.EFI

EFI File

UEFI (EFI) Boot Application / Driver
Ask a question
QUICK ANSWER

An EFI file is a UEFI boot program - an executable the computer's firmware runs at startup, before the operating system loads. You do not open it by double-clicking; the motherboard firmware runs it automatically. You encounter EFI files when making a bootable USB, repairing a bootloader, or browsing the EFI System Partition. Do not delete them from the EFI System Partition - doing so can leave the PC unbootable.

Developer: UEFI Forum (specification); binaries built by OS/firmware/bootloader vendors Category: System Files Open standard MIME: application/efi
OPENS ON Windows macOS Linux
Related: .NOMEDIA · .DLL · .TMP · .LNK

On this page

19k+ extensions indexed
Last reviewed Jun 21, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the EFI file format?

A .efi file is a system file used by computer systems and devices based on x86-64 and ARM-based hardware. An .efi file contains executable code that runs between the firmware and operating system levels - technically it is a PE32+ Portable Executable image with a UEFI-specific subsystem value rather than a standard Windows subsystem.

Usage of .efi files

.efi system files are used during the system boot process, for staging firmware updates, and running pre-boot programs. .efi files allow the system to hand off pre-boot processes to a controlled environment. Common examples include bootmgfw.efi (Windows Boot Manager), grubx64.efi (GRUB bootloader for Linux), and shimx64.efi (Secure Boot shim). Sometimes .efi files are included in firmware update packages and loaded during the boot process. All .efi binaries must reside on the EFI System Partition (ESP) - a FAT32 volume on a GPT-partitioned disk that firmware can access before any OS driver loads.

EFI and the UEFI specification

The EFI standard was initially developed by Intel. EFI was later updated and became known as UEFI (Unified Extensible Firmware Interface), which has replaced the legacy Basic Input/Output System (BIOS) on virtually all modern PCs and servers. The UEFI Forum, an industry consortium, now maintains the specification.

Security & safety

RISK: MEDIUM

An .efi is executable code that runs at a very privileged moment - before the OS, with full firmware access - so a MALICIOUS .efi (a "bootkit") can be dangerous and persistent. Modern PCs mitigate this with UEFI Secure Boot, which refuses to run .efi binaries that aren't signed by a trusted key. Practical guidance: never place or run an unknown .efi in your EFI System Partition or boot from an untrusted .efi; keep Secure Boot enabled unless you have a specific reason not to. The opposite risk is just as real: deleting or renaming legitimate .efi files in the ESP (e.g. bootmgfw.efi, grubx64.efi) can make the machine unbootable - leave them alone unless you're deliberately repairing the bootloader.

Format details

in a nutshell
FULL NAMEUEFI (EFI) Boot Application / Driver
DEVELOPERUEFI Forum (specification); binaries built by OS/firmware/bootloader vendorssince EFI 1.0 (Intel, ~2000) → UEFI 2.x (UEFI Forum, 2005+); standard on PCs since ~2012
CATEGORYSystem Files
MIME TYPEapplication/efi
TYPEExecutable boot binary - PE32+ (Portable Executable) image with the "EFI Application/Driver" subsystem; run by UEFI firmware, not the OS
STANDARDOpen · royalty-free
This extension is also used by…
  • Adobe Encapsulated/embedded font or HP printer firmware blobs - A few unrelated products have historically used .efi for internal data; on a PC almost every .efi you meet is a UEFI boot binary.
MAGIC BYTES · FILE SIGNATURE
OFFSET
0001
HEX
4D5A
ASCII
MZ
An .efi binary is a Portable Executable (PE32+) image, so it begins with the "MZ" (4D 5A) DOS stub at offset 0, with the "PE\0\0" (50 45 00 00) signature later at the offset given by the header at 0x3C. What makes it an EFI binary rather than a Windows .exe is the PE Subsystem field: 10 = EFI Application, 11 = EFI Boot Service Driver, 12 = EFI Runtime Driver. So an .efi looks like a Windows executable at the byte level but targets UEFI firmware, not Windows.

Programs that open EFI files

Windows3 apps
UEFI firmware (the motherboard itself) Built-in An .efi is RUN, not opened: the firmware executes it at boot (e.g. via the boot menu / boot order). You don't double-click it in Windows.
EDK II (TianoCore) Open-source For developers: the reference UEFI SDK to build, inspect and debug .efi applications/drivers.
PE viewer (e.g. PE-bear / CFF Explorer) Open-source To INSPECT what an .efi is, open it as a PE file and check the Subsystem field (10/11/12 = EFI). Doesn't run it.
macOS1 app
EDK II (TianoCore) Open-source Cross-build/inspect UEFI .efi binaries (Macs use a related EFI firmware); developer-oriented.
Linux2 apps
UEFI firmware + efibootmgr Open-source Manage which .efi bootloader the firmware launches (boot entries/order) from Linux; the .efi itself runs at boot.
EDK II (TianoCore) / GNU-EFI Open-source Build and inspect UEFI .efi binaries; run/test them in the QEMU+OVMF virtual UEFI environment.

