Peacock: UEFI Firmware Runtime Observability Layer for Detection and Response

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Gorelik, Hadar Cochavi, Fadlon, Orel, Klimov, Denis, Brodt, Oleg, Shabtai, Asaf, Elovici, Yuval
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866908759674060800
author Gorelik, Hadar Cochavi
Fadlon, Orel
Klimov, Denis
Brodt, Oleg
Shabtai, Asaf
Elovici, Yuval
author_facet Gorelik, Hadar Cochavi
Fadlon, Orel
Klimov, Denis
Brodt, Oleg
Shabtai, Asaf
Elovici, Yuval
contents Modern computing platforms rely on the Unified Extensible Firmware Interface (UEFI) to initialize hardware and coordinate the transition to the operating system. Because this execution environment operates with high privileges and persists across reboots, it has increasingly become a target for advanced threats, including bootkits documented in real systems. Existing protections, including Secure Boot and static signature verification, are insufficient against adversaries who exploit runtime behavior or manipulate firmware components after signature checks have completed. In contrast to operating system (OS) environments, where mature tools provide dynamic inspection and incident response, the pre-OS stage lacks practical mechanisms for real-time visibility and threat detection. We present Peacock, a modular framework that introduces integrity-assured monitoring and remote verification for the UEFI boot process. Peacock consists of three components: (i) a UEFI-based agent that records Boot and Runtime Service activity with cryptographic protection against tampering; (ii) a cross-platform OS Agent that extracts the recorded measurements and produces a verifiable attestation bundle using hardware-backed guarantees from the platform's trusted module; and (iii) a Peacock Server that verifies attestation results and exports structured telemetry for enterprise detection. Our evaluation shows that Peacock reliably detects multiple real-world UEFI bootkits, including Glupteba, BlackLotus, LoJax, and MosaicRegressor. Taken together, these results indicate that Peacock provides practical visibility and verification capabilities within the firmware layer, addressing threats that bypass traditional OS-level security mechanisms.
format Preprint
id arxiv_https___arxiv_org_abs_2601_07402
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Peacock: UEFI Firmware Runtime Observability Layer for Detection and Response
Gorelik, Hadar Cochavi
Fadlon, Orel
Klimov, Denis
Brodt, Oleg
Shabtai, Asaf
Elovici, Yuval
Cryptography and Security
Modern computing platforms rely on the Unified Extensible Firmware Interface (UEFI) to initialize hardware and coordinate the transition to the operating system. Because this execution environment operates with high privileges and persists across reboots, it has increasingly become a target for advanced threats, including bootkits documented in real systems. Existing protections, including Secure Boot and static signature verification, are insufficient against adversaries who exploit runtime behavior or manipulate firmware components after signature checks have completed. In contrast to operating system (OS) environments, where mature tools provide dynamic inspection and incident response, the pre-OS stage lacks practical mechanisms for real-time visibility and threat detection. We present Peacock, a modular framework that introduces integrity-assured monitoring and remote verification for the UEFI boot process. Peacock consists of three components: (i) a UEFI-based agent that records Boot and Runtime Service activity with cryptographic protection against tampering; (ii) a cross-platform OS Agent that extracts the recorded measurements and produces a verifiable attestation bundle using hardware-backed guarantees from the platform's trusted module; and (iii) a Peacock Server that verifies attestation results and exports structured telemetry for enterprise detection. Our evaluation shows that Peacock reliably detects multiple real-world UEFI bootkits, including Glupteba, BlackLotus, LoJax, and MosaicRegressor. Taken together, these results indicate that Peacock provides practical visibility and verification capabilities within the firmware layer, addressing threats that bypass traditional OS-level security mechanisms.
title Peacock: UEFI Firmware Runtime Observability Layer for Detection and Response
topic Cryptography and Security
url https://arxiv.org/abs/2601.07402