---
title: "Intel ME rootkits"
date: 2022-10-19T13:20:19-07:00
replyURI: "https://mastodon.social/@byterhymer/109181969125151465"
replyTitle: "Don't forget there have already been Intel ME rootkits too"
replyType: "SocialMediaPosting"
replyAuthor: "@byterhymer@mastodon.social"
replyAuthorURI: "https://mastodon.social/@byterhymer"
---
I know of two Intel ME rootkits that didn't involve Intel AMT; the latter can be enabled/disabled on "vPro" chips. One rootkit was from 2009 and seems less relevant now; the more recent of the two was by {{}} and {{}} at Black Hat Europe 2017: {{}} (application/pdf).
Without AMT, they required physical access. Most PCs are woefully unprepared against the sorts of attacks enabled by physical access, and ME is only one entry in a long list of issues.