The GlitchMod knowledge base

Creating a Shadowboot Image

You can create custom NAND images that can be used through Shadowbooting. GoobyCorp has created a script as part of their Xbox-360-Crypto suite, shadowboot.py, which is designed for extracting, analyzing, and building Xbox 360 shadowboot i…

3 min readUpdated Oct 9, 2026

You can create custom NAND images that can be used through Shadowbooting. GoobyCorp has created a script as part of their Xbox-360-Crypto suite, shadowboot.py, which is designed for extracting, analyzing, and building Xbox 360 shadowboot images.

Setup

As a prerequisite, Python 3 must be installed on your PC.

  1. Run pip install cryptography to install the cryptography library in python.
  2. Download Xbox-360-Crypto and extract the contents to your PC.
  3. On line 23 of shadowboot.py, add from nand_tool import * and save the file.
  4. Add keys to Xbox-360-Crypto-master\Keys\:
    • 1BL_pub.bin (key size is 272 bytes, if your key is 16 bytes it is the wrong key)
    • Master_pub.bin (rename if the key you have is called MAST_pub.bin)
    • SB_prv.bin (rename if the key you have is called SB_priv.bin)
  5. Download and extract the contents of StreamIO into Xbox-360-Crypto-master\StreamIO.

Usage

Build Mode (build)

Creates a new shadowboot image at the specified OUTPUT_PATH. Requires a manifest file or build directory.

python3 shadowboot.py build OUTPUT_PATH [options]

Options
Option Purpose
--nochecks Skip integrity checks when parsing the shadowboot.
-m, --manifest MANIFEST_PATH Use a build manifest JSON file.
-b, --build-dir BUILD_DIR_PATH Use a directory containing required files.

Example:

python3 shadowboot.py build ./output/jasper-bb-zerofuse.bin --manifest ./Build/jasper-bb-zerofuse.json

Manifest file:

./build/manifest_template.json is a template you can copy and modify. Options are explained below. Note that if a base image is provided, it will use it as a fallback so if a component is missing (e.g. "SC") it will use the component from the base image.

{
  "build": {
    "version": 17559  // (Required) Kernel version to use
  },
  "options": {
    "use_smc": true,   // (Optional) Whether to include SMC
    "use_kv": true,    // (Optional) Whether to include KeyVault
    "test_kit": false, // (Optional) Build for testkit (true) or retail/devkit (false)
    "base_image_checks_disabled": false // (Optional) Disable integrity checks on base image
  },
  "files": {
    "base_directory": "Build",   // (Required) Base directory containing the following input files
    "base_image": "xboxrom.bin", // (Optional) Base firmware image (fallback)
    "SMC": "SMC_dec.bin",    // (Optional) Decrypted SMC file
    "KV": "KV_dec.bin",      // (Optional) KeyVault file
    "SB": "sb.bin",          // (Required) SB bootloader
    "SC": "sc.bin",          // (Required) SC bootloader
    "SD": "sd.bin",          // (Required) SD bootloader
    "SE": "se.bin",          // (Optional) SE bootloader (used if HV/kernel not provided)
    "kernel": "kernel.bin",  // (Optional) Kernel binary (required if SE not provided)
    "HV": "hypervisor.bin",  // (Optional) Hypervisor binary (required if SE not provided)
    "HVK_patches": "hvk.bin" // (Optional) Patches for HV/kernel
  }
}

Extract Mode (extract)

Extracts various components from a shadowboot or flash image.

python3 shadowboot.py extract INPUT_PATH OUTPUT_DIR [options]

Options
Option Purpose
--flash Parse a full flash image instead of just a shadowboot.
--nochecks Skip integrity checks.
--all Extract everything.
--smc Extract SMC.
--keyvault, --kv Extract KeyVault.
--sb Extract SB bootloader.
--sc Extract SC bootloader.
--sd Extract SD bootloader.
--se Extract SE bootloader.
--kernel Extract Kernel.
--hypervisor, --hv Extract Hypervisor.
--loader Extract HV/kernel patch loader.
--patches Extract HV/kernel patches.

Example:

python3 shadowboot.py extract ./input/falcon-xdkbuild-nand.bin ./output/falcon-xdkbuild-nand --all

Info Mode (info)

Displays metadata about a shadowboot or flash image, including:

  • Console type
  • SMC version
  • Bootloader versions (SB, SC, SD, SE)
  • Hypervisor and Kernel versions
  • Whether the image is retail, testkit, or devkit.

python3 shadowboot.py info INPUT_PATH [options]

Options
Option Purpose
--flash Parse a full flash image instead of just a shadowboot.
--nochecks Skip integrity checks.

Example:

python3 shadowboot.py info ./input/zephyr-nand.bin

Split Mode (split)

Extracts a specific firmware version from a multi-image file.

python3 shadowboot.py split INPUT_PATH OUTPUT_DIR [options]

Options
Option Purpose
-k, --kernel KERNEL_VERSION Specify the kernel version to extract.
-r, --revision {xenon, zephyr, falcon, jasper, trinity, corona, winchester} Specify the console revision.
-t, --type {retail, testkit, devkit} Specify the console type.
--nochecks Skip integrity checks.

Test Mode (test)

Placeholder mode, currently unused.

python3 shadowboot.py test INPUT_PATH OUTPUT_PATH [options]

Options
Option Purpose
--nochecks Skip integrity checks.