{"id":38148,"date":"2020-11-12T17:00:33","date_gmt":"2020-11-12T17:00:33","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=92175"},"modified":"2020-11-12T17:00:33","modified_gmt":"2020-11-12T17:00:33","slug":"system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/","title":{"rendered":"System Management Mode deep dive: How SMM isolation hardens the platform"},"content":{"rendered":"<p>Ensuring that the platform firmware is healthy and trustworthy is fundamental to guaranteeing that powerful platform security features like Hypervisor-protected code integrity (HVCI) and Windows Defender Credential Guard are functioning as expected. Windows 10 achieves this by leveraging a hardware-based root of trust that ensures unauthorized code like Unified Extensible Firmware Interface (UEFI) malware cannot take root before the Windows bootloader launches.<\/p>\n<p>Key to defending the hypervisor, and by extension the rest of the OS, from such low-level threats is protecting System Management Mode (SMM), an execution mode in x86-based processors that runs at a higher effective privilege than the hypervisor. Because of its traditionally unfettered access to memory and device resources, SMM is a known vector of attack for gaining access to the OS and hardware. SMM is particularly vulnerable to threats like <a href=\"https:\/\/edk2-docs.gitbook.io\/security-advisory\/sw-smi-confused-deputy-smramsavestate_c\">confused deputy attacks<\/a>, in which malicious code tricks another code with higher privileges to perform certain activities. One could have perfect code in SMM and still be affected by behavior like trampolining into secure kernel code.<\/p>\n<p>Sometimes referred to as \u201cRing -2\u201d, SMM is used by OEMs to interact with hardware like NV RAM, emulate hardware functionality, handle hardware interrupts or errata, and perform other functions. SMM runs in the form of interrupt handlers that are triggered by timers or access to certain memory, registers, or hardware resources. OEM drivers and runtime firmware services may explicitly trap SMM to control certain hardware functionality.<\/p>\n<p>To stop sophisticated attacks from taking control of the system through SMM, the OS must have enforcement or oversight of SMM\u2019s behavior. As part of Secured-core PCs and System Guard, Intel and AMD have developed mechanisms to isolate SMM from the OS by enforcing and reporting what resources SMM has access to.<\/p>\n<h2>SMM isolation<\/h2>\n<p>Isolating SMM is implemented in three parts: OEMs implement a policy that states what they require access to; the chip vendor enforces this policy on SMIs; and the chip vendor reports compliance to this policy to the OS.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-92176\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-1.png\" alt=\"Diagram showing process of isolation in System Management Mode\" width=\"900\" height=\"277\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-1.png 900w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-1-300x92.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-1-768x236.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\"><\/p>\n<p>The policy provided by the OEM is a list detailing the resources that the SMI handlers require access to. This policy is validated and enforced by the chipset vendors\u2019 specific enforcement mechanism detailed later. The OS does not have any control over what the policy is; it is only guaranteed enforcement of the policy stated.<\/p>\n<p>Trusted Computing Base (Tcb) Launch, introduced in the Windows implementation of Dynamic Root of Trust (DRTM), gets the enforced policy from the chip vendor\u2019s reporting mechanism. Because resource access is specific to a platform\u2019s needs, Tcb Launch compares the OEM\u2019s SMM access policy with several levels of Windows SMM isolation requirements to determine the level of isolation provided. The isolation level achieved by the OEM\u2019s policy is measured for attestation and is reported to the OS.<\/p>\n<p>The isolation levels consist of increasing restrictions on what SMIs may access, as well as enforcement capabilities required on the system. An example of an isolation requirement is that SMIs may not access memory owned by the OS. Additionally, these requirements can include restrictions on the following resources:<\/p>\n<ol>\n<li>SMM page configuration lockdown<\/li>\n<li>Static page tables<\/li>\n<li>Model-Specific Register (MSR) access<\/li>\n<li>IO port access<\/li>\n<li>Processor state save access<\/li>\n<\/ol>\n<p>In order to ensure a consistent security promise for customers using Secured-core PCs if the &nbsp;minimum requirements are not met, the DRTM measurements are capped, and local and remote attestation fail. SMM isolation is tied with DRTM because without DRTM, the OS cannot trust anything evaluated by the boot environment as it is not protected from the influence of SMM. SMIs are suspended during DRTM, so the new root of trust established by DRTM can evaluate the security of the SMM access policy.