CPU Spectre Forensi...
 
Notifications
Clear all

CPU Spectre Forensics

5 Posts
3 Users
0 Reactions
720 Views
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter   [#16205]

Where would be a successfull Spectre variant 3 attack be logged or traceable? Which tool can enable to find this?

We want so software guard an AMD machine.



   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 22 years ago
Posts: 3568
 

Where would be a successfull Spectre variant 3 attack be logged or traceable? Which tool can enable to find this?

We want so software guard an AMD machine.

What do you see as the delivery mechanism?

What is the target OS? I'm sure what's logged (if anything) would vary depending upon the OS running, and what *it's* capable of logging.

What additional applications do you have running? EDR?



   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

Lessons learned of Intel ME Patch Rollback attacks recently. SGX is the problem. KAISER is well documented, crime is learning we observe.

New MeltSpect-Ransomware on the rise.

Tiny primer on SGX
http//slideplayer.com/slide/10575320/



   
ReplyQuote
(@c-r-s)
Estimable Member
Joined: 15 years ago
Posts: 170
 

Excellent Blog post from Endgame on this https://www.endgame.com/blog/technical-blog/detecting-spectre-and-meltdown-using-hardware-performance-counters



   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

Thank you! Top.

Question Did you google, regularly visit this page, get the info by a tweet or 4th unknown reason?

Like to really learn from you -)



   
ReplyQuote
Share: