Friday, June 19th 2020
Microsoft Extends its ATP Defender Protection to UEFI BIOS With UEFI Scanner
Microsoft has announced an extension to the Windows Defender System Guard which will allow it to also verify and guarantee integryity of systems at a UEFI BIOS level. Citing an increase in hardware and firmware-level attacks over the years, the extended protection functionality aims to guarantee protection across the entire hierarchy of a device, from firmware up through to cloud processing.
The UEFI scanner is a new component of the built-in antivirus solution on Windows 10 and gives Microsoft Defender ATP the unique ability to scan inside of the firmware filesystem and perform security assessment. Working in conjunction with your systems' chipset, the UEFI scanner features a three-pronged solution to firmware security: UEFI anti-rootkit, which reaches the firmware through Serial Peripheral Interface (SPI); Full filesystem scanner, which analyzes content inside the firmware; and a Detection engine, which identifies exploits and malicious behaviors.This new tool aims to increase odds of detection for devices whose boot has already been compromised by rootkits or other kind of malware acting at the firmware level. The idea is to keep your boot flow secure and trustworthy, something that will almost certainly be rendered impossible by a rootkit messing with OS and software protection privileges to keep escalating their control over your machine.
Source:
Microsoft
The UEFI scanner is a new component of the built-in antivirus solution on Windows 10 and gives Microsoft Defender ATP the unique ability to scan inside of the firmware filesystem and perform security assessment. Working in conjunction with your systems' chipset, the UEFI scanner features a three-pronged solution to firmware security: UEFI anti-rootkit, which reaches the firmware through Serial Peripheral Interface (SPI); Full filesystem scanner, which analyzes content inside the firmware; and a Detection engine, which identifies exploits and malicious behaviors.This new tool aims to increase odds of detection for devices whose boot has already been compromised by rootkits or other kind of malware acting at the firmware level. The idea is to keep your boot flow secure and trustworthy, something that will almost certainly be rendered impossible by a rootkit messing with OS and software protection privileges to keep escalating their control over your machine.
25 Comments on Microsoft Extends its ATP Defender Protection to UEFI BIOS With UEFI Scanner
A specific version of Windows 10?
An automatic update for all versions of Windows 10?
A separate download?
And when do we get this?
www.microsoft.com/en-us/microsoft-365/windows/microsoft-defender-atp
3 words - fek you M$
I doubt this'll work without firmware integration anyways. It certainly won't be able to REMOVE any threats without help from the firmware vendor, so kinda pointless.
I sort of was one of the UEFI malware pioneers, if people recall. Dealt with a case a year or so ago. I know a thing or two and this is really just publicity horseshit. it's most likely just running signature checks and then saying "oh nos!" and leaving you to figure it out...
Not always a justified one but certainly a hard to defeat one.
The ME binary and psp binaries are pretty opaque though.