Intel ME: Flash File System Explained

Presented at Black Hat Europe 2017, Dec. 6, 2017, 11:45 a.m. (60 minutes)

Intel Management Engine (ME) technology has been around for over 10 years (since 2005), but it seems impossible to find any official information about ME on the Internet. Fortunately, some studies have been published in recent years; however, all of them deal with ME 10 and earlier, while modern computers implement ME 11 (introduced in 2015 for Skylake microarchitecture). In our presentation, we explain in detail how ME 11.x stores its state on the flash and the other types of file systems that are supported by ME 11.x.


Presenters:

  • Dmitry Sklyarov - Head of Reverse Engineering, Positive Technologies
    Dmitry Sklyarov is Head of Reverse Engineering at Positive Technologies. He is Former Security Researcher at Elcomsoft and a lecturer at Moscow State Technical University. He researched the security of eBooks, authentication of digital photos and smartphone forensics. His work has been presented at many conferences, including Black Hat EU/UAE, Confidence, Troopers.

Links:

Similar Presentations: