Lab 5 of 6

UEFI and BlackLotus

Explore EFI visibility, the EFI System Partition, measured boot and BlackLotus detection.

2023 workshop archive · Version details

Migrated from the original Notion material. Commands and examples are preserved from 2023 and have not been retested against current releases. Screenshots and lab behaviour may differ with newer versions.

On this page

Objective #

This lab is a walkthrough of Velociraptor UEFI visibility and simulation on how we would deploy capability to detect BlackLotus from a technical detection article.

  1. Generic Velociraptor visibility from the Windows EFI API.
  2. Install BlackLotus malware sample.
  3. We will walk through several detection capabilities for BlackLotus style attacks that can be used at scale via Velociraptor.

Dependencies #

VM with UEFI installed. I have also added a task below to walk through this process.

VM with internet access and Velociraptor available on the desktop to run as per Lab: GUI mode walk through.

Artifact Exchange content has been imported into your Velociraptor instance - Lab: GUI mode walk through

Take a snapshot of your VM to enable rollback : We are going to run malware and its much easier to simply roll back at the end of the lab.

Open cmd, browse to desktop and run: velociraptor .exe gui -–datastore=./VRdata -v

The Velociraptor GUI is configured to open automatically upon start, but the credentials are available below:

Tasks #

Task 1 · Enabling UEFI on your Virtual Machine

Probably the most confusing task for users when unfamiliar with UEFI is how to setup their virtualisation environment to support UEFI.

Your pain after running through windows install and not having UEFI enabled!
Select screenshot to view full size in a new tab.

Your pain after running through windows install and not having UEFI enabled!

For Windows machines I have included a link in my references: How to enable TPM and Secure Boot on VMware to install Windows 11

Essentially we need to configure the following additions:

  • UEFI firmware
  • Trusted Platform Module (TPM) chip
  • Encryption enabled

A configuration on MacOS VMFusion for a fresh Windows 11 install is as follows:

  1. Enabled UEFI firmware type and Virtual Based Security - VBS

UEFI and BlackLotus: Enabling UEFI on your Virtual Machine (02)
Select screenshot to view full size in a new tab.

  1. Install a Trusted Platform Module (TPM) chip

UEFI and BlackLotus: Enabling UEFI on your Virtual Machine (03)
Select screenshot to view full size in a new tab.

  1. Enable Encryption

UEFI and BlackLotus: Enabling UEFI on your Virtual Machine (04)
Select screenshot to view full size in a new tab.

  1. Processors and Memory should be enabled and greyed out

UEFI and BlackLotus: Enabling UEFI on your Virtual Machine (05)
Select screenshot to view full size in a new tab.

Please take a snapshot after install of Windows.

UEFI secure boot may cause blue screens if there is an issue during the boot process. I have found after installing BlackLotus a rare occurrence of a BlueScreen during the boot process (after successful testing).I was able to boot after this successfully, so try to reboot and see if it resolves your issue.

Task 2 · Walk through EFI API visibility

Thank you to the community! Velociraptor has a cross platform (Windows + Linux) EFI plugin and function to query a system’s EFI variables.

💡 Velociraptor EFI visibility

efivariables() plugin: for extracting EFI variables from Linux and Windows.

Generic.System.EfiSignatures: artifact to parse EFI signature information from efivariables

  1. Open a new notebook and run the efivariables() plugin
SELECT * FROM efivariables()

UEFI and BlackLotus: Walk through EFI API visibility (06)
Select screenshot to view full size in a new tab.

You can see the variable name and namespace listed but no values. Using the ? in notebook we can see the arguments for this plugin and to view values we need to run the plugin with the argument: efivariables( value=’Y’)

UEFI and BlackLotus: Walk through EFI API visibility (07)
Select screenshot to view full size in a new tab.

  1. Rerun the query with efivariables( value=’Y’)

    Review the efi variables available on your machine. Note some entries are text, others binary.

UEFI and BlackLotus: Walk through EFI API visibility (08)
Select screenshot to view full size in a new tab.

I encourage you to read this description on UEFI variable keys James Bottomley - The Meaning of all the UEFI Keys

  1. Open the Velociraptor artifact view and search for Generic.System.EfiSignatures

    Review the VQL:

    UEFI and BlackLotus: Walk through EFI API visibility (09)
    Select screenshot to view full size in a new tab.

    This artifact has an exportable EFI profile and dynamic function that calls the efivariables plugin and uses the Velociraptor binary parser to extract EFI signature information.

    UEFI and BlackLotus: Walk through EFI API visibility (10)
    Select screenshot to view full size in a new tab.

    The Certificates scope focuses on the Platform Key (PK) and Signature Database (db) variable names.

    The Hashes scope focuses on the Revoked Signatures Database (dbx)

  2. Run Generic.System.EfiSignatures either in a collection view or in your previous notebook

    SELECT * FROM Artifact.Generic.System.EfiSignatures()
    

As you can see in the results and from the previous description these datapoints are excellent for data stacking.

