{"repo":"cjee21/Check-UEFISecureBootVariables","free":true,"listed":false,"github":"https://github.com/cjee21/Check-UEFISecureBootVariables","clone":"git clone https://github.com/cjee21/Check-UEFISecureBootVariables.git","description":"PowerShell scripts to check the UEFI KEK, DB and DBX Secure Boot variables as well as scripts for other Secure Boot related items.","language":"PowerShell","stars":309,"topics":["command-prompt","db","dbx","kek","powershell","powershell-script","registry","secure-boot","uefi-secureboot","windows"],"license":null,"category":"deployment-docker-iac","readme_excerpt":"Check-UEFISecureBootVariables PowerShell scripts to check the UEFI KEK, DB and DBX Secure Boot variables as well as scripts for other Secure Boot related items. [!IMPORTANT] The DBX checking in Check UEFI PK, KEK, DB and DBX is UEFI architecture dependent. The script attempts to detect the installed Windows architecture and assumes that the UEFI architecture matches (this should be the case on officially supported systems[[ ]](https://learn.microsoft.com/en-us/windows/deployment/windows-deployment-scenarios-and-tools)). If this is not the case or the detection fails, the DBX check results will be invalid. [!WARNING] Disabling Secure Boot should be avoided. If Windows is booted when Secure Boot is turned off, all the Secure Boot and UEFI-related configurations are reset[[ ]](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#remove-the-lsa-protection-uefi-variable). This may include the deletion of UEFI variables for LSA protection[[ ]](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#remove-the-lsa-protection-uefi-variable), SkuSiPolicy.p7b[[ ]](https://support.microsoft.com/en-gb/topic/guidance-for-blocking-rollback-of-virtualization-based-security-vbs-related-security-updates-b2e7ebf4-f64d-4884-a390-38d63171b8d3#bkmk policy removal and recovery procedure) and SBAT[[ ]](https://github.com/canonical/sbat-reset-","default_branch":null,"files":null,"tree":[],"storefront":"/r/cjee21","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cjee21/Check-UEFISecureBootVariables/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}