolute=0x000EA000 size=0x00059000 flags=0x00002780 bounds=OK MDMV: offset=0x00140000 absolute=0x00143000 size=0x00040000 flags=0x00002780 bounds=OK FTPR: offset=0x00180000 absolute=0x00183000 size=0x000CA000 flags=0x00002780 bounds=OK NFTP: offset=0x0024A000 absolute=0x0024D000 size=0x0025A000 flags=0x00002780 bounds=OK [INFO] FPT offsets are interpreted relative to the descriptor-declared ME region when available. [INFO] NV*/indirect FPT entries with offset=0xFFFFFFFF are non-resident/indirect entries; physical storage is typically resolved through EFFS/FDOC/runtime metadata. Intel ME / CSE manifest/version analysis [OK] Probable legacy ME/CSE version: 8.1.0.1265 source=FTPR/NFTP relative=0x24 method=legacy_redundant_partition_match confidence=medium-high note: not signed-manifest parsed; validated by redundant partition match Intel advisory reference (version lookup only): [INFO] Version search URL: https://www.intel.com/content/www/us/en/security-center/advisory.html?version=8.1.0.1265 [INFO] This offline version candidate does not determine CVE exposure; confirm the exact platform and current Intel advisory applicability separately [INFO] 15 additional heuristic candidate(s) hidden; rerun with --verbose to show them Manifest signature anchors (preferred partitions, first 32 KiB): [INFO] FTPR $MN2 abs=0x0018301C rel=0x1C version=n/a [INFO] NFTP $MN2 abs=0x0024D01C rel=0x1C version=n/a [INFO] Manifest anchors=2 (signature presence only; not cryptographic verification) [INFO] ME/CSE SKU string candidates: candidate 0: value=TXE source=FTPR offset=0x0018F252 confidence=low Dump scope assessment Scope: FULL SPI chip candidate (IFD present; all declared regions in image) scope_id: full_spi_chip_candidate Image size: 16777216 bytes (16.00 MiB) IFD present: yes Declared regions in-bounds: 4/4 Declared region span end: 0x01000000 Covers all declared regions: yes ME region fully in image: yes ME content: present ME host-unreadable/blank: no $FPT present: yes UEFI FV payload: yes [INFO] Image size covers all descriptor-declared regions (Descriptor/BIOS/ME/GbE/PDR as valid). UEFI firmware volumes FV base=0xB30000 sig=0xB30028 len=0x250000 end=0xD80000 hdr=0x48 checksum=OK bounds=OK structural=OK FV content: files=1 invalid_headers=0 hint=DXE/application FV types={DXE_CORE:1} FFS inventory: fs=FFSv1 supported=yes complete=yes files=1 valid=1 deleted=0 exec=0 pe32=0 te=0 bad_sum=0 bad_exec=0 opaque=0 nested_fv=1 expanded=1 nested_files=235 nested_exec=213 FV base=0xEE0000 sig=0xEE0028 len=0x40000 end=0xF20000 hdr=0x48 checksum=BAD bounds=OK structural=OK FV base=0xF20000 sig=0xF20028 len=0x50000 end=0xF70000 hdr=0x48 checksum=BAD bounds=OK structural=BAD FV base=0xF90000 sig=0xF90028 len=0x70000 end=0x1000000 hdr=0x48 checksum=OK bounds=OK structural=BAD FV content: files=62 invalid_headers=0 hint=PEI/SEC FV types={SECURITY_CORE:1,PEI_CORE:1,PEIM:52,RAW:1,FREEFORM:5,PAD:2} [OK] Inferred UEFI FV payload coverage: 0xB30000-0x1000000 (4 top-level FV headers) [INFO] Descriptor BIOS region differs from content-inferred FV coverage: descriptor=0x00B00000-0x00FFFFFF fv_payload=0x00B30000-0x00FFFFFF UEFI FV coverage analysis Merged FV coverage: 0xB30000-0xD80000 size=0x250000 0xEE0000-0xF70000 size=0x90000 0xF90000-0x1000000 size=0x70000 FV gaps: [INFO] Gap between top-level FVs: 0xD80000-0xEE0000 size=0x160000 [INFO] Gap between top-level FVs: 0xF70000-0xF90000 size=0x20000 Intel ME / CSE region coverage analysis Descriptor-declared ME region: 0x00003000-0x00AFFFFF First inferred UEFI FV starts at 0x00B30000 Physical FPT partition coverage: 0x000033C0-0x004A7000 size=0x4A3C40 FPT table metadata coverage: 0x00003010-0x00003320 size=0x310 Unidentified ME/CSE-region areas: [INFO] 0x004A7000-0x00B00000 size=0x659000 (padding/OEM/reserved/EFFS-managed data candidate; marker_scan=none) Region SHA-256 inventory Descriptor (descriptor): range=0x00000000-0x00000FFF size=0x1000 sha256=34a52280d5f256bfaa75cc009ba21a68b3397baa78f5d63873cffcb9c59cd300 BIOS (descriptor): range=0x00B00000-0x00FFFFFF size=0x500000 sha256=0a8141aba2dc19965a570b738d0bd214626de0a115ad618a63cb63c57ba4bcda ME (descriptor): range=0x00003000-0x00AFFFFF size=0xAFD000 sha256=2e261d4e480bb3f93422c2cc1beb63b54cd6e0c7acfa4f2df0b60257973aff50 GbE (descriptor): range=0x00001000-0x00002FFF size=0x2000 sha256=9d20f3df71adba32d397f94f177f785958f636ac9143ecc6c09868ef5a988bf8 UEFI FV payload (content-inferred): range=0x00B30000-0x00FFFFFF size=0x4D0000 sha256=c547209f04e4b815556dd3ce73e15b447526de81fc61d66a25fe31c9b50b2c62 UEFI PE/DXE module risk scan [INFO] Heuristic offline PE/DXE anomaly scan for implant triage; not signature AV and not a clean/malware verdict scanned: volumes=2 files=236 executables=213 pe_te=213 opaque_containers=0 findings: high=1 medium=1 low=0 info=0 interesting_modules=1 smm_modules=0 Interesting PE/DXE modules (triage priority) [INFO] Ranked by host-API / W+X / packaging heuristics; extract with --extract-pe [WARN] #1 score=53 guid=7FECA262-E72B-4262-B3F2-43A308318E73 type=APPLICATION pe=PE32+ sub=10 off=0x002E30C8 reasons=pe_suspicious_string,pe_host_injection_api hot_imports=ascii:CreateRemoteThread entropy=6.31 entry_rva=0x1B60 payload_sha256=c711349dacd9f4a8... extract_hint=filename contains 7FECA262-E72B-4262-B3F2-43A308318E73 PE/DXE anomaly findings [WARN] pe_host_injection_api guid=7FECA262-E72B-4262-B3F2-43A308318E73 type=APPLICATION pe=PE32+ off=0x002E30C8 ascii:CreateRemoteThread [INFO] pe_suspicious_string guid=7FECA262-E72B-4262-B3F2-43A308318E73 type=APPLICATION pe=PE32+ off=0x002E30C8 ASCII marker "CreateRemoteThread" in PE body [WARN] High-severity PE/DXE anomalies present - prioritize manual implant review UEFI module dispatch reconstruction (offline partial order) Modules=214 DEPEX=154 valid=154 malformed=0 limits=0 apriori_ignored_depex=0 hard_edges=182 apriori_files=0 apriori_entries=0 depex_interface_operands=86 timeline_stages=4 Mainline track: SEC -> PEI -> DXE MM/SMM track: separate; its placement relative to arbitrary DXE/BDS modules is not proven offline Boot-policy track: applications are candidates selected by BDS policy, not automatically dispatched stages [INFO] Waves are earliest eligible groups from phase gates, Apriori and DEPEX BEFORE/AFTER; they are not measured boot timestamps. [INFO] Boolean DEPEX GUID operands preserve OR/NOT ambiguity; provider modules are not guessed without call-site evidence. mainline stage 0 (PEI wave 0) [UNORDERED ELIGIBLE SET] modules=3 PEIM PpisNeededByDxeCore [4D37DA42-3A0C-4EDA-B9EB-BC0E1DB4713B] @0xF028 certainty=eligible_set pred=0 succ=0 depex=boolean/valid PEIM PchS3Peim [271DD6F2-54CB-45E6-8585-8C923C1AC706] @0x6EE490 certainty=eligible_set pred=0 succ=0 depex=boolean/valid PEIM SmmRelocPeim [ABB74F50-FD2D-4072-A321-CAFC72977EFA] @0x714120 certainty=eligible_set pred=0 succ=0 depex=boolean/valid mainline stage 1 (DXE wave 0) [UNORDERED ELIGIBLE SET] modules=2 DXE_CORE DxeMain [35B898CA-B6A9-49CE-8C72-904735CC49B7] @0x58 