Advisor
Wiki Threats & Attacks Physical & Hybrid Attacks Evil Maid Attacks

Evil Maid Attacks

1 min read
Jump to:

Summary

Evil Maid Attacks are a type of physical security threat where an attacker gains unauthorized access to a device, typically a laptop or encrypted system, by tampering with it while the owner is away. This attack often involves installing malicious hardware or software to capture sensitive information such as encryption keys or passwords, compromising the device’s security without the user’s knowledge.

Key Characteristics

  • Requires physical access to the target device, usually when the owner is absent.
  • Commonly targets encrypted systems to extract cryptographic keys or credentials.
  • May involve installing keyloggers, bootkits, or modifying firmware.
  • Often undetectable by the user until the compromise is discovered.
  • Exploits weaknesses in physical security and device tamper resistance.

Defensive Controls

  • Use full disk encryption with strong authentication mechanisms.
  • Implement tamper-evident seals or cases to detect physical intrusion.
  • Enable secure boot and firmware integrity checks.
  • Store sensitive devices in secure locations when unattended.
  • Regularly audit and verify device integrity and firmware authenticity.

Related Security Solutions

Solutions such as Trusted Platform Modules (TPM), hardware security modules (HSM), secure boot processes, and endpoint detection and response (EDR) tools help mitigate Evil Maid Attacks by enhancing device integrity and detecting unauthorized modifications. Physical security measures and encryption software also play critical roles in defending against these attacks.

Tags: Application Attacks encryption endpoint security Evil Maid Attacks physical security secure boot Threats & Attacks TPM