Skip to main content

Overview

The SecureBoot command checks the status and configuration of Secure Boot, a UEFI firmware security feature that ensures only trusted bootloaders and operating systems can run during system startup. Secure Boot status affects bootkit deployment and certain rootkit attacks.

Syntax

Remote Execution

Output

Returns Secure Boot information:
  • Secure Boot enabled/disabled status
  • Setup Mode status
  • Secure Boot Policy
  • Platform key information

Use Cases

  • Determine bootkit deployment viability
  • Assess firmware-level persistence options
  • Identify kernel driver signing requirements
  • Understand boot-time security controls

Example Output

Remote Execution

This command supports remote execution using the -computername parameter.

Detection Considerations

Minimal detection risk - reads UEFI variables via WMI.