如何在Windows系统中用Python检查Secure Boot是否启用
检测Windows系统Secure Boot状态的Python实现方法
你提到的Secure Boot状态并非完全不向操作系统暴露,Windows提供了多种合法途径获取该信息,下面是两种可行的Python实现方案:
方案1:通过调用PowerShell命令(简单易实现)
Windows自带的Get-SecureBootStatus命令可以直接返回Secure Boot的启用状态,Python可以通过subprocess模块调用该命令并解析输出:
import subprocess import re def check_secure_boot(): try: # 执行PowerShell命令,捕获输出 result = subprocess.run( ["powershell", "-Command", "Get-SecureBootStatus"], capture_output=True, text=True, check=True ) # 匹配输出中的SecureBootEnabled字段值 status_match = re.search(r"SecureBootEnabled\s+:\s+(\w+)", result.stdout) if status_match: return status_match.group(1) == "True" return None except subprocess.CalledProcessError: # 命令执行失败,通常是BIOS不支持Secure Boot或权限不足 return None except Exception as e: print(f"检测出错: {str(e)}") return None # 调用示例 sb_status = check_secure_boot() if sb_status is True: print("Secure Boot 已启用") elif sb_status is False: print("Secure Boot 未启用") else: print("无法获取Secure Boot状态")
注意事项
- 多数情况下普通用户权限即可执行,但部分受限制环境可能需要管理员权限;
- 如果系统使用传统BIOS而非UEFI,该命令会返回不支持的提示。
方案2:直接调用Windows内核API(底层实现)
通过ctypes调用Windows的GetFirmwareEnvironmentVariableW API,直接读取UEFI固件中的SecureBoot变量,这是更底层的实现方式:
import ctypes from ctypes import wintypes def check_secure_boot_api(): kernel32 = ctypes.WinDLL('kernel32', use_last_error=True) # 定义API函数原型 GetFirmwareEnvVar = kernel32.GetFirmwareEnvironmentVariableW GetFirmwareEnvVar.argtypes = [wintypes.LPCWSTR, wintypes.LPCWSTR, wintypes.LPVOID, wintypes.DWORD] GetFirmwareEnvVar.restype = wintypes.DWORD # Secure Boot变量的GUID和名称(UEFI标准定义) SB_GUID = "{8BE4DF61-93CA-11D2-AA0D-00E098032B8C}" SB_VAR_NAME = "SecureBoot" # 准备缓冲区存储变量值 buffer = ctypes.c_byte() buf_size = ctypes.sizeof(buffer) # 调用API读取变量 bytes_read = GetFirmwareEnvVar(SB_VAR_NAME, SB_GUID, ctypes.byref(buffer), buf_size) if bytes_read == 0: error_code = ctypes.get_last_error() if error_code == 2: # 变量不存在,说明Secure Boot未启用或不支持 return False elif error_code == 5: print("需要管理员权限才能读取Secure Boot状态") return None else: print(f"API调用失败,错误码: {error_code}") return None # 变量值为1表示启用,0表示禁用 return buffer.value == 1 # 调用示例 sb_status = check_secure_boot_api() if sb_status is True: print("Secure Boot 已启用") elif sb_status is False: print("Secure Boot 未启用") else: print("无法获取Secure Boot状态")
注意事项
- 必须以管理员权限运行脚本,否则会返回权限错误;
- 仅支持UEFI系统,传统BIOS系统无法读取该变量。
关于Valorant等游戏的检测逻辑
这类游戏的检测方式和上述方案类似,要么调用系统提供的合法接口,要么直接读取UEFI固件变量,并非利用未公开的漏洞——Windows本身就提供了获取Secure Boot状态的官方途径。
内容的提问来源于stack exchange,提问作者archangel78
相关产品推荐
相关产品推荐

