Ghidra analyzer for UEFI firmware.
Find a file
Евгений Рассказов 573f4b9b5b added compatibility with ghidra 10.2_dev
2022-04-26 17:03:33 +03:00
data Initial commit 2020-07-04 14:12:01 +03:00
ghidra_scripts Updated processing of meta. 2020-11-08 13:36:13 +03:00
gradle/wrapper added compatibility with ghidra 10.2_dev 2022-04-26 17:03:33 +03:00
img Initial commit 2020-07-04 14:12:01 +03:00
src/main/java/efiSeek added compatibility with ghidra 10.2_dev 2022-04-26 17:03:33 +03:00
.gitignore updated gitignore 2020-10-18 21:49:29 +03:00
build.gradle Added json lib load 2020-09-30 17:09:38 +03:00
extension.properties hardcoded version changed to @extversion@ 2021-03-09 14:33:46 +03:00
gradlew Initial commit 2020-07-04 14:12:01 +03:00
gradlew.bat Initial commit 2020-07-04 14:12:01 +03:00
LICENSE Initial commit 2020-07-04 14:12:01 +03:00
Module.manifest Initial commit 2020-07-04 14:12:01 +03:00
README.md Update README. 2020-07-07 18:26:00 +03:00

efiSeek for Ghidra

About

The analyzer automates the process of researching EFI files, helps to discover and analyze well-known protocols, smi handlers, etc.

Features

Finds known EFI GUID's

guids

Identifies protocols located with LOCATE_PROTOCOL function

locateProtocols

Identifies functions used as the NOTIFY function

notify

Identifies protocols installed in the module through INSTALL_PROTOCOL_INTERFACE

install

Identifies functions used as an interrupt function (like some hardware, software/child interrupt)

ioTrap

sx

child

sw

Script for loading efi modules to relevant directories in Headless mode

Sorting smm modules relying on meta information into next folders:

  • SwInterrupts
  • ChildInterrupts
  • HwInterrupts
  • UnknownInterrupts

sort

Installation

Set GHIDRA_INSTALL_DIR environment variable to ghidra path.

Start gradlew.bat, after the completion of building a copy archive from the dist directory to GHIDRA_HOME_DIR/Extensions/Ghidra/. And turn on this extention in your ghidra.

Usage

After installation you are free to use this analyzer. If you open a EFI file, the analyzer appears selected automatically. To start the analyzer, press A or Analysis/Auto Analyze and press Analyze.

References