DMA attack techniques
Identify the memory initiator, transport, required privilege, isolation boundary, and observable artifacts before classifying a technique as DMA.
Topic routing
- Classification and threat model for acquisition-path distinctions and attacker prerequisites.
- PCIe devices for TLPs, configuration space, FPGA constraints, pcileech, and device emulation.
- IOMMU and defense for VT-d/AMD-Vi, ACS, ATS/PASID, domain assignment, hypervisors, and trust anchors.
- Detection and forensics for fingerprinting, evidence capture, Thunderbolt/USB4, and memory access.
- Acquisition and transport, assurance boundaries, and repository resources for focused evidence and source selection.
- Repository map when maintaining the collection.
Use windows-kernel-security for host driver and kernel internals. Apply game-security-research-rigor before turning architecture claims into findings.