LT11-Using MCRIT for firmware analysis: experimental poorman's integrity check pipeline
2026-04-16 , Amphitheater

Sharing experimental approach for assessing UEFI firmware integrity on a laptop - extracting the dumped firmware PE and submitting them to MCRIT. Then proceeding on min-hashing comparison with editor's published firmware images to hunt for malicious executables.
WARNING: work in progress and artisanal - not a industrialized pipeline : we used ducktape :)

DFIR analyst at EDF's CERT. My work focuses primarily on digital forensics and OSINT, although I also occasionally handle basic software and hardware reverse engineering.