English

Bringing Forensic Readiness to Modern Computer Firmware

Cryptography and Security 2025-05-12 v1

Abstract

Today's computer systems come with a pre-installed tiny operating system, which is also known as UEFI. UEFI has slowly displaced the former legacy PC-BIOS while the main task has not changed: It is responsible for booting the actual operating system. However, features like the network stack make it also useful for other applications. This paper introduces UEberForensIcs, a UEFI application that makes it easy to acquire memory from the firmware, similar to the well-known cold boot attacks. There is even UEFI code called by the operating system during runtime, and we demonstrate how to utilize this for forensic purposes.

Cite

@article{arxiv.2505.05697,
  title  = {Bringing Forensic Readiness to Modern Computer Firmware},
  author = {Tobias Latzo and Florian Hantke and Lukas Kotschi and Felix Freiling},
  journal= {arXiv preprint arXiv:2505.05697},
  year   = {2025}
}

Comments

Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU) 2021, March 29-April 1, 2021

R2 v1 2026-06-28T23:26:37.593Z