BIOS / UEFI ROM Analysis

Low-level firmware assessment powered by the proprietary GGSec Firmware Toolkit, with complementary manual analysis and independent validation using established third-party tools where appropriate.

Price Starting from EUR 4,500
Typical engagement 3-7 business days
Confidentiality NDA available

Investigation Methodology

• GGFW live platform-security assessment
• Verified SPI acquisition
• GGFW offline firmware image analysis
• Live-to-image configuration correlation
• Manual UEFI module investigation
• Independent CHIPSEC comparison where applicable
• Hardware programmer acquisition when required
Scope: BIOS/SPI protection, SMM and SMRR evidence, memory and platform locks, Secure Boot variable evidence, firmware structure and analyst-led review.

Hardware vs. Software SPI Acquisition

A software dump is useful for trusted systems, diagnostics and correlation, but a potentially compromised host may not be a trustworthy source of firmware bytes. For forensic integrity questions, external hardware acquisition is the reference method.

Read methodology note →

Example GGFW Evidence

Controller lock detected, but BIOS-region write protection still fails

1. Live Platform Security Assessment

GGSec Firmware Toolkit v0.5.11 Beta
Module: platform security checks (read-only)

[FAIL] BIOS SMM write protection
       BIOS_CNTL=0x08 BLE=0 BIOSWE=0 EISS/SMM_BWP=0

[WARN] BIOS Lock Enable is clear
       kernel/SMM-capable code may be able to toggle BIOSWE

[FAIL] common.spi_access
       FDV=1 descriptor_write=1 me_write=1 gbe_write=1

[FAIL] SPI protected ranges cover BIOS
       no WPE coverage

[OK] common.spi_lock
       HSFS=0xE009 FLOCKDN=1

[INFO] FLOCKDN scope
       controller lock does not prove BIOS-region write protection

[OK] common.smrr
       range=0xDF800000-0xDFFFFFFF type=6 valid=1

[FAIL] BIOS region write-protection verdict
       neither SMM protection nor full SPI PR coverage passed

Security posture: FAIL
PASS=7 FAIL=7 WARN=3 ERROR=0 N/A=7 INFO=1 PARTIAL=1

Why this matters: GGFW does not treat a single positive control bit as proof of firmware security. It correlates BIOS_CNTL, SMM_BWP/EISS, descriptor access, protected ranges and controller lock evidence before issuing the final verdict.

2. Secure Boot Configuration Evidence

Secure Boot variable attribute checks (read-only)
  [OK] SecureBoot - size=1 attrs=0x00000006 [BS,RT] value=1
  [OK] SetupMode - size=1 attrs=0x00000006 [BS,RT] value=0
  [INFO] AuditMode - firmware variable not found
  [INFO] DeployedMode - firmware variable not found
  [INFO] VendorKeys - firmware variable not found
  [OK] PK - size=1139 attrs=0x00000027 [NV,BS,RT,TIME_AUTH]
       lists=1 signatures=1 x509=1 sha256=0 other=0
  [OK] KEK - size=4184 attrs=0x00000027 [NV,BS,RT,TIME_AUTH]
       lists=3 signatures=3 x509=3 sha256=0 other=0
  [OK] db - size=9899 attrs=0x00000027 [NV,BS,RT,TIME_AUTH]
       lists=7 signatures=7 x509=7 sha256=0 other=0
  [OK] dbx - size=13976 attrs=0x00000027 [NV,BS,RT,TIME_AUTH]
       lists=2 signatures=290 x509=0 sha256=290 other=0

SecureBoot appears to be enabled
[OK] Secure Boot variable protection verdict
      required variables are present, authenticated, and structurally valid EFI Signature Lists

Security posture: PASS
PASS=1 FAIL=0 WARN=0 ERROR=0 N/A=0 INFO=0

GGFW validates Secure Boot configuration and variable evidence, including authenticated variable attributes and EFI Signature List structure. It does not perform destructive or state-changing Secure Boot tests.

3. Analyst-Led Firmware Investigation

Automated GGFW evidence

SPI and BIOS protection state, platform locks, Secure Boot variable evidence, firmware image structure, hashes, GPU ROM validation and live/offline correlation.

Manual expert analysis

UEFI module review, comparison with vendor firmware, suspicious module triage, implant investigation, CVE mapping and remediation guidance.

Deliverables

• GGFW platform-security report
• Verified SPI dump and SHA-256 evidence
• Offline firmware structure analysis
• Live-to-image correlation notes
• Independent CHIPSEC comparison where applicable
• Remediation roadmap and analyst summary

Important Boundaries

• No flash erase or programming during GGFW evidence collection • Structural integrity is reported separately from cryptographic authenticity • Unsupported, unavailable and not-applicable states are not collapsed into generic failures

Ready to audit your BIOS/UEFI firmware?

Request a confidential firmware assessment powered by GGSec Firmware Toolkit. Starting from EUR 4,500

Request Investigation Explore GGFW