<\/p>\n<p>Not only are these protections utilized by Windows for local secrets protection, but remote attestation tools can also leverage this information to determine the security posture of a specific device. This attestation report can be used to prevent access to sensitive network files, for example, unless a certain combination of features is present.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-92184\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-2a.png\" alt=\"Diagram showing SMM architecture\" width=\"1162\" height=\"396\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-2a.png 1162w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-2a-300x102.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-2a-1024x349.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/SMM-2a-768x262.png 768w\" sizes=\"auto, (max-width: 1162px) 100vw, 1162px\"><\/p>\n<h2>AMD solution (SMM Supervisor)<\/h2>\n<p>During UEFI boot phase, the SMM Supervisor is loaded as a UEFI driver. This driver is signed by AMD and authenticated by the Platform Security Processor (PSP) at the time of DRTM launch. Failure of authentication will fail DRTM. (It is also under firmware anti-rollback protection by PSP.)<\/p>\n<p>SMM Supervisor provides and initializes the SMI entry routine (the first code block executed after SMI is triggered). This routine is also signed by AMD and authenticated by PSP at the time of DRTM launch. Upon DRTM event, PSP also verifies that the SMI entry is properly configured to this authenticated block. Failure of this authentication will also result in DRTM failure.<\/p>\n<p>SMM Supervisor marks critical pages\u2014including SMM Supervisor code block, internal data, the page table itself, exception handler, as well as processor save state\u2014as supervisor pages, accessible only&nbsp; from current privilege level 0 (CPL0, the most privileged level).<\/p>\n<p>Immediately after SMI is triggered, the SMI entry routine demotes the system to execute under CPL3 (least privileged level) before executing any third party SMI handlers. From CPL3 environment, MSR, IO, and supervisor pages access, critical register changes such as CR3, as well as privileged instructions such as \u201chlt\u201d and \u201ccli\u201d all end up as General Protection Fault enforced by CPU hardware.<\/p>\n<p>In order for SMI handlers under CPL3 to access privileged data and register, SMM Supervisor provides syscall interface to allow third-party SMI handlers to make such requests. The backend of the syscall interface, which resides in SMM supervisor, is controlled by SMM secure policy. The said policy is a deny list that can be customized per platform to determine which MSRs, IOs, or memory regions can be accessed from CPL3. SMM secure policy is reported to and verified by OS secure loader during DRTM event.<\/p>\n<h2>Intel Hardware Shield<\/h2>\n<p>Intel\u00ae Hardware Shield, a part of the Intel vPro\u00ae platform, uses CPU hardware and firmware to enforce the platform\u2019s SMM access policy. Generationally, these capabilities evolve using new CPU hardware features in conjunction with existing CPU capabilities to strengthen related micro-architectural flows and provide new register locks in support of related firmware hardening<sup>*<\/sup>.<\/p>\n<ul>\n<li>Intel vPro\u00ae platform with 8<sup>th<\/sup> Generation Intel\u00ae Core\u2122 vPro\u00ae processors introduced firmware hardening and hardware-locked static page table support to reduce SMM privilege with regard to memory and to lock the memory configuration. These new locks include: CR3 lock, MSEG lock, SMBASE lock, etc.<\/li>\n<li>Intel vPro platform with 9<sup>th<\/sup> Generation Intel Core vPro processors added an Intel signed SMM module enables attestation of the SMM memory configuration using Intel\u00ae Trusted Execution Technology (Intel\u00ae TXT), a component of Intel\u00ae Hardware Shield, via PCR17. The module first verifies the integrity of the hardened SMM code used to enforce the SMM access policy. It then reports this, as well as the details of the policy, back to the OS. Therefore, the OS can verify the trustworthiness of SMM and evaluate the platform\u2019s SMM access policy without the possibility of interference from SMI handlers.<\/li>\n<li>Intel vPro platform with 10<sup>th<\/sup> Generation Intel Core vPro processors enhanced the verified CPL0 SMM components to create a privilege separation with SMI handlers in order to extend policy enforcement to MSRs, IO ports, and SMM state save (access policy may vary by platform). The reporting mechanism was extended to include these capabilities as well.<\/li>\n<\/ul>\n<p><span>*<\/span>No product or component can be absolutely secure.<\/p>\n<h2>Secured-core PCs give the simplest experience for customers to get Secure Launch and SMM protection<\/h2>\n<p>Enabling SMM protection and System Guard Secure Launch may be achieved when the following support is present:<\/p>\n<ul>\n<li>Intel, AMD, or ARM virtualization extensions<\/li>\n<li>Trusted Platform Module (TPM) 2.0<\/li>\n<li>On Intel: TXT support in the BIOS<\/li>\n<li>On AMD: SKINIT package must be integrated in the Windows system image<\/li>\n<li>On Qualcomm: Implements DRTM TrustZone application and supports SMC memory protections.