CERT UEFI Parser
The CERT UEFI Parser is a Python-based tool for inspecting firmware ROM images, installers, and related files, especially those associated with UEFI. It combines information from the UEFI specifications with insights from independent firmware research (for example, Igor Skochinsky’s Intel ME work).
Written for Python 3 and built on the Construct parsing framework, the parser is more flexible than the EDK2 reference implementation and is easier to extend to proprietary or experimental data structures. CERT UEFI Parser aims to support all data formats commonly found inside UEFI ROMs, including Portable Executables (PEs) and image structures. The project is free of NDAs or other restrictions; all proprietary formats have been reverse engineered from public information and original analysis.
Installation
The parser depends on the cert-uefi-support package, which provides lower-level decompression and binary utilities. Both packages are now available on PyPI.
Basic installation:
$ python3 -m venv cert-venv
$ ./cert-venv/bin/pip install cert-uefi-support cert-uefi-parser
Optional GUI Support (Qt)
GUI support is optional and provided via the PySide6 package. It is a large dependency, so it is not installed by default. To install with the GUI extras:
$ python3 -m venv cert-venv
$ ./cert-venv/bin/pip install cert-uefi-support 'cert-uefi-parser[qt]'
Installing from the Official Git Repositories
$ python3 -m venv cert-venv
$ ./cert-venv/bin/pip install \
git+https://github.com/cmu-sei/cert-uefi-support \
"cert-uefi-parser[qt] @ git+https://github.com/cmu-sei/cert-uefi-parser.git"
Usage
CERT UEFI Parser provides four primary output modes: a graphical interface, an ASCII text display (with ANSI color output enabled by default), a full JSON representation, and a filtered JSON representation containing fields that are useful for generating a Software Bill of Materials (SBOM).
$ ./cert-venv/bin/cert-uefi-parser --gui {firmware-related-file}
$ ./cert-venv/bin/cert-uefi-parser --text {firmware-related-file} | less
$ ./cert-venv/bin/cert-uefi-parser --json {firmware-related-file} >output.json
$ ./cert-venv/bin/cert-uefi-parser --sbom {firmware-related-file} >output.json
Sample firmware files can typically be obtained by downloading the BIOS or UEFI update tools from your system vendor’s support site. While not all models are guaranteed to be fully supported, many common vendor formats parse successfully, and examining these update files is a good way to begin exploring the parser’s capabilities.
Metadata
Release files for cert-uefi-parser 1.0.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cert_uefi_parser-1.0.8.tar.gz | 1.1 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cert_uefi_parser-1.0.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 2.2 MB
Release files / cert_uefi_parser-1.0.8.tar.gz
| Download URL | cert_uefi_parser-1.0.8.tar.gz |
|---|---|
| Size | 1.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a5cec42bb59b5791001edf75e629b18ec3364d74d72ae32118fc8a702364c72c
|
|
BLAKE2b-256 checksum How to use checksums |
7e456d9dedb0417ed89289afd57c90ad58cfe7c6a88eb22b93c8daea56a75483
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 27, 2026.
Transparency logRelease files / cert_uefi_parser-1.0.8-py3-none-any.whl
| Download URL | cert_uefi_parser-1.0.8-py3-none-any.whl |
|---|---|
| Size | 1.1 MB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2b7387b8d748d30f688ad311138bf817896907b5c977623b9bef1320e3040218
|
|
BLAKE2b-256 checksum How to use checksums |
235e00e42633cff7553d78f3f3a9bd24a7c7155cc59aa097c588e3498244357b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 27, 2026.
Transparency log