UEFI and BlackLotus: Walk through EFI API visibility (11)
Select screenshot to view full size in a new tab.

UEFI and BlackLotus: Walk through EFI API visibility (12)
Select screenshot to view full size in a new tab.

Task 3 · Install BlackLotus

  1. Browse to my DEATHcon staging gist: blacklotus_demo.ps1

    Copy this Powershell into a privileged Powershell_ISE window (it embeds the binary and is much too large to share in this page).

    The Powershell will set a payload variable, disable Defender then drop the BlackLotus payload to disk, then execute it.

UEFI and BlackLotus: Install BlackLotus (13)
Select screenshot to view full size in a new tab.

After running the above, please reboot your machine so we can generate a BlackLotus boot event in TCGLogs.

One of the interesting features of BlackLotus is that it removes token privileges from Defender (MsMpEng.exe) with SE_PRIVILEGE_REMOVED. Once rebooted, you can also try to run the Defender configuration from the previous step once more and you should get errors.\

UEFI and BlackLotus: Install BlackLotus (14)
Select screenshot to view full size in a new tab.

Note: This may not work all the time as the implementation is buggy if Defender process restarts but it is a good indicator if your BlackLotus deployment is successful.

Task 4 · Query the EFI System Partition (ESP)

  1. First open the reference Microsoft article: Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

    Review the section on Recently created and locked bootloader files

    UEFI and BlackLotus: Query the EFI System Partition (ESP) (15)
    Select screenshot to view full size in a new tab.

    The EFI System Partition is typically a small FAT format partitioned drive we can discover using the raw_file accessor and parsing the PartitionTable.

    Exchange.Windows.Forensics.UEFI is an artifact that enumerates any ESP that exists on disk. It allows parsing of the ESP File Allocation Table to run forensics use cases on an ESP.

    1. Review Exchange.Windows.Forensics.UEFI

    UEFI and BlackLotus: Query the EFI System Partition (ESP) (16)
    Select screenshot to view full size in a new tab.

    The default glob which returns all **/*.efi files on the partition.

    1. Open collection view and run Exchange.Windows.Forensics.UEFI.

      We want to target \efi\microsoft\boot\*.efi

    UEFI and BlackLotus: Query the EFI System Partition (ESP) (17)
    Select screenshot to view full size in a new tab.

    UEFI and BlackLotus: Query the EFI System Partition (ESP) (18)
    Select screenshot to view full size in a new tab.

    I have included authenticode data in this artifact, mainly for signing details. Due to the way secureboot implements trust we can ignore the Authenticode.Trusted field for this artifact. We can however, spot other Certificate or PE abnormalities.

    1. Change the results notebook to target fields of interest
    SELECT OSPath, Size, Mtime,Btime,Attr,IsDeleted,ShortName,Hash.SHA256
    FROM source(artifact="Exchange.Windows.Forensics.UEFI")
    

    UEFI and BlackLotus: Query the EFI System Partition (ESP) (19)
    Select screenshot to view full size in a new tab.

    It should also be easy to spot both the timestamps on malicious files and deleted original EFI files.

    1. Next open the reference Microsoft article: Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

      Review the section on BlackLotus staging directory presence

      UEFI and BlackLotus: Query the EFI System Partition (ESP) (20)
      Select screenshot to view full size in a new tab.

      Using the same fields as previous in the notebook results Here we can clearly see the BlackLotus deleted files which line up to the publicly available BatonDrop - CVE-2022-21894.

    Rerun the collection from last step and use the path: system32/**

    UEFI and BlackLotus: Query the EFI System Partition (ESP) (21)
    Select screenshot to view full size in a new tab.

    NOTE: As all files are deleted, the hash values may be incorrect.

    Publicly available BattonDrop iso contents on Github
    Select screenshot to view full size in a new tab.

    Publicly available BattonDrop iso contents on Github

Task 5 · Yara EFI System Partition (ESP)

As Velociraptor has the ability to query the ESP via the fat accessor, we can also add a yara hunt easily.

  1. Open collection view and run a new collection with the artifact the artifact: Exchange.Windows.Detection.Yara.UEFI this is currently in the artifact exchange but will be added to the main repository in future.

UEFI and BlackLotus: Yara EFI System Partition (ESP) (23)
Select screenshot to view full size in a new tab.

As you can see the default rule for this artifact is the BlackLotus rule available on Malpedia

UEFI and BlackLotus: Yara EFI System Partition (ESP) (24)
Select screenshot to view full size in a new tab.

Task 6 · MeasuredBoot logs

  1. Open the reference Microsoft article: Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

    Review the section on Boot configuration log analysis:

    Trusted Computing Group (TCG) logs, also known as MeasuredBoot logs, are Windows Boot Configuration Logs that contain information about the Windows OS boot process. To retrieve these logs, the device must be running at least Windows 8 and have the Trusted Platform Module (TPM) enabled.