<\/li>\n<li>Kernel DMA Protection (<a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/information-protection\/kernel-dma-protection-for-thunderbolt\">learn more<\/a>)<\/li>\n<\/ul>\n<p>Further configuration information and requirements can be found <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-system-guard\/system-guard-how-hardware-based-root-of-trust-helps-protect-windows\">here<\/a>.On <a href=\"https:\/\/www.microsoft.com\/en-us\/windowsforbusiness\/windows10-secured-core-computers?SilentAuth=1\">Secured-core PCs<\/a>, virtualization-based security is supported, and hardware-backed security features like System Guard Secure Launch with SMM Protections are enabled by default. Customers do not need to worry about&nbsp; configuring the necessary functionality as Secured-core PCs come with the right configurations from OEMs, thereby providing the simplest path to the most secure Windows 10 systems. <a href=\"https:\/\/www.microsoft.com\/en-us\/windowsforbusiness\/windows10-secured-core-computers#:~:text=Secured-core%20PCs%20are%20the%20most%20secure%20Windows%2010,with%20integrated%20hardware%2C%20firmware%2C%20software%2C%20and%20identity%20protection.\">Learn more<\/a> about the line of Secured-core PCs available today.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/11\/12\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Key to defending the hypervisor, and by extension the rest of the OS, from low-level threats is protecting System Management Mode (SMM), an execution mode in x86-based processors that runs at a higher effective privilege than the hypervisor.<br \/>\nThe post System Management Mode deep dive: How SMM isolation hardens the platform appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":38149,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,8508,9037,9038,9039,5326,357],"class_list":["post-38148","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-hypervisor-protected-code-integrity-hvci","tag-smm","tag-smm-isolation","tag-system-management-mode","tag-uefi","tag-windows"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>System Management Mode deep dive: How SMM isolation hardens the platform 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"System Management Mode deep dive: How SMM isolation hardens the platform 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-12T17:00:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"277\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"System Management Mode deep dive: How SMM isolation hardens the platform\",\"datePublished\":\"2020-11-12T17:00:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/\"},\"wordCount\":1395,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png\",\"keywords\":[\"Cybersecurity\",\"hypervisor-protected code integrity (HVCI)\",\"SMM\",\"SMM isolation\",\"System Management Mode\",\"UEFI\",\"Windows\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/\",\"name\":\"System Management Mode deep dive: How SMM isolation hardens the platform 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png\",\"datePublished\":\"2020-11-12T17:00:33+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png\",\"width\":900,\"height\":277},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"System Management Mode deep dive: How SMM isolation hardens the platform\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"System Management Mode deep dive: How SMM isolation hardens the platform 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/","og_locale":"en_US","og_type":"article","og_title":"System Management Mode deep dive: How SMM isolation hardens the platform 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-11-12T17:00:33+00:00","og_image":[{"width":900,"height":277,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"System Management Mode deep dive: How SMM isolation hardens the platform","datePublished":"2020-11-12T17:00:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/"},"wordCount":1395,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png","keywords":["Cybersecurity","hypervisor-protected code integrity (HVCI)","SMM","SMM isolation","System Management Mode","UEFI","Windows"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/","url":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/","name":"System Management Mode deep dive: How SMM isolation hardens the platform 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png","datePublished":"2020-11-12T17:00:33+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform.png","width":900,"height":277},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"System Management Mode deep dive: How SMM isolation hardens the platform"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/38148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=38148"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/38148\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/38149"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=38148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=38148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=38148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}