Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Drop down and tweak it!

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Tweaking.com - Windows Repair
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » June 2023 » NSA Issues a Black Lotus Mitigation Guide

NSA Issues a Black Lotus Mitigation Guide


Posted by: Corporal Punishment on 06/24/2023 09:51 AM [ comments Comments ]


BlackLotus is malware software that exploits a boot loader flaw known as Baton Drop (CVE-2022-21894) to bypass Secure Boot and take control of the endpoint from the earliest phase of software boot. Microsoft has issued patches for supported versions of Windows, but according to the BlackLotus Mitigation Guide published this week by the NSA; more is needed to mitigate the threat fully.

According to the NSA, BlackLotus is not a firmware threat but a software threat that targets the boot partition. It uses Shim and GRUB, two components commonly used in Linux boot, to integrate its payload and implant itself into the endpoint. Once implanted, BlackLotus can strip the Secure Boot policy and prevent its enforcement. This means that attackers can replace fully patched boot loaders with vulnerable versions to execute BlackLotus.

Here are some of the steps suggested by the NSA:

Update recovery media and activate optional mitigations
Create updated recovery media for each endpoint and enable optional mitigations such as Credential Guard, Device Guard, and Secure Launch.

Harden user executable policies
Configure user executable policies such as AppLocker or Windows Defender Application Control to prevent unauthorized executables from running on the endpoint.

Monitor boot partition integrity
Use tools such as BitLocker or VeraCrypt to encrypt the boot partition and monitor its integrity using tools such as Windows Defender System Guard or Linux Integrity Measurement Architecture.

Customize Secure Boot policy
As an advanced mitigation, customize the Secure Boot policy by adding DBX records to revoke trust in vulnerable boot loaders on Windows endpoints or remove the Windows Production CA certificate from Linux endpoints.

For more details on these mitigation steps, please refer to the BlackLotus Mitigation Guide. The guide also provides some indicators of compromise and detection methods for BlackLotus.


« Pixilio The Ultimate AI Image Generator: Lifetime Subscription $39.99 · NSA Issues a Black Lotus Mitigation Guide · NZXT H9 Flow Review – Look at the Glass on that and more @ NT Compatible »




Comments
comments powered by Disqus

MajorGeeks.Com » News » June 2023 » NSA Issues a Black Lotus Mitigation Guide

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition