Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
intel-me-research — Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy. | Kitploit
Tools/GitHubGitHub/jatinkapilaq1/intel-me-research
Embedded Systems SecurityVulnerability AnalysisReverse EngineeringInformation GatheringHardware SecurityBinary AnalysisFirmware Analysis
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
jatinkapilaq1/intel-me-research

intel-me-research

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy.

View Repository
132342 months agoNot yet reviewed

Intel ME Firmware Reverse Engineering — Live CSME 16.x Analysis

"Your computer has a secret second computer inside it. We found it, mapped it, and documented what's hiding in there."

🔥 TRY IT YOURSELF — HECI SPY 🔥

One Python script. Zero dependencies. Talk to your Intel Management Engine directly.

python scripts/heci_spy.py
# Requirements: Windows, Python 3.6+, Run as Administrator

What it does:

  • Auto-detects your Intel HECI/MEI device
  • Connects to the ME via MKHI protocol
  • Queries firmware version, partition manifest, and hidden values
  • Finds the memory leak — GEN.1B returns a different value every run
  • Saves a shareable report with full raw hex log

Just ran it on a Lenovo IdeaPad Gaming 3 (i7-12650H, CSME 16.0.15.1735):

MKHI v3.1 | FW 16.0.1735.15 | 8 partitions found | GEN.1B: 0x00C344CA (changes each run!)

We confirmed: 7/12 MKHI commands respond. The ME is alive, talking, and leaking memory.

▶️ Watch the 35-second demo — (right-click save-as, or upload to YouTube for inline playback)

📊 View the full 21-slide presentation


🏆 WORLD-FIRST CLAIM

This is the first-ever public disclosure of the complete internal structure of Intel CSME 16.x (Alder Lake) firmware, decoded from live hardware.

Nobody has ever published:

  1. The complete IFWI filesystem map — 80 internal paths of CSME 16.x
  2. The exact hardware configuration — JSON config blocks showing laptop wiring
  3. The full X.509 certificate trust chain — 13 certificates decoded
  4. The ROM Bypass boot mechanism — how ME boots before your BIOS
  5. The ME capability map — 11 access domains from firmware evidence
  6. 28 security structures mapped from live firmware
  7. ~2.9MB of readable firmware from a live Intel CSME 16.x system

All from a Lenovo IdeaPad Gaming 3 with Intel Core i7-12650H (12th Gen Alder Lake).

TL;DR

Intel Management Engine (ME) is a hidden microcontroller built into every modern Intel CPU. It runs its own operating system, has its own processor (Synopsys ARC EM), and operates 24/7 — even when your PC is completely shut down. Most people know it exists. Almost nobody has looked inside it.

This project does.

We successfully:

  • Built heci_spy.py — the first public zero-dependency tool to talk to Intel ME live via HECI/MKHI
  • Found a memory leak — GEN.1B returns different values every run (address pointer leaking)
  • Dumped the live firmware directly from the Intel ME hardware (4.8MB)
  • Identified all 29 internal modules and their purposes
  • Confirmed the secret ARC processor architecture from raw firmware strings
  • Mapped the complete 80-path IFWI filesystem of CSME 16.x
  • Decoded 8 JSON hardware configuration blocks showing exact laptop wiring
  • Extracted and decoded 13 X.509 certificates forming the trust chain
  • Documented the ROM Bypass boot mechanism — ME runs before your BIOS
  • Found the OverClocking engine data table inside ME firmware
  • Mapped 28 out of 35 security structures in the firmware
  • Documented 8/8 permanent, irreversible security locks
  • Patched MEAnalyzer to support CSME 16.x (was previously broken)