certainty=eligible_set pred=0 succ=182 DXE_CORE FvMainCompact [4A538818-5AE0-4EB2-B2EB-488B23657022] @0xB30048 certainty=eligible_set pred=0 succ=0 mainline stage 2 (DXE wave 1) [UNORDERED ELIGIBLE SET] modules=182 DXE_DRIVER Smbios [EAF59C0E-BD46-413A-9AE9-DD9F6D1A927D] @0x12138 certainty=eligible_set pred=1 succ=0 depex=boolean/valid DXE_DRIVER HpQuickLookTrebuchet [FEA2BC49-33D1-4D3C-9B22-8B0D4A798109] @0x16CD8 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=4 DXE_DRIVER HpStringInterface [7367B3B6-DAAF-4A23-9287-373F47FA2BCB] @0x1D198 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=2 DXE_DRIVER CmosChecksum [ED31ED0E-E974-4565-9705-4CA960C5567C] @0x26928 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1 DXE_DRIVER MemoryOverwrite [53AC75F6-D2F2-4538-A0A3-029D5FA79DC7] @0x27080 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=2 DXE_DRIVER HpSmartAdapterStatus [2EA1CB9E-B051-44F3-844C-31E5265D2F8D] @0x27B50 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1 DXE_DRIVER HpThermalDiagnostic [A804C9DE-8CF4-483A-9D25-4874F6CDDDAB] @0x28378 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1 DXE_DRIVER OwnerShip [3B7F9DD6-BA6A-4479-AA17-E56C6E07E371] @0x29BA0 certainty=eligible_set pred=1 succ=0 implicit_dxe_arch_protocols=yes DXE_DRIVER HpGraphicalFirmwareInterfaceStringsSubcomponent [8F2B9D3B-9AE8-4468-8F60-84A1D36564CC] @0x2A790 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=1 DXE_DRIVER HpGraphicalFirmwareInterfaceFontSubcomponent [85D5DF6C-E3A1-11DB-9706-00E081611600] @0x30848 certainty=eligible_set pred=1 succ=0 depex=boolean/valid DXE_DRIVER HpGraphicalFirmwareInterfaceFullFontSubcomponent [5D8AFDDF-5C95-4DA5-BB46-832F0D4BBC76] @0x3A488 certainty=eligible_set pred=1 succ=0 depex=boolean/valid DXE_DRIVER HpGraphicalFirmwareInterface [85D5DF6C-E3A1-11DB-9706-00E08161165F] @0xBF4F0 certainty=eligible_set pred=1 succ=0 depex=boolean/valid guid_operands=6 ... 170 additional same-stage modules; use --verbose or module-order.csv boot_policy stage 0 (BDS/APP wave 0) [UNORDERED ELIGIBLE SET] modules=27 APPLICATION HpDiagsDriver [C998C52D-47D2-495E-AFF7-483A2A3D9DF1] @0x29C850 certainty=eligible_set pred=0 succ=0 APPLICATION AbsoluteDriver [7FECA262-E72B-4262-B3F2-43A308318E73] @0x2E30C8 certainty=eligible_set pred=0 succ=0 APPLICATION Dhcp6Dxe [ABAD63B0-8935-433B-9DD7-2EF141D96E23] @0x425F80 certainty=eligible_set pred=0 succ=0 APPLICATION Ip6Dxe [6D5BDEC4-D8EE-46F1-B058-88D5F1EBD3C8] @0x430DF0 certainty=eligible_set pred=0 succ=0 APPLICATION IpSecDxe [4EF2DFBF-1E17-48A0-A08E-76F7C5C76213] @0x44D760 certainty=eligible_set pred=0 succ=0 APPLICATION Mtftp6Dxe [8D2313D8-213E-4328-B8E2-E16DAB8D1EEF] @0x4D3590 certainty=eligible_set pred=0 succ=0 APPLICATION TcpDxe [273F74EA-68F5-4498-B8E4-7C3646DB59AA] @0x4DCD20 certainty=eligible_set pred=0 succ=0 APPLICATION Udp6Dxe [04F21AF5-D001-42E8-BC3E-32CFE6A4D309] @0x4EFF50 certainty=eligible_set pred=0 succ=0 APPLICATION MnpDxe [C326CB94-81A9-4977-99D8-0B6FDF0258BC] @0x4F9B60 certainty=eligible_set pred=0 succ=0 APPLICATION SnpDxe [614070E0-289D-4055-A41B-4F19953D0E21] @0x504230 certainty=eligible_set pred=0 succ=0 APPLICATION DpcDxe [4A40BB4C-5AA1-433B-AD5F-543C0F7940B4] @0x50B820 certainty=eligible_set pred=0 succ=0 APPLICATION UefiPxeBcDxe [F77C2C86-585F-46D0-AB78-8BB6A8EB40B8] @0x50C110 certainty=eligible_set pred=0 succ=0 ... 