optional
EFI
Boot Services
EFI
Runtime Services
Winload.efi
Bootmgr.efi
WinPE?
Bootmgfw.efi
Loader.efi
EFI DXE
Dispatcher
EfiGuardDxe.efi
Ntoskrnl.exe
PG
DSE
HAL.dll
EfiDSEFix.exe
UM-KM boundary
Kernel mode
User mode
load
hook
patch
syscall
No
Yes
patch