Secuere Boot Process

UEFI (Unified Extensible Firmware Interface)

Boots by loading EFI program files (with .efi filename extensions).

  • stored in a special disk partition, known as the EFI System Partition (ESP).

It can read files from a partition on th ehard disk.

It is not limited to the size of the first sector.

It allows booting OS on disks with more than 2TB.

  • regardless of the CPU architecture.

It supports graphics user interfaces on startup.

Secure boot - is a feature of UEFI.

  • The boot code must be digitally signed to prevent the installation of malware in the boot code.

  • The examiner must be a forensic boot device that supports secure boot.

Last updated