Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Geek your mind, the rest will follow.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » June 2023 » NSA Issues a Black Lotus Mitigation Guide

NSA Issues a Black Lotus Mitigation Guide


Posted by: Corporal Punishment on 06/24/2023 09:51 AM [ comments Comments ]


BlackLotus is malware software that exploits a boot loader flaw known as Baton Drop (CVE-2022-21894) to bypass Secure Boot and take control of the endpoint from the earliest phase of software boot. Microsoft has issued patches for supported versions of Windows, but according to the BlackLotus Mitigation Guide published this week by the NSA; more is needed to mitigate the threat fully.

According to the NSA, BlackLotus is not a firmware threat but a software threat that targets the boot partition. It uses Shim and GRUB, two components commonly used in Linux boot, to integrate its payload and implant itself into the endpoint. Once implanted, BlackLotus can strip the Secure Boot policy and prevent its enforcement. This means that attackers can replace fully patched boot loaders with vulnerable versions to execute BlackLotus.

Here are some of the steps suggested by the NSA:

Update recovery media and activate optional mitigations
Create updated recovery media for each endpoint and enable optional mitigations such as Credential Guard, Device Guard, and Secure Launch.

Harden user executable policies
Configure user executable policies such as AppLocker or Windows Defender Application Control to prevent unauthorized executables from running on the endpoint.

Monitor boot partition integrity
Use tools such as BitLocker or VeraCrypt to encrypt the boot partition and monitor its integrity using tools such as Windows Defender System Guard or Linux Integrity Measurement Architecture.

Customize Secure Boot policy
As an advanced mitigation, customize the Secure Boot policy by adding DBX records to revoke trust in vulnerable boot loaders on Windows endpoints or remove the Windows Production CA certificate from Linux endpoints.

For more details on these mitigation steps, please refer to the BlackLotus Mitigation Guide. The guide also provides some indicators of compromise and detection methods for BlackLotus.


« Pixilio The Ultimate AI Image Generator: Lifetime Subscription $39.99 · NSA Issues a Black Lotus Mitigation Guide · NZXT H9 Flow Review – Look at the Glass on that and more @ NT Compatible »




Comments
comments powered by Disqus

MajorGeeks.Com » News » June 2023 » NSA Issues a Black Lotus Mitigation Guide

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition