> [0]: https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bo...
So how do you remove it?
So how do you remove it?
Obviously requires admin permissions on a running host, but if you're injecting into the bootloader you're already admin (or you can get it easily).
Half the problem I find with these security products is knowing what their actual abilities are and inabilities. I've assumed wrongly in the past that some security products are doing things when in fact they are not, and thats obviously an area for exploitation.