Ross ROSS = Recommend OSS · open-source software intelligence for agents

ldpreload/BlackLotus

BlackLotus UEFI Windows Bootkit observed · 2026-08-28

github.com/ldpreload/BlackLotus · C observed · 2026-08-28

Health v2 · maintenance only

29/100

  • Activity 0
  • Release rhythm 35
  • Longevity 82

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1148
  • days_rel: n/a
  • days_push: 888
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2240 stars · 478 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

An open-source UEFI bootkit targeting Windows that implements a Secure Boot bypass, kernel-level persistence, and an HTTP-based C2 loader with a web management panel. It is a proof-of-concept/research implementation of the BlackLotus bootkit, written in C and x86 assembly with no third-party libraries.

Use cases

  • study how UEFI bootkits achieve Secure Boot bypass
  • research bootkit persistence techniques on Windows
  • analyze malware C2 communication patterns
  • build defensive detections against UEFI bootkits
  • learn UEFI driver development with EDK2
  • evaluate EDR bypass and anti-hooking techniques

When to choose

  • you are a security researcher studying bootkit internals
  • you need a reference implementation for building bootkit detections
  • you want to understand Secure Boot and BitLocker bypass mechanics

When to avoid

  • you need a legitimate bootloader or system utility
  • you lack secure malware analysis infrastructure
  • you want production-ready or supported software
  • you cannot legally possess offensive tooling in your jurisdiction

Facets

library · maturity maintenance

security reverse-engineering penetration-testing security reverse-engineering operating-systems windows cpp c uefi-bootkit malware secure-boot-bypass rootkit research c2 firmware

1 source

Member repositories

RepositoryRoleHealth v2
ldpreload/BlackLotusmain29

For agents

markdown · JSON · MCP: product_card(name="ldpreload/BlackLotus")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem