• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.
  • The forums have been upgraded with support for dark mode. By default it will follow the setting on your system/browser. You may override it by scrolling to the end of the page and clicking the gears icon.

Microsoft Extends its ATP Defender Protection to UEFI BIOS With UEFI Scanner

Raevenlord

News Editor
Joined
Aug 12, 2016
Messages
3,755 (1.16/day)
Location
Portugal
System Name The Ryzening
Processor AMD Ryzen 9 5900X
Motherboard MSI X570 MAG TOMAHAWK
Cooling Lian Li Galahad 360mm AIO
Memory 32 GB G.Skill Trident Z F4-3733 (4x 8 GB)
Video Card(s) Gigabyte RTX 3070 Ti
Storage Boot: Transcend MTE220S 2TB, Kintson A2000 1TB, Seagate Firewolf Pro 14 TB
Display(s) Acer Nitro VG270UP (1440p 144 Hz IPS)
Case Lian Li O11DX Dynamic White
Audio Device(s) iFi Audio Zen DAC
Power Supply Seasonic Focus+ 750 W
Mouse Cooler Master Masterkeys Lite L
Keyboard Cooler Master Masterkeys Lite L
Software Windows 10 x64
Microsoft has announced an extension to the Windows Defender System Guard which will allow it to also verify and guarantee integryity of systems at a UEFI BIOS level. Citing an increase in hardware and firmware-level attacks over the years, the extended protection functionality aims to guarantee protection across the entire hierarchy of a device, from firmware up through to cloud processing.

The UEFI scanner is a new component of the built-in antivirus solution on Windows 10 and gives Microsoft Defender ATP the unique ability to scan inside of the firmware filesystem and perform security assessment. Working in conjunction with your systems' chipset, the UEFI scanner features a three-pronged solution to firmware security: UEFI anti-rootkit, which reaches the firmware through Serial Peripheral Interface (SPI); Full filesystem scanner, which analyzes content inside the firmware; and a Detection engine, which identifies exploits and malicious behaviors.





This new tool aims to increase odds of detection for devices whose boot has already been compromised by rootkits or other kind of malware acting at the firmware level. The idea is to keep your boot flow secure and trustworthy, something that will almost certainly be rendered impossible by a rootkit messing with OS and software protection privileges to keep escalating their control over your machine.



View at TechPowerUp Main Site
 
And how do we get this?

A specific version of Windows 10?

An automatic update for all versions of Windows 10?

A separate download?

And when do we get this?
 
Actually, you need Microsoft 365 A5 subscription to enable ATP capabilities and the Microsoft Defender Security Center portal...
 
Sure, we'll just give Microsoft full access and control over our systems right down to Bios level. :kookoo:
 
just wonder how the scanner can recognize a hacked signed firmware ...
 
i hope it does not detect OC tweaks such as xeon turbo uefi hack, which loads via efi command each boot
 
And how do we get this?

A specific version of Windows 10?

An automatic update for all versions of Windows 10?

A separate download?

And when do we get this?

This is enterprise stuff. You might be able to get past the business requirements but you will pay out the nose for licensing.
 
Hey this actually works with Intune within Azure too. You can monitor company laptops now.
 
Hey this actually works with Intune within Azure too. You can monitor company laptops now.

yes was actually happy to see the panel isn’t terrible either. If we weren’t getting such a deep discount on our current offering I’d be tempted to switch to be honest.
 
Microshaft can now scan our BIOS firmware ? and we want to keep that garbage ? lol. Nope Win10 is already a piece of crap with bugs always thrown into the wild and release a crappy patch tuesday while enterprise users get a polished and stable options with all customized WaaS garbage - Windows as a Service. M$ is just absuing their monopoly nowadays, made Office as a Service, OS as a service and their game studios is literal trash tier garbage, ruined Gears of War with some political garbage shoe horned for representation and massive departure of art style and still no release on PC, their Halo MCC is full of bugs and garbage issues. No hope for this but they will always have thier stock at top because of monopoly and successful subversion of people thinking M$ does for their best.
 
