# Unified Extensible Firmware Interface
UEFI is the modern firmware interface for platform initialization and boot services; it matters here as the successor to legacy BIOS in boot-media compatibility.
## Historical and Technical Context
The page compares legitimate multiboot/storage devices with offensive USB research. IODD devices emulate optical disks or virtual drives from stored ISO/VHD images, allowing one physical unit to present many bootable environments across legacy BIOS and UEFI systems. RMPrepUSB is a boot-media preparation and testing utility. Hak5’s Rubber Ducky class uses USB HID behavior to inject keystrokes; PoisonTap used a Raspberry Pi Zero configured as a USB Ethernet gadget to manipulate a locked computer’s network behavior and siphon web credentials/cookies. [S14] The page’s conceptual insight is that **USB is not merely storage**: the same connector can impersonate disks, keyboards, serial devices, or network adapters.
## Role in Scanned_20260730-1802
The primary identifying evidence appears on PDF page 28. A landscape-oriented page with a rectangular copper/orange tape patch at upper right. The writing is divided into a boot-media block and a security-research block. Arrows and slashes connect ISO/VHD, legacy/UEFI, and named USB attack projects. Within that page, Unified Extensible Firmware Interface helps the notebook move from a visible name or artifact toward the underlying identity, protocol, ownership, or control structure.
## Notebook Evidence
- `Scanned_20260730-1802.pdf`, PDF page 28: "Legacy & UEFI"
**Evidentiary status:** Visible evidence: explicit “Attack” labels and boot-mode comparison. Verified fact: PoisonTap used Raspberry Pi Zero USB networking; IODD presents virtual media. Strong inference: laboratory/security research. No evidence on this page of deployment against a third party.
The canonical name **Unified Extensible Firmware Interface** is normalized outside the quotations. The quoted lines preserve the completed reconstruction's spelling, capitalization, and uncertainty markers.
## Relationships
On PDF page 28, Unified Extensible Firmware Interface appears in the same evidentiary cluster as [[Bootable Virtual Drive|Bootable Virtual Drive]], [[IODD|IODD]], [[ISO Image|ISO Image]], [[Virtual Hard Disk|Virtual Hard Disk]], [[BIOS|BIOS]], [[USB Rubber Ducky|USB Rubber Ducky]], [[Raspberry Pi Zero W|Raspberry Pi Zero W]], [[PoisonTap|PoisonTap]], [[RMPrepUSB|RMPrepUSB]]. These links record page-level proximity and the reconstruction's systems map; they do not by themselves prove corporate ownership or a direct technical dependency.
## Cross-Notebook Significance
Pages 28-30 extend the notebook’s recurring interest in boundary objects—hardware that changes identity according to protocol. This anticipates later concerns with programmable interfaces, hidden menus, and universal interaction.
## Scanned_20260730-1706 Overlay
**Source overlay:** [[Scanned_20260730-1706|Scanned_20260730-1706]] (specific PDF page references follow).
`Scanned_20260730-1706.pdf`, PDF pages 10 and 35–37 expands UEFI from the boot-media compatibility concern in `Scanned_20260730-1802.pdf`, page 28 into rEFInd selection, option-ROM management, firmware setup, system recovery, boot override, Intel ME/CIRA, and PXE network boot. UEFI is shown as a recovery and authority surface, not only a successor to legacy BIOS.
## Missed Signals and Open Leads
Identify the exact IODD model, supported encryption implementation, and target hardware. Separate authorized penetration-testing equipment from ordinary recovery media in the device inventory.
## Sources
- [[Scanned_20260730-1802|Scanned_20260730-1802]], especially PDF page 28.
- `Scanned_20260730-1802.pdf`, cited as a plain archival filename; the PDF is not stored in `wiki-notes`.
- **[S14]** Samy Kamkar, “PoisonTap,” GitHub. https://github.com/samyk/poisontap
## Scanned_20260730-1719 overlay
**Source evidence:** [[Scanned_20260730-1719#PDF page 20 — macOS recovery and command-line tool inventory|page 20]], [[Scanned_20260730-1719#PDF page 21 — “Whatever it is” system and NVRAM variables|page 21]], [[Scanned_20260730-1719#PDF page 44 — Wineskin, cloud configuration, and Ozmosis|page 44]], [[Scanned_20260730-1719#PDF page 45 — Contacts and Hackintosh firmware utility stack|page 45]], [[Scanned_20260730-1719#PDF page 46 — UBU, MMTool, microcode, and AMI Aptio BIOS modding|page 46]], [[Scanned_20260730-1719#PDF page 47 — Ozmosis tooling and firmware image references|page 47]], [[Scanned_20260730-1719#PDF page 48 — MMTool/Ozmosis and RetroArch|page 48]], [[Scanned_20260730-1719#PDF page 49 — Mojave APFS and Hackintosh source repositories|page 49]], [[Scanned_20260730-1719#PDF page 50 — AMI Aptio firmware modules and UEFITool|page 50]], [[Scanned_20260730-1719#PDF page 51 — Ordered UEFI modules in a Z77/Ozmosis firmware image|page 51]], [[Scanned_20260730-1719#PDF page 52 — RetroArch BIOS, PlayStation firmware, and Ozmosis modules|page 52]], [[Scanned_20260730-1719#PDF page 53 — Ozmosis build components, PXE, and Kext-to-FFS conversion|page 53]], [[Scanned_20260730-1719#PDF page 54 — Windows system inventory, firmware shortcuts, GRUB, and partitioning|page 54]], [[Scanned_20260730-1719#PDF page 55 — Windows installation media, AMI setup, and administrator shell|page 55]].
UEFI is the modern firmware interface for platform initialization, boot services, firmware drivers, applications, and NVRAM-managed boot policy. The notebook moves from changing UEFI settings to inspecting and rebuilding modules inside specific firmware images.
**Relationship overlay:** [[Acidanthera|Acidanthera]] · [[ACPI Differentiated System Description Table|ACPI Differentiated System Description Table]] · [[American Megatrends|American Megatrends]] · [[AMI Aptio|AMI Aptio]] · [[Apple File System|Apple File System]] · [[Beetle PSX HW|Beetle PSX HW]] · [[Btrfs|Btrfs]] · [[cfdisk|cfdisk]] · [[Clover EFI bootloader|Clover EFI bootloader]] · [[CPU microcode|CPU microcode]] · [[Enhanced FAT UEFI driver|Enhanced FAT UEFI driver]] · [[exFAT|exFAT]].
This occurrence connects the existing note to [[Federated Continuity Computer|Federated Continuity Computer]], [[Vendor-Agnostic Recovery|vendor-agnostic recovery]], and [[Scanned_20260730-1706|Scanned_20260730-1706]] without replacing the earlier evidence.
## Scanned_20260730-1314 overlay
[[Scanned_20260730-1314#Scanned_20260730-1314.pdf — PDF page 28|Pages 28–29]]: UEFI is mapped through boot executables, GPT, and GRUB, contrasting modern firmware boot with legacy layouts.
**Relationship overlay:** [[GNU GRUB]] · [[GUID Partition Table]].