dma-attack-techniques
GitHub分析PCIe DMA攻击技术、内存获取及IOMMU防御,识别内存发起者与隔离边界。适用于涉及设备边界或内核安全的场景,辅助威胁建模、取证检测与防御验证。
Trigger Scenarios
Install
npx skills add gmh5225/awesome-game-security --skill dma-attack-techniques -g -y
SKILL.md
Frontmatter
{
"name": "dma-attack-techniques",
"description": "Analyze PCIe DMA threats, host-mediated memory acquisition, FPGA behavior, and IOMMU defenses. Use when the memory initiator or device boundary matters; use kernel security for host-only mechanisms."
}
DMA attack techniques
Identify the memory initiator, transport, required privilege, isolation boundary, and observable artifacts before classifying a technique as DMA.
Topic routing
- Classification and threat model for acquisition-path distinctions and attacker prerequisites.
- PCIe devices for TLPs, configuration space, programmable endpoints, and emulation limits.
- IOMMU and defense for VT-d/AMD-Vi, ACS, ATS/PASID, domain assignment, hypervisors, and trust anchors.
- IOMMU state verification for separating ACPI advertisement, Windows policy, live unit state, and per-requester coverage.
- Detection and forensics for defensive PCIe inventory, signal correlation, evidence capture, Thunderbolt/USB4, and memory access.
- Acquisition and transport, assurance boundaries, and repository resources for focused evidence and source selection.
- Repository map when maintaining the collection.
Use windows-kernel-security for host driver and kernel internals. Apply game-security-research-rigor before turning architecture claims into findings.
Version History
-
44719c6
Current 2026-09-27 15:08
更新DMA检测与IOMMU验证相关文档,强化对Thunderbolt/USB4指纹识别及设备模拟限制的说明。
-
4a52192
2026-09-22 04:11
优化技能结构以适配GPT-6 Astra,修正过时的安全声明,恢复直接数据源并强化游戏安全技能的证据引用。
-
51e379d
2026-07-31 02:58
澄清了FPGA设计的行为及TLP格式中流量类型的影响
-
c7ff340
2026-07-19 14:07
优化了Wiki结构并增强了自动化功能。
- f65b5b3 2026-07-05 12:04