15 additional same-stage modules; use --verbose or module-order.csv [OK] All bounded DEPEX/order evidence parsed; runtime scheduler effects remain outside offline proof UEFI host execution evidence (bounded offline) complete=no call_complete=no export_complete=no producer_resolution_complete=no inventories=2 physical_executables=213 quick_disasm_scans=212 call_sites=12639 interfaces=86 consumers=331 calls: direct_internal=8664 direct_external=158 unresolved_indirect=3817 interface consumers: positive=297 ambiguous=34 producers_resolved=0 exports: executables=0 unique_names=0 [INFO] Exports are executable identity evidence only and never protocol/PPI producer proof. [REVIEW] call 1 executable=0 modules=1 rva=0x339 kind=indirect_register [REVIEW] call 32 executable=0 modules=1 rva=0x708 kind=indirect_register [REVIEW] call 40 executable=0 modules=1 rva=0xAA8 kind=indirect_register [REVIEW] call 42 executable=0 modules=1 rva=0xC61 kind=indirect_register [REVIEW] call 43 executable=0 modules=1 rva=0xCA1 kind=indirect_register [REVIEW] call 91 executable=0 modules=1 rva=0x1A67 kind=indirect_register [REVIEW] call 92 executable=0 modules=1 rva=0x1A92 kind=indirect_register [REVIEW] call 122 executable=0 modules=1 rva=0x26E2 kind=indirect_register [REVIEW] call 163 executable=0 modules=1 rva=0x2DAA kind=indirect_register [REVIEW] call 280 executable=0 modules=1 rva=0x43AE kind=indirect_register [REVIEW] call 281 executable=0 modules=1 rva=0x43D3 kind=indirect_register [REVIEW] call 300 executable=0 modules=1 rva=0x4832 kind=indirect_register [INFO] +3963 additional unresolved/external calls in uefi-execution.json [REVIEW] interface-consumer module=101 protocol=1C0C34F6-D380-41FA-A049-8AD06C1A66AA certainty=ambiguous [REVIEW] interface-consumer module=4 protocol=1E5668E2-8481-11D4-BCF1-0080C73C8881 certainty=ambiguous [REVIEW] interface-consumer module=42 protocol=1E5668E2-8481-11D4-BCF1-0080C73C8881 certainty=ambiguous [REVIEW] interface-consumer module=117 protocol=1E5668E2-8481-11D4-BCF1-0080C73C8881 certainty=ambiguous [REVIEW] interface-consumer module=117 protocol=2F707EBB-4A1A-11D4-9A38-0090273FC14D certainty=ambiguous [REVIEW] interface-consumer module=117 protocol=389F751F-1838-4388-8390-CD8154BD27F8 certainty=ambiguous [REVIEW] interface-consumer module=191 protocol=389F751F-1838-4388-8390-CD8154BD27F8 certainty=ambiguous [REVIEW] interface-consumer module=191 protocol=493B5BAC-BB9E-4BF5-8379-20E2ACA98541 certainty=ambiguous [REVIEW] interface-consumer module=42 protocol=4CF5B200-68B8-4CA5-9EEC-B23E3F50029A certainty=ambiguous [REVIEW] interface-consumer module=4 protocol=9042A9DE-23DC-4A38-96FB-7ADED080516A certainty=ambiguous [REVIEW] interface-consumer module=14 protocol=9042A9DE-23DC-4A38-96FB-7ADED080516A certainty=ambiguous [REVIEW] interface-consumer module=42 protocol=9042A9DE-23DC-4A38-96FB-7ADED080516A certainty=ambiguous [INFO] +22 additional ambiguous consumers in uefi-execution.json [WARN] dispatch module has no physical executable mapping: 0 [WARN] protocol/PPI producers unresolved: QuickDisasm exposes call edges but not service-call plus GUID-argument proof PE/TE extract (YARA/AV triage) [OK] extracted=1 skipped=212 hit_files=1 volumes=1 dir=analysis/out\engagement_hp_f1\pe_hits [INFO] Interesting modules use .HIT extension under pe/ (easy filter) manifest_csv=analysis/out\engagement_hp_f1\pe_hits/pe_extract_manifest.csv manifest_json=analysis/out\engagement_hp_f1\pe_hits/pe_extract_manifest.json [INFO] PE/TE modules extracted for offline YARA/AV triage; not an in-process signature engine [WARN] HIT