Update 'README.md'

This commit is contained in:
Ekranoplan 2023-06-21 07:49:51 +00:00
parent 37d11b19ee
commit 7a7eb72c7b

View File

@ -1,7 +1,11 @@
# BlackLotus_Ioc_scan_Powershell # BlackLotus_Ioc_scan_Powershell
Powershell script(s) to scan windows PC for published IoCs of BlackLotus bootkit documented by Eset and Microsoft Powershell script(s) to scan windows PC for published IoCs of BlackLotus bootkit documented by Eset and Microsoft
https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/ https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/
https://www.microsoft.com/en-us/security/blog/2023/04/11/guidance-for-investigating-attacks-using-cve-2022-21894-the-blacklotus-campaign/ https://www.microsoft.com/en-us/security/blog/2023/04/11/guidance-for-investigating-attacks-using-cve-2022-21894-the-blacklotus-campaign/
Usage:
Open Powershell (as Admin) and run: .\Black-Lotus_check.ps1