Downloads

Tools

ida-efiutils - IDA Pro scripts to assist in reverse engineering EFI binaries.

efitools - some scripts for manipulating EFI binaries, capsules, etc.

KernelResolver - sample Mac OS X kernel extension to demonstrate resolving symbols within the running kernel.

Presentations

Ruxcon 2012 - presentation on EFI-based rootkits on Macs.

Black Hat USA 2012 Slides / Paper - presentation on EFI-based rootkits on Macs.

SyScan Singapore 2012 - presentation on EFI-based rootkits on Macs.

Ruxcon 2011 - presentation on Mac OS X rootkits from Ruxcon 2011.

Kiwicon 2011 - presentation on Mac OS X rootkits from Kiwicon 2011.