Sure, we'll just give Microsoft full access and control over our systems right down to Bios level. :kookoo:

Very well said and Microsoft has deep roots that are connected to foreign government aka India.
 
How come every Microsoft article on here devolves into the usual "Microsoft sucks!" crap? :rolleyes:
 
Because screw users paying $400 for genuine retail Win 10 Pro licenses, or God forbid - Pro for Workstations...
3 words - fek you M$
 
yes was actually happy to see the panel isn’t terrible either. If we weren’t getting such a deep discount on our current offering I’d be tempted to switch to be honest.

Didn't Microsoft offer your company that "hefty" discount at the beginning of COVID? Our renewal was in February but they extended a bit and hit us with an offer we cannot refuse. :laugh: Way better than the trash GSuite that Google was attempting to deal to us. We have an internal Outlook add-in (or add-on according to Google) that we need to integrate for all faculty and staff members and they said its not possible to convert because they want us to conform to their "Build cards" thing. Our CIO obviously said no.
 
Great, UEFI level botnet.
 
Great, UEFI level botnet.

We've had those for a while.

I doubt this'll work without firmware integration anyways. It certainly won't be able to REMOVE any threats without help from the firmware vendor, so kinda pointless.

I sort of was one of the UEFI malware pioneers, if people recall. Dealt with a case a year or so ago. I know a thing or two and this is really just publicity horseshit.

just wonder how the scanner can recognize a hacked signed firmware ...

it's most likely just running signature checks and then saying "oh nos!" and leaving you to figure it out...
 
We've had those for a while.

I doubt this'll work without firmware integration anyways. It certainly won't be able to REMOVE any threats without help from the firmware vendor, so kinda pointless.

I sort of was one of the UEFI malware pioneers, if people recall. Dealt with a case a year or so ago. I know a thing or two and this is really just publicity horseshit.



it's most likely just running signature checks and then saying "oh nos!" and leaving you to figure it out...
So basically, as useful as Windows Firewall.
 
How come every Microsoft article on here devolves into the usual "Microsoft sucks!" crap? :rolleyes:
More like how every article here devolves into the usual "[Company/Organisation/Country] sucks!" crap
 
More like how every article here devolves into the usual "[Company/Organisation/Country] sucks!" crap

Microsoft sucking is practically an internet meme at this point though.

Not always a justified one but certainly a hard to defeat one.
 
I doubt this'll work without firmware integration anyways. It certainly won't be able to REMOVE any threats without help from the firmware vendor, so kinda pointless.
Pretty much this, yes.

More like how every article here devolves into the usual "[Company/Organisation/Country] sucks!" crap
That happens everywhere. TPU is not the exclusive hotbed of complainers. Have you ever been on Reddit? 'Cause damn...
 
Last edited:
How come every Microsoft article on here devolves into the usual "Microsoft sucks!" crap? :rolleyes:
Not sure, but it always draws the tinfoil out, like this one below:

Microshaft can now scan our BIOS firmware ? and we want to keep that garbage ? lol. Nope Win10 is already a piece of crap with bugs always thrown into the wild and release a crappy patch tuesday while enterprise users get a polished and stable options with all customized WaaS garbage - Windows as a Service. M$ is just absuing their monopoly nowadays, made Office as a Service, OS as a service and their game studios is literal trash tier garbage, ruined Gears of War with some political garbage shoe horned for representation and massive departure of art style and still no release on PC, their Halo MCC is full of bugs and garbage issues. No hope for this but they will always have thier stock at top because of monopoly and successful subversion of people thinking M$ does for their best.

I could try to argue, but what is the point?
 
If anyone wanted to actually formulate an argument, they could talk about how the UEFI spec is kinda bloated and sucks in that way... but then they'd really have to blame one of the sponsor companies (Intel is one IIRC) not Microsoft.

That happens everywhere. TPU is not the exclusive hotbed of complainers.

For certain.
 
And how AGESA and the rest are proprietary blobs. I mean yeah, 'trade secrets' but we can never be sure.
 
Back
Top