path=pe/002E30C8_7FECA262-E72B-4262-B3F2-43A308318E73_APPLICATION_PE32_.HIT score=53 guid=7FECA262-E72B-4262-B3F2-43A308318E73 kind=PE32+ str=CreateRemoteThread [OK] YARA scan complete match_lines=1 report=analysis/out\engagement_hp_f1\pe_hits/yara_hits.txt [WARN] YARA reported match lines - review analysis/out\engagement_hp_f1\pe_hits/yara_hits.txt UEFI variable store analysis [INFO] EfiSystemNvDataFvGuid volume not found by GUID scan [INFO] Marker-only VSS/VSS2 candidate(s): 2 (markers are not validated variable records) NVRAM variable export [OK] exported vars written=0 skipped=0 dir=analysis/out\engagement_hp_f1\nvram [INFO] No complete primary store for export [INFO] No complete FDC/recovery store for export manifest_csv=analysis/out\engagement_hp_f1\nvram/nvram_manifest.csv manifest_json=analysis/out\engagement_hp_f1\nvram/nvram_manifest.json [INFO] Diff example: fc /b primary\PK_*.bin recovery\PK_*.bin AMI NVAR export [OK] AMI NVAR records=0 written=0 skipped=0 deduped_mirrors=0 effective=0 nested_containers=0 named_exports~=0 banks=0 [OK] GUID resolve: full=0 (store_lookup=0 inline_or_prior=0) unresolved_idx=0 StdDefaults_resolved=0 dir=analysis/out\engagement_hp_f1\nvram/nvar manifest_csv=analysis/out\engagement_hp_f1\nvram/nvar_manifest.csv manifest_json=analysis/out\engagement_hp_f1\nvram/nvar_manifest.json [INFO] No AMI NVAR records decoded (image may use VSS/EVSA only) Phoenix EVSA variable export [OK] EVSA stores=0 data_payloads_written=0 rows=0 dir=analysis/out\engagement_hp_f1\nvram/evsa manifest_csv=analysis/out\engagement_hp_f1\nvram/evsa_manifest.csv [INFO] No Phoenix EVSA store headers found (common on AMI/Insyde images) [INFO] Secure Boot UTF-16 name hints exist, but no active record was validated [INFO] Offline variable-store evidence cannot prove runtime Secure Boot enablement or select the active recovery copy Firmware family [OK] Primary=insyde_h2o confidence=medium [INFO] InsydeH2O / OEM notebook UEFI candidate confidence=medium [OK] VSS/VSS2 variable-store style present Marker hits: Hewlett-Packard=14 [INFO] InsydeH2O verdict is heuristic; capsule/tool-specific structures require dedicated Insyde parsing Summary Dump scope: FULL SPI chip candidate (IFD present; all declared regions in image) [full_spi_chip_candidate] This looks like a full raw Intel SPI image when descriptor, ME marker, and UEFI firmware volumes are present. UEFI payload often starts after descriptor/ME regions, so offset 0x0 is not expected to look like a PE/UEFI file. [FAIL] SPI descriptor access-control summary: Host CPU/BIOS master has overly broad write permissions. Security posture Overall: CRITICAL (1 FAIL, 0 WARN, 0 INFO) Critical findings: - Host CPU/BIOS master write access spans non-BIOS SPI regions Attack surface summary - Host CPU can write BIOS region -> firmware modification risk depends on BIOS_CNTL/PRx/SMM protections at runtime --- engagement correlate --- match=0 hash_mismatch=0 attr_mismatch=0 live_only=0 dump_only=5 missing_both=4 live_error=0 --- engagement s3 --- live_verdict=skipped entry_protection=skipped markers=0 tables=0 targets=0 --- engagement mei --- heci_devices=0 mkhi=none registry_version=none dump_versions=3 compare=n/a advisory_hints=1 [OK] Engagement package: analysis/out\engagement_hp_f1 [OK] SUMMARY: analysis/out\engagement_hp_f1\SUMMARY.txt [OK] SUMMARY.html (client annex): analysis/out\engagement_hp_f1\SUMMARY.html [OK] MANIFEST: analysis/out\engagement_hp_f1\MANIFEST.txt [OK] Annex: correlate/ s3/ mei/