    From How Windows uses the Trusted Platform Module: “Windows 8 introduced Measured Boot as a way for the operating system to record the chain of measurements of software components and configuration information in the TPM through the initialization of the Windows operating system.” “For software, Measured Boot records measurements of the Windows kernel, Early-Launch Anti-Malware drivers, and boot drivers in the TPM.”

    The BlackLotus bootkit has boot drivers that are loaded in the boot cycle. MeasuredBoot logs list the BlackLotus components as EV_EFI_Boot_Services_Application.

    Measured boot logs are stored at C:\Windows\Logs\MeasuredBoot*.log and

    We can also extract the latest log from memory using Tbsi_Get_TCG_Log_Ex Windows API.

    In Windows.Forensics.UEFI.BootApplication I have implemented parsing these locations leveraging the Velociraptor inventory capability to manage execution of Matt Graeber’s TCGLogTools.

  2. Run Exchange.Windows.Forensics.UEFI.BootApplication imported from the artifact Exchange.

    Available options are a glob to target local log files and AllParsedTCGLog, an option to select returning all TCGLogs for triage.

    UEFI and BlackLotus: MeasuredBoot logs (25)
    Select screenshot to view full size in a new tab.

    Default output it is fairly easy to spot the non default BootApplication entries that match the Microsoft article.

    UEFI and BlackLotus: MeasuredBoot logs (26)
    Select screenshot to view full size in a new tab.

    With AllParsedTCGLog option we can also view individual BootApplication events manually.

    UEFI and BlackLotus: MeasuredBoot logs (27)
    Select screenshot to view full size in a new tab.

💡 Hunting opportunity

The BootApplication field from Windows.Forensics.UEFI.BootApplication is an interesting datapoint to hunt for!

You will find lots of vendors that have EFI hooks in the wild.

When hunting: I do not recommend selecting AllParsedTCGLog unless you are running a small machine size triage as the size of the AllParsed collection may be high across thousands of machines.

Task 7 · HVCI registry

From Microsoft: “Memory integrity (HVCI) is a virtualization-based security (VBS) feature available in Windows. Memory integrity and VBS improve the threat model of Windows and provide stronger protections against malware trying to exploit the Windows kernel. VBS uses the Windows hypervisor to create an isolated virtual environment that becomes the root of trust of the OS that assumes the kernel can be compromised. Memory integrity is a critical component that protects and hardens Windows by running kernel mode code integrity within the isolated virtual environment of VBS. Memory integrity also restricts kernel memory allocations that could be used to compromise the system.”

  1. Open the reference Microsoft article: Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

    Review the section on Registry modification:

UEFI and BlackLotus: HVCI registry (28)
Select screenshot to view full size in a new tab.

  1. In a default VM install I did not have this feature installed, so we want to generate data for this testing.

    From an elevated cmd prompt and run:

    reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /v "Enabled" /t REG_DWORD /d 0 /f
    

    UEFI and BlackLotus: HVCI registry (29)
    Select screenshot to view full size in a new tab.

  2. Windows.Registry.HVCI will return any items in the Hypervisor-protected Code Integrity (HVCI) registry path. An adversary may set the Enabled key to 0 if they intend to manipulate UEFI boot process.

    Open a new collection and run Exchange.Windows.Registry.HVCI

    UEFI and BlackLotus: HVCI registry (30)
    Select screenshot to view full size in a new tab.

    As you can see results are expected.

    UEFI and BlackLotus: HVCI registry (31)
    Select screenshot to view full size in a new tab.

    This artifact can be useful in a stacked hunt or monitoring capacity.

Task 8 · Event Logs

  1. Open the reference Microsoft article: Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

Review the section on Event logs entries - there are 2 main potential EventLogs of interest:

  • Microsoft-Windows-Windows Defender/Operational EventID: 3002

    IOCRegex: 0x80070057|error and failed

    UEFI and BlackLotus: Event Logs (32)
    Select screenshot to view full size in a new tab.

  • System event log EventID: 7023

    IOCRegex: Defender|Windefend

    Note: I have noticed other System service failures at the same time which may also indicate the malware’s method of disabling, but further research is required.

    UEFI and BlackLotus: Event Logs (33)
    Select screenshot to view full size in a new tab.

  1. Run a collection for Windows.EventLogs.EvtxHunter targeting the details above:

UEFI and BlackLotus: Event Logs (34)
Select screenshot to view full size in a new tab.

UEFI and BlackLotus: Event Logs (35)
Select screenshot to view full size in a new tab.

UEFI and BlackLotus: Event Logs (36)
Select screenshot to view full size in a new tab.

UEFI and BlackLotus: Event Logs (37)
Select screenshot to view full size in a new tab.

References: #

  1. ESET, Martin Smolar - BlackLotus UEFI bootkit: Myth confirmed
  2. Microsoft Incident Response - Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign
  3. James Bottomley - The Meaning of all the UEFI Keys
  4. Microsoft - Enable virtualization-based protection of code integrity
  5. How to enable TPM and Secure Boot on VMware to install Windows 11
  6. Adam Paulina - Running Malware Below the OS – The State of UEFI Firmware Exploitation