| name | analyzing-bootkit-and-rootkit-samples |
| description | Use when analyzing bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection. |
| domain | cybersecurity |
| tags | ["malware","bootkit","rootkit","UEFI","MBR-analysis"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Analyzing Bootkit And Rootkit Samples
Overview
Cybersecurity skill for analyzing bootkit and rootkit samples. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing bootkit and rootkit samples"
-
"Analyzes bootkit and advanced rootkit malware that infects the Master Boot Recor"
-
A system shows signs of compromise that persist through OS reinstallation
-
Antivirus and EDR are unable to detect malware despite clear evidence of compromise
-
UEFI Secure Boot has been disabled or shows integrity violations
-
Memory forensics reveals rootkit behavior (hidden processes, hooked system calls)
-
Investigating nation-state level threats known to deploy bootkits (APT28, APT41, Equation Group)
Do not use for standard user-mode malware; bootkits and rootkits operate at a fundamentally different level requiring specialized analysis techniques.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Disk imaging tools (dd, FTK Imager) for acquiring MBR/VBR sectors
- UEFITool for UEFI firmware volume analysis and module extraction
- chipsec for hardware-level firmware security assessment
- Ghidra with x86 real-mode and 16-bit support for MBR code analysis
- Volatility 3 for kernel-level rootkit artifact detection
- Bootable Linux live USB for offline system analysis
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}