Skip to main content

CERT UEFI Parser

The CERT UEFI Parser is a Python-based tool for inspecting firmware ROM images, installers, and related files, especially those associated with UEFI. It combines information from the UEFI specifications with insights from independent firmware research (for example, Igor Skochinsky’s Intel ME work).

Written for Python 3 and built on the Construct parsing framework, the parser is more flexible than the EDK2 reference implementation and is easier to extend to proprietary or experimental data structures. CERT UEFI Parser aims to support all data formats commonly found inside UEFI ROMs, including Portable Executables (PEs) and image structures. The project is free of NDAs or other restrictions; all proprietary formats have been reverse engineered from public information and original analysis.

Installation

The parser depends on the cert-uefi-support package, which provides lower-level decompression and binary utilities. Both packages are now available on PyPI.

Basic installation:

  $ python3 -m venv cert-venv
  $ ./cert-venv/bin/pip install cert-uefi-support cert-uefi-parser

Optional GUI Support (Qt)

GUI support is optional and provided via the PySide6 package. It is a large dependency, so it is not installed by default. To install with the GUI extras:

  $ python3 -m venv cert-venv
  $ ./cert-venv/bin/pip install cert-uefi-support 'cert-uefi-parser[qt]'

Installing from the Official Git Repositories

  $ python3 -m venv cert-venv
  $ ./cert-venv/bin/pip install \
    git+https://github.com/cmu-sei/cert-uefi-support \
    "cert-uefi-parser[qt] @ git+https://github.com/cmu-sei/cert-uefi-parser.git"

Usage

CERT UEFI Parser provides four primary output modes: a graphical interface, an ASCII text display (with ANSI color output enabled by default), a full JSON representation, and a filtered JSON representation containing fields that are useful for generating a Software Bill of Materials (SBOM).

  $ ./cert-venv/bin/cert-uefi-parser --gui {firmware-related-file}
  $ ./cert-venv/bin/cert-uefi-parser --text {firmware-related-file} | less
  $ ./cert-venv/bin/cert-uefi-parser --json {firmware-related-file} >output.json
  $ ./cert-venv/bin/cert-uefi-parser --sbom {firmware-related-file} >output.json

Sample firmware files can typically be obtained by downloading the BIOS or UEFI update tools from your system vendor’s support site. While not all models are guaranteed to be fully supported, many common vendor formats parse successfully, and examining these update files is a good way to begin exploring the parser’s capabilities.

Metadata

Release files for cert-uefi-parser 1.0.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cert-uefi-parser 1.0.8
File Size Uploaded
cert_uefi_parser-1.0.8.tar.gz 1.1 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for cert-uefi-parser 1.0.8
File Interpreter ABI Platform
cert_uefi_parser-1.0.8-py3-none-any.whl Python 3 none any Details

Total release size: 2.2 MB

Release files / cert_uefi_parser-1.0.8.tar.gz

Download URL cert_uefi_parser-1.0.8.tar.gz
Size 1.1 MB
Tags Source
SHA-256 checksum
How to use checksums
a5cec42bb59b5791001edf75e629b18ec3364d74d72ae32118fc8a702364c72c
BLAKE2b-256 checksum
How to use checksums
7e456d9dedb0417ed89289afd57c90ad58cfe7c6a88eb22b93c8daea56a75483
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 27, 2026.

Transparency log

Release files / cert_uefi_parser-1.0.8-py3-none-any.whl

Download URL cert_uefi_parser-1.0.8-py3-none-any.whl
Size 1.1 MB
Tags Python 3
SHA-256 checksum
How to use checksums
2b7387b8d748d30f688ad311138bf817896907b5c977623b9bef1320e3040218
BLAKE2b-256 checksum
How to use checksums
235e00e42633cff7553d78f3f3a9bd24a7c7155cc59aa097c588e3498244357b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.8 This release

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page