Tools
DAWGMON
Dawg the hallway monitor: monitor operating system changes and analyze introduced attack surface when installing software. See the introductory blogpost
White Papers
Defeating Secure Boot Protections With Symlink and Hard Link Attacks
The white paper demonstrates the use of file systems features of a non-verified partition such as symbolic links (symlinks)ย to defeat secure boot protection.