Topics
Follow your own topics →
DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join now → Learn more
TOPICS

Below the OS, UEFI bootkits, firmware implants, and the artifacts Volatility will never find

219 · · June 12, 2026, 7:09 a.m.
Security dfir Firmware Security uefi uefi Firmware Bootkits dfir
Summary
This blog post discusses the challenges faced by standard Digital Forensics and Incident Response (DFIR) tools when dealing with UEFI firmware and bootkits. It explores the remnants and artifacts left by such implants and provides guidance on where to look for indicators of compromise when traditional tools fail.
Read full post on andreafortuna.org →
MORE POSTS LIKE THIS
security: GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
Sujith Quintelier · Jul 10, 2026
Cybersecurity malware-analysis
Diamond chains and “GDIDs”: How this alleged Scattered Spider member got busted
Thestack · Jul 9, 2026
microsoft fbi
Going beneath NTFS — USN Journal, dfir_ntfs, and artefact-driven investigations
andreafortuna · Jul 6, 2026
Security dfir
X-VPN Installer Hijacked to Spread STX RAT Malware
Securityonline · Jun 15, 2026
malware Howler Cell
Beyond Context Windows: When Malware Stops Fitting into Naive Automated Analysis
JP Dias · Jun 13, 2026
Phishing vbs
Try an Browser Sandbox! (For Free!)
Peter Krumins · Jul 5, 2025
Browser sandbox Cybersecurity
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google