
1/30/2016 · Ted Reed
What this post added
This post details the evolving landscape of hardware and firmware attacks and introduces osquery as a tool for defense and detection. It highlights the addition of hardware monitoring to osquery, enabling security teams to gain insights into system behavior, detect compromises, and manage vulnerabilities. The post discusses specific attack vectors like drive firmware attacks, EFI RATs, and the challenges of securing firmware due to its early execution and black-box nature. It proposes defense strategies including tracking kernel modules, auditing bootloaders, and leveraging osquery for collecting hardware-related signals and event-based data.