GrabAccess is an open-source UEFI bootkit utility engineered to bypass Windows local account sign-in authentication via physical access. Operating through the Windows Platform Binary Table (WPBT) ACPI mechanism, it enables direct system access without kernel-level modification.
Technical Overview of GrabAccess
GrabAccess operates entirely as a portable, standalone solution deployed to FAT16/FAT32 USB media or integrated directly into motherboard UEFI firmware. Execution occurs at pre-boot via UEFI DXE drivers and Native NT applications, incurring zero background resource consumption once OS initialization concludes. Unlike conventional proprietary bypass utilities such as Kon-Boot, it relies on legitimate ACPI table manipulation rather than runtime Windows kernel patching.
Core Features of GrabAccess
- Authentication bypass hooks local account verification in LSASS to accept arbitrary password, PIN, or picture password inputs.
- Fallback rescue shell provides SYSTEM-level file explorer, command prompt, and account management when accounts cannot be bypassed.
- Hardware-level persistence embeds payload deployment into motherboard UEFI firmware to survive hard disk replacements and clean OS reinstallations.
- Automated startup injection writes custom user-specified executables directly to Windows startup without manual installation wizards.
System Compatibility & Updates
GrabAccess supports 64-bit UEFI-based Windows installations with Secure Boot and CSM disabled; it does not support 32-bit operating systems or legacy MBR partitions. The latest Version 1.2 release adds local sign-in bypass for PIN and picture passwords alongside standalone file management fallback capabilities.