Read-only, offline analysis of an already-acquired image — no hardware touched. Heuristic triage surfaces candidates in seconds; every verdict states its confidence and identification stays analyst-led. The same run also writes a client-ready engagement package (SUMMARY, MANIFEST, per-region SHA-256, NVRAM/PE exports).

Acquisition trust boundary

Software evidence and hardware reference dumps

GGFW provides read-only software-side evidence collection and correlation. In suspected firmware compromise cases, external hardware acquisition may still be required as the forensic reference method.

Hardware Dump vs. Software Dump of SPI Flash

Learn why a software dump is useful for trusted systems and diagnostics, but should not be treated as final proof of firmware integrity on a potentially compromised host.

Read methodology note →
Safe by design

Built to collect evidence, not modify the platform

Read-only architecture

No SPI erase, no SPI programming, no general-purpose MMIO write interface, no general-purpose PCI write interface and no public MSR write interface.

Restricted low-level access

Driver operations are restricted to allowlisted reads and accessible only to Administrators and SYSTEM.

Evidence preservation

Read-back verification, SHA-256 artifact hashes, timestamped names, anonymous machine IDs and non-overwriting report output.

Reporting and automation

From raw registers to reproducible evidence

Human-readable output

Clear module verdicts such as [FAIL] common.bios_wp, [OK] common.spi_lock and [N/A] common.smm_lock.

JSON automation

Stable module identifiers, schema-based results, evidence fields, confidence levels and machine-readable status values.

Audit artifacts

Timestamped reports, firmware dumps, SHA256 files, offline-analysis JSON and release manifests for repeatable review.

Read-onlyplatform evidence collection
SPI + GPUfirmware acquisition
Text + JSONreporting outputs
Betaprivate evaluation access

Request a firmware security assessment

GGSEC performs acquisition, platform-security validation and analyst-led firmware investigation using GGFW and complementary laboratory tooling.