
Habla directamente con tu Intel Management Engine — herramienta Python sin dependencias. Detecta fugas de memoria, manifiesto de partición, sondeo de MKHI en vivo. Primer HECI Spy público.
"Tu ordenador tiene un segundo ordenador secreto en su interior. Lo encontramos, lo mapeamos y documentamos lo que se esconde ahí dentro."
Un script de Python. Cero dependencias. Habla directamente con tu Intel Management Engine.
python scripts/heci_spy.py
# Requirements: Windows, Python 3.6+, Run as Administrator
Qué hace:
Lo acabamos de ejecutar en un Lenovo IdeaPad Gaming 3 (i7-12650H, CSME 16.0.15.1735):
MKHI v3.1 | FW 16.0.1735.15 | 8 partitions found | GEN.1B: 0x00C344CA (changes each run!)
Lo confirmamos: 7/12 comandos MKHI responden. El ME está vivo, hablando y filtrando memoria.
▶️ Ver la demo de 35 segundos — (clic derecho y guardar como, o súbelo a YouTube para reproducirlo en línea)
📊 Ver la presentación completa de 21 diapositivas
Esta es la primera divulgación pública de la estructura interna completa del firmware de Intel CSME 16.x (Alder Lake), decodificada desde hardware real en vivo.
Nadie ha publicado nunca:
Todo desde un Lenovo IdeaPad Gaming 3 con Intel Core i7-12650H (12.ª Gen Alder Lake).
Intel Management Engine (ME) es un microcontrolador oculto integrado en cada CPU moderna de Intel. Ejecuta su propio sistema operativo, tiene su propio procesador (Synopsys ARC EM) y funciona 24/7 — incluso cuando tu PC está completamente apagado. La mayoría de la gente sabe que existe. Casi nadie ha mirado en su interior.
Este proyecto lo hace.
Conseguimos con éxito:
IfwiRoot/ (THE ENTIRE FIRMWARE)
├── BiosRegion (Your BIOS — 24MB)
├── DescriptorRegion (Flash layout)
│ ├── FDBAR/ (Flash Database)
│ │ ├── FLASH_VALID_SIGNATURE
│ │ ├── FLMAP0-4 (Component maps)
│ │ └── EcRegionPointer ← EC firmware pointer
│ ├── PchStraps (PCH hardware config)
│ │ ├── PCH_Strap_DMI_OPDMI_TLS: "4 GT/s"
│ │ ├── PCH_Strap_DMI_OPD_LVO: "0.95 Volts"
│ │ └── PCH_Strap_FIA_LOSL0-3: USB3/PCIe config
│ ├── MipDesc/ (Management Engine descriptors)
│ │ ├── PmcStraps (PMC config — Type-C ports)
│ │ └── DbCStraps (Debug Capability)
│ ├── MasterAccessPermissions ← SECURITY LOCKS
│ ├── OEM (Lenovo OEM data)
│ └── VsccTable (SPI flash component table)
│
├── CseRegion (THE INTEL ME — 4.8MB)
│ ├── RomBypass ← HIDDEN BOOT MECHANISM
│ ├── RomBypassVector (Jump table)
│ ├── BPDT1/ (Boot Partition Table 1)
│ │ ├── FTPR (Fault Tolerant Recovery — 2.2MB)
│ │ ├── RBE (ROM Bypass Engine)
│ │ ├── PMC (Power Management)
│ │ ├── IOM (Intel Orchestrator Manager)
│ │ ├── NPHY (Network PHY firmware)
│ │ ├── IDLM (Dynamic Link Manager)
│ │ ├── TBTP (Thunderbolt — 40KB readable)
│ │ ├── OEM_KM (OEM Key Manifest — Lenovo's keys)
│ │ └── PCHC (PCH Configuration)
│ ├── BPDT3/
│ │ ├── NFTP (Non-Fault Tolerant — 436KB readable)
│ │ ├── ISHC (Integrated Sensor Hub — 88KB)
│ │ ├── IUNIT (Intel Unit firmware)
│ │ └── GBST (Performance Boost)
│ └── DATA_PARTITION/
│ ├── FLOG (Flash Log)
│ ├── ELOG (Event Log)
│ ├── EFS (Encrypted File System)
│ ├── FITC/ (Flash Image Tool Config)
│ │ ├── HmrfpoNvar (HMRFPO config)
│ │ ├── ConfigRulesNvar (Configuration rules)
│ │ ├── PavpHdcpNvar (DRM/ HDCP config)
│ │ ├── ChipsetInit (Chipset initialization)
│ │ ├── EomNvar (End-of-Manufacturing config)
│ │ ├── TbtConfigDataNvar (Thunderbolt config)
│ │ └── CameraGpioNvar (Camera GPIO config)
│ ├── HVMP (Hypervisor Management Policy)
│ ├── IVBP (Intel Verified Boot Policy)
│ ├── IMDP (Intel Management Data Path)
│ └── UTOK (Unit Token — device authentication)
│
├── EcRegion (Embedded Controller firmware)
├── GbeRegion (Gigabit Ethernet MAC)
└── SigningContainer (Intel signing blob)
// Platform Identification (at ME+0x29C134)
{
"StrapsProject": "adp_p_straps.xml",
"HarnessProject": "ADP-P PCH (w/ADL-P / M CPU) RDL v1.0.2.5",
"HarnessLabel": "v1.30 ADP-P (Harness #50)",
"SelectedRvp": "ADL-P DDR4 (ADL-P + ADP-P)"
}
// PCH Strap Configuration (at ME+0x29C523)
{
"PCH_Strap_DMI_OPDMI_TLS": "4 GT/s",
"PCH_Strap_DMI_OPD_LVO": "0.95 Volts",
"PCH_Strap_FIA_LOSL0": "USB3",
"PCH_Strap_FIA_LOSL1": "USB3",
"PCH_Strap_FIA_LOSL2": "PCIe",
"PCH_Strap_FIA_LOSL3": "PCIe"
}
// PMC Type-C Port Configuration (at ME+0x29C753)
{
"PD0_Type_C_Port_Enabled": "Yes",
"PD0_USB2_Port": "USB2 Port 2",
"PD1_Type_C_Port_Enabled": "No",
"PD2_Type_C_Port_Enabled": "No",
"PD3_Type_C_Port_Enabled": "No"
}
// BootGuard Profile (at ME+0x29D38F)
{ "BtGuardProfileConfig": 3 }
Intel On-Die Root CA (ODCA CA2)
│ https://tsci.intel.com/.../ODCA_CA2_CSME_Indirect.crl
└── signs
CSME ADL ROM CA0 (Root of Trust — CPU fuses)
│ Serial: 0x01 | SHA-256: 86474ecc2fc0c74b
│ BURNED INTO HARDWARE — CANNOT be changed
├── signs
│ CSME ADL SVN01 Kernel CA0 (Core ME OS)
│ └── signs CSME ADL PAVP 01SVN0 (DRM)
│ └── signs PAVP SGX CP0 + Playready
└── signs
CSME ADL PTT 01SVN0 (Platform Trust)
└── signs 3 PTT signing certificates