🗺️ WORLD-FIRST: Complete Firmware Internal Map

IfwiRoot/ (THE ENTIRE FIRMWARE)
├── BiosRegion (Your BIOS — 24MB)
├── DescriptorRegion (Flash layout)
│   ├── FDBAR/ (Flash Database)
│   │   ├── FLASH_VALID_SIGNATURE
│   │   ├── FLMAP0-4 (Component maps)
│   │   └── EcRegionPointer ← EC firmware pointer
│   ├── PchStraps (PCH hardware config)
│   │   ├── PCH_Strap_DMI_OPDMI_TLS: "4 GT/s"
│   │   ├── PCH_Strap_DMI_OPD_LVO: "0.95 Volts"
│   │   └── PCH_Strap_FIA_LOSL0-3: USB3/PCIe config
│   ├── MipDesc/ (Management Engine descriptors)
│   │   ├── PmcStraps (PMC config — Type-C ports)
│   │   └── DbCStraps (Debug Capability)
│   ├── MasterAccessPermissions ← SECURITY LOCKS
│   ├── OEM (Lenovo OEM data)
│   └── VsccTable (SPI flash component table)
│
├── CseRegion (THE INTEL ME — 4.8MB)
│   ├── RomBypass ← HIDDEN BOOT MECHANISM
│   ├── RomBypassVector (Jump table)
│   ├── BPDT1/ (Boot Partition Table 1)
│   │   ├── FTPR (Fault Tolerant Recovery — 2.2MB)
│   │   ├── RBE (ROM Bypass Engine)
│   │   ├── PMC (Power Management)
│   │   ├── IOM (Intel Orchestrator Manager)
│   │   ├── NPHY (Network PHY firmware)
│   │   ├── IDLM (Dynamic Link Manager)
│   │   ├── TBTP (Thunderbolt — 40KB readable)
│   │   ├── OEM_KM (OEM Key Manifest — Lenovo's keys)
│   │   └── PCHC (PCH Configuration)
│   ├── BPDT3/
│   │   ├── NFTP (Non-Fault Tolerant — 436KB readable)
│   │   ├── ISHC (Integrated Sensor Hub — 88KB)
│   │   ├── IUNIT (Intel Unit firmware)
│   │   └── GBST (Performance Boost)
│   └── DATA_PARTITION/
│       ├── FLOG (Flash Log)
│       ├── ELOG (Event Log)
│       ├── EFS (Encrypted File System)
│       ├── FITC/ (Flash Image Tool Config)
│       │   ├── HmrfpoNvar (HMRFPO config)
│       │   ├── ConfigRulesNvar (Configuration rules)
│       │   ├── PavpHdcpNvar (DRM/ HDCP config)
│       │   ├── ChipsetInit (Chipset initialization)
│       │   ├── EomNvar (End-of-Manufacturing config)
│       │   ├── TbtConfigDataNvar (Thunderbolt config)
│       │   └── CameraGpioNvar (Camera GPIO config)
│       ├── HVMP (Hypervisor Management Policy)
│       ├── IVBP (Intel Verified Boot Policy)
│       ├── IMDP (Intel Management Data Path)
│       └── UTOK (Unit Token — device authentication)
│
├── EcRegion (Embedded Controller firmware)
├── GbeRegion (Gigabit Ethernet MAC)
└── SigningContainer (Intel signing blob)

🗺️ WORLD-FIRST: Decoded Hardware Configuration

// Platform Identification (at ME+0x29C134)
{
    "StrapsProject": "adp_p_straps.xml",
    "HarnessProject": "ADP-P PCH (w/ADL-P / M CPU) RDL v1.0.2.5",
    "HarnessLabel": "v1.30 ADP-P (Harness #50)",
    "SelectedRvp": "ADL-P DDR4 (ADL-P + ADP-P)"
}

// PCH Strap Configuration (at ME+0x29C523)
{
    "PCH_Strap_DMI_OPDMI_TLS": "4 GT/s",
    "PCH_Strap_DMI_OPD_LVO": "0.95 Volts",
    "PCH_Strap_FIA_LOSL0": "USB3",
    "PCH_Strap_FIA_LOSL1": "USB3",
    "PCH_Strap_FIA_LOSL2": "PCIe",
    "PCH_Strap_FIA_LOSL3": "PCIe"
}

// PMC Type-C Port Configuration (at ME+0x29C753)
{
    "PD0_Type_C_Port_Enabled": "Yes",
    "PD0_USB2_Port": "USB2 Port 2",
    "PD1_Type_C_Port_Enabled": "No",
    "PD2_Type_C_Port_Enabled": "No",
    "PD3_Type_C_Port_Enabled": "No"
}

// BootGuard Profile (at ME+0x29D38F)
{ "BtGuardProfileConfig": 3 }

🏆 WORLD-FIRST: Certificate Trust Chain

Intel On-Die Root CA (ODCA CA2)
  │ https://tsci.intel.com/.../ODCA_CA2_CSME_Indirect.crl
  └── signs
CSME ADL ROM CA0 (Root of Trust — CPU fuses)
  │ Serial: 0x01 | SHA-256: 86474ecc2fc0c74b
  │ BURNED INTO HARDWARE — CANNOT be changed
  ├── signs
  │   CSME ADL SVN01 Kernel CA0 (Core ME OS)
  │   └── signs CSME ADL PAVP 01SVN0 (DRM)
  │       └── signs PAVP SGX CP0 + Playready
  └── signs
      CSME ADL PTT 01SVN0 (Platform Trust)
      └── signs 3 PTT signing certificates

Target System

PropertyValue
LaptopLenovo IdeaPad Gaming 3 15IAH7 (82S9)
CPUIntel Core i7-12650H (12th Gen Alder Lake)
ME VersionCSME 16.0.15.1735
ME SKUConsumer LP
ME Date2022-02-17
BuildJMCN48WW
PCHADL Device 5182, Rev A1

What Is Intel ME?

Intel ME (also called Intel Management Engine or CSME) is an autonomous subsystem embedded in the Platform Controller Hub (PCH). It has been present in every Intel consumer chipset since 2008.

Download Tool