Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
Installs into .claude/skills of the current project.
Are you the author of Cyber Hunting Bootkits In Efi System Partition?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nexuslinkproductions-cyber-hunting-bootkits-in-efi-system-partition)
---
name: cyber-hunting-bootkits-in-efi-system-partition
description: "Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files."
hide: true
---
<!-- GENERATED:YURI-CODEX-SKILL-ADAPTER:v1 -->
# YURI skill adapter
Authoritative source: `.claude/skills/cyber-hunting-bootkits-in-efi-system-partition/SKILL.md`
Authoritative source SHA-256: `0002a15b128f2523c3e0cb3620f946ae863ffd5fc0ecdb6751625061224b536e`
Source class: `cyber-armed`
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run `node _SYSTEM/Scripts/skill-recall.mjs --show cyber-hunting-bootkits-in-efi-system-partition` and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.