Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Enermax Aquafusion 360 review LCS
Intel Core i5 11400F processor review
Corsair Vengeance RGB Pro SL 3600 MHz 32GB review
ASRock Z590 Extreme review
Gigabyte Radeon RX 6700 XT Gaming OC review
Corsair K70 RGB TKL keyboard review
Corsair RM650x (2021) power supply review
be quiet! Silent Loop 2 280mm review
Corsair K55 RGB PRO XT keyboard review
Guru3D Rig of the Month - March 2021

New Downloads
AMD Radeon Adrenalin Edition 21.4.1 driver download
3DMark Download v2.17.7166 + Time Spy
NVIDIA Unreal Engine 4 RTX & DLSS Demo
Intel HD graphics Driver Download Version: DCH 27.20.100.9466
CPU-Z download v1.96
GeForce 466.11 WHQL driver download
Guru3D RTSS Rivatuner Statistics Server Download 7.3.2 Beta 2
MSI Afterburner 4.6.4 Beta 2 Download
HWiNFO Download v7.02
Corsair Utility Engine Download (iCUE) Download v4.9.350


New Forum Topics
World Record for the fastest Graphics card ever recorded done on a Red Devil Ultimate , 3225Mhz ! NVidia Anti-Aliasing Guide (updated) WDDM 3.0 / 470.25 So if your a normal user and hate GPU mining,get over it.Try this Fix game stutter on Win 10 1703-1809 Download: Radeon Software Adrenalin 21.4.1 drivers Apple 2021 iMac, Powered by M1 Chip, Featuring 4.5K Retina Display Fine Utilise Power of RadeonPRO Software & SweetFX Part 2 Vivid Gaming Display Color Enhancement for CGN cards??? RDNA2 RX6000 Series Owners Thread, Tests, Mods, BIOS & Tweaks !




Guru3D.com » News » UEFI scanner brings Microsoft Defender ATP protection to a new level

UEFI scanner brings Microsoft Defender ATP protection to a new level

by Hilbert Hagedoorn on: 06/18/2020 08:12 AM | source: | 16 comment(s)
UEFI scanner brings Microsoft Defender ATP protection to a new level

Let's face it, UEFI, in your BIOS is a little operating system on its own, completely unprotected. Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) is extending its protection capabilities to the firmware level with a new Unified Extensible Firmware Interface (UEFI) scanner.

The Unified Extensible Firmware Interface (UEFI) is a replacement for legacy BIOS. If the chipset is configured correctly (UEFI & chipset configuration itself) and secure boot is enabled, the firmware is reasonably secure. To perform a hardware-based attack, attackers exploit a vulnerable firmware or a misconfigured machine to deploy a rootkit, which allows attackers to gain foothold on the machine.

Hardware and firmware-level attacks have continued to rise in recent years, as modern security solutions made persistence and detection evasion on the operating system more difficult. Attackers compromise the boot flow to achieve low-level malware behavior that’s hard to detect, posing a significant risk to an organization’s security posture.

Windows Defender System Guard helps defend against firmware attacks by providing guarantees for secure boot through hardware-backed security features like hypervisor-level attestation and Secure Launch, also known as Dynamic Root of Trust (DRTM), which are enabled by default in Secured-core PCs. The new UEFI scan engine in Microsoft Defender ATP expands on these protections by making firmware scanning broadly available. 

 

 

The UEFI scanner is a new component of the built-in antivirus solution on Windows 10 and gives Microsoft Defender ATP the unique ability to scan inside of the firmware filesystem and perform security assessment. It integrates insights from our partner chipset manufacturers and further expands the comprehensive endpoint protection provided by Microsoft Defender ATP.

The new UEFI scanner reads the firmware file system at runtime by interacting with the motherboard chipset. To detect threats, it performs dynamic analysis using multiple new solution components that include:

  • UEFI anti-rootkit, which reaches the firmware through Serial Peripheral Interface (SPI)
  • Full filesystem scanner, which analyzes content inside the firmware
  • Detection engine, which identifies exploits and malicious behaviors

Firmware scanning is orchestrated by runtime events like suspicious driver load and through periodic system scans. Detections are reported in Windows Security, under Protection history. 

Microsoft Defender ATP customers will also see these detections raised as alerts in Microsoft Defender Security Center, empowering security operations teams to investigate and respond to firmware attacks and suspicious activities at the firmware level in their environments. 

To detect unknown threats in SPI flash, signals from the UEFI scanner are analyzed to identify anomalies and where they have been executed. Anomalies are reported to the Microsoft Defender Security Center for investigation. Thanks, Watcher for the news submit.



UEFI scanner brings Microsoft Defender ATP protection to a new level




« AMD Ryzen ZEN3 architecture not delayed, still to be released in 2020 says AMD · UEFI scanner brings Microsoft Defender ATP protection to a new level · ViewSonic Launches New Line of 4K Premium Wireless Presentation Displays »

4 pages 1 2 3 4


tsunami231
Senior Member



Posts: 11521
Joined: 2003-05-24

#5802938 Posted on: 06/24/2020 10:00 PM
they are all gona start doing this at somepoint give them time not sure I feel about software having access to UEFI I barely like the stuff MS has access too, I pretty sure Avast already does this

4 pages 1 2 3 4


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2021