The analyzer automates the process of researching EFI files, helps to discover and analyze well-known protocols, smi handlers, etc.
Sorting smm modules relying on meta information into next folders:
- SwInterrupts
- ChildInterrupts
- HwInterrupts
- UnknownInterrupts
Set GHIDRA_INSTALL_DIR
environment variable to ghidra path.
Start gradlew.bat
, after the completion of building a copy archive from the dist
directory to GHIDRA_HOME_DIR/Extensions/Ghidra/
.
And turn on this extention in your ghidra.
After installation you are free to use this analyzer. If you open a EFI file, the analyzer appears selected automatically.
To start the analyzer, press A
or Analysis/Auto Analyze
and press Analyze
.