logo

Direct Memory Access (DMA) attacks. Risks, techniques, and mitigations in hardware hacking

ID: abec8f4d-3fb6-5538-925a-906aa3a5f2c2

STIX ID: report--abec8f4d-3fb6-5538-925a-906aa3a5f2c2

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-09-26

Date Updated: 2026-03-24

Author: Rachel Rabin

...
...

This report examines DMA attacks across physical and remote vectors and demonstrates a PCIe-based proof of concept using PCILeech and Squirrel Screamer to achieve kernel-level memory access on a Linux system, enabling filesystem modification and credential/rooting scenarios. It highlights risks to enterprise and cloud/RDMA environments (including pre-boot exposures and past cases like macOS FileVault) and outlines mitigations such as disabling or controlling DMA-capable ports, enforcing IOMMU/Kernel DMA Protection, and strengthening BIOS/UEFI boot protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.