Score: 1

Bringing Forensic Readiness to Modern Computer Firmware

Published: May 9, 2025 | arXiv ID: 2505.05697v1

By: Tobias Latzo , Florian Hantke , Lukas Kotschi and more

Potential Business Impact:

Lets investigators copy computer brain data.

Business Areas:
Flash Storage Hardware

Today's computer systems come with a pre-installed tiny operating system, which is also known as UEFI. UEFI has slowly displaced the former legacy PC-BIOS while the main task has not changed: It is responsible for booting the actual operating system. However, features like the network stack make it also useful for other applications. This paper introduces UEberForensIcs, a UEFI application that makes it easy to acquire memory from the firmware, similar to the well-known cold boot attacks. There is even UEFI code called by the operating system during runtime, and we demonstrate how to utilize this for forensic purposes.

Country of Origin
🇩🇪 Germany

Repos / Data Links

Page Count
9 pages

Category
Computer Science:
Cryptography and Security