Technical details

deep spec
File signature`MZ` (hex `4D 5A`) at offset 0 - DOS stub; PE signature (bytes `50 45 00 00`) at the offset given by the 4-byte LE pointer at header offset `0x3C`
Base binary formatPE32+ (64-bit Portable Executable) - same container format as a Windows `.exe`, differentiated only by the PE Subsystem field value
PE subsystem field values10 = EFI Application; 11 = EFI Boot Service Driver; 12 = EFI Runtime Driver; 13 = EFI ROM Image
MIME type`application/efi`
Supported CPU architecturesx86-64 (IA-32e), IA-32, ARM Thumb-2, AArch64, RISC-V 32/64/128, IA-64 (Itanium) - architecture encoded in the PE Machine field
Required partition and filesystemEFI System Partition (ESP) formatted as FAT12, FAT16, or FAT32 on a GPT-partitioned disk; NTFS and ext4 are not supported natively by UEFI firmware
Standard install path on ESP`\EFI\<Vendor>\<name>.efi` - e.g., `\EFI\Microsoft\Boot\bootmgfw.efi` or `\EFI\ubuntu\grubx64.efi`
Secure Boot code signingSigned with Authenticode (RSA + SHA-256); verified against UEFI Secure Boot key databases: PK (Platform Key), KEK, `db` (allowed), and `dbx` (revoked)
Entry point prototype`EFI_STATUS EFIAPI ImageEntry(EFI_HANDLE ImageHandle, EFI_SYSTEM_TABLE *SystemTable)` - same signature for all EFI application types
Execution privilege levelHighest CPU privilege level - ring 0 (CPL0) on x86; EL1 or EL2 on AArch64 - in a flat pre-OS address space with direct hardware access
Boot Service vs. Runtime residencyBoot Service Drivers (subsystem 11) are unloaded when the OS calls `ExitBootServices()`; Runtime Drivers (subsystem 12) remain mapped after OS handoff
Disk partitioning requirementGPT (GUID Partition Table) required for native UEFI boot mode; MBR-only disks are not supported
Common well-known binaries`bootmgfw.efi` (Windows Boot Manager), `grubx64.efi` (GRUB), `shimx64.efi` (Secure Boot shim), `Shell.efi` (UEFI interactive shell)
Build toolchainsEDK II (TianoCore), GNU-EFI, LLVM/clang with `-target x86_64-unknown-uefi`; output must be linked as a PE32+ image with UEFI subsystem flags
ReleasedEFI 1.0 (Intel, ~2000) → UEFI 2.x (UEFI Forum, 2005+); standard on PCs since ~2012
Open standardYes · royalty-free
Specificationuefi.org

EFI conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with EFI files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about EFI files.

Frequently asked questions

What is an EFI file?
It's a UEFI boot program - an executable the computer's firmware runs at startup, before the operating system (for example bootx64.efi on a bootable USB, or the Windows/GRUB bootloader in the EFI System Partition). It's not a document or media file.
How do I open an EFI file?
You don't open it like a normal file - it's RUN by the motherboard's UEFI firmware at boot. To inspect what it is, you can open it in a PE viewer (it's a PE32+ executable). Developers build/test .efi binaries with EDK II (TianoCore).
Can I delete EFI files?
Not the ones in the EFI System Partition - files like bootmgfw.efi or grubx64.efi are what boot your OS, and deleting them can leave the PC unbootable. Only remove .efi files if you're deliberately and carefully repairing the boot configuration.
Is an EFI file the same as an EXE?
They share the PE format, but an .efi targets UEFI firmware (EFI subsystem) while an .exe targets Windows. An .efi won't run as a Windows program and can't be converted to one.
Why is there an EFI partition / BOOTX64.EFI on my drive or USB?
UEFI firmware boots by running an .efi bootloader. Installed systems keep it in the FAT32 EFI System Partition; removable media use the standard fallback path \EFI\BOOT\BOOTX64.EFI so any UEFI PC can boot them.
Are EFI files safe?
Legitimate ones are essential and safe; the danger is a malicious .efi (bootkit) running before the OS. UEFI Secure Boot blocks unsigned/untrusted .efi binaries - keep it on, and never boot from or install an unknown .efi.

References

1UEFI Forum - Specificationsuefi.org
2TianoCore / EDK II - UEFI development kitwww.tianocore.org

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.BINCD/DVD Disc Image (BIN/CUE)
7.NOMEDIAAndroid No-Media Marker File
8.MDMarkdown Document
9.RPMSGRestricted Permission Message
10.TMPTemporary File

Related extensions

.NOMEDIAAndroid No-Media Marker File
.DLLDynamic Link Library
.TMPTemporary File
.LNKWindows Shell Link (Shortcut)
.PKGmacOS Installer Package
.ETLEvent Trace Log

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z