Tools
- Volatility 3 Framework:
- me_cleaner (Intel ME):
Module Summary
| Topic | Cybersecurity Relevance | Key Attack | Key Defense |
|---|---|---|---|
| CPU | Spectre/Meltdown, RIP control in exploits | Speculative execution side-channel | Microcode updates, software mitigations |
| RAM | Fileless malware, memory forensics | Cold boot, Rowhammer, process injection | Pre-boot PIN, ECC RAM, IOMMU |
| ROM | Firmware persistence | HDD firmware implant (Equation Group) | Secure firmware verification, signing |
| GPU | Password cracking acceleration | GPU memory scraping | Strong passwords (12+ chars, Argon2 hashing) |
| Motherboard | ME/AMT backdoor, DMA attacks | Intel AMT auth bypass, PCILeech | IOMMU, disable unnecessary ME features |
| Storage | Data recovery, forensics | Disk imaging, file carving | Crypto erase (NVMe Sanitize), physical destruction |
| BIOS/UEFI | Most persistent malware class | BlackLotus Secure Boot bypass | Secure Boot, firmware updates, UEFI password |
| PSU | Hardware fault injection | Power glitching, side-channel analysis | UPS for availability, constant-time crypto |
| Physical | Attack foundation for everything | Evil Maid, hardware keylogger, tailgating | Layered physical controls, tamper evidence |
This document is part of the **Zero to Expert Cybersecurity Roadmap* — a comprehensive, systematic curriculum designed for professionals at the intersection of electrical engineering and cybersecurity.*
Stage 0.1 Complete → Proceed to Stage 0.2: Operating System Fundamentals
Document Version: 1.0
Last Updated: 2025
License: MIT — Free to use, share, and modify with attribution
SOCIAL SHARE CARD GENERATOR