Your browser does not fully support modern features. Please upgrade for a smoother experience.
Submitted Successfully!
Thank you for your contribution! You can also upload a video entry or images related to this topic. For video creation, please contact our Academic Video Service.
Version Summary Created by Modification Content Size Created at Operation
1 handwiki Rita Xu -- 4459 2022-10-31 01:34:29

Video Upload Options

We provide professional Academic Video Service to translate complex research into visually appealing presentations. Would you like to try it?
Cite
If you have any further questions, please contact Encyclopedia Editorial Office.
HandWiki. Intel Active Management Technology. Encyclopedia. Available online: https://encyclopedia.pub/entry/32068 (accessed on 22 September 2026).
HandWiki. Intel Active Management Technology. Encyclopedia. Available at: https://encyclopedia.pub/entry/32068. Accessed September 22, 2026.
HandWiki. "Intel Active Management Technology" Encyclopedia, https://encyclopedia.pub/entry/32068 (accessed September 22, 2026).
HandWiki. (2022, October 31). Intel Active Management Technology. In Encyclopedia. https://encyclopedia.pub/entry/32068
HandWiki. "Intel Active Management Technology." Encyclopedia. Web. 31 October, 2022.
Intel Active Management Technology
Edit

Intel Active Management Technology (AMT) is hardware and firmware for remote out-of-band management of select business computers, running on the Intel Management Engine, a microprocessor subsystem not exposed to the user, in order to monitor, maintain, update, upgrade and repair them. Out-of-band (OOB) or hardware-based management is different from software-based (or in-band) management and software management agents. Hardware-based management works at a different level from software applications, and uses a communication channel (through the TCP/IP stack) that is different from software-based communication (which is through the software stack in the operating system). Hardware-based management does not depend on the presence of an OS or locally installed management agent. Hardware-based management has been available on Intel/AMD based computers in the past, but it has largely been limited to auto-configuration using DHCP or BOOTP for dynamic IP address allocation and diskless workstations, as well as wake-on-LAN (WOL) for remotely powering on systems. AMT is not intended to be used by itself; it is intended to be used with a software management application. It gives a management application (and thus, the system administrator who uses it) access to the PC down the wire, in order to remotely do tasks that are difficult or sometimes impossible when working on a PC that does not have remote functionalities built into it. AMT is designed into a service processor located on the motherboard, and uses TLS-secured communication and strong encryption to provide additional security. AMT is built into PCs with Intel vPro technology and is based on the Intel Management Engine (ME). AMT has moved towards increasing support for DMTF Desktop and mobile Architecture for System Hardware (DASH) standards and AMT Release 5.1 and later releases are an implementation of DASH version 1.0/1.1 standards for out-of-band management. AMT provides similar functionality to IPMI, although AMT is designed for client computing systems as compared with the typically server-based IPMI. Currently, AMT is available in desktops, servers, ultrabooks, tablets, and laptops with Intel Core vPro processor family, including Intel Core i5, Core i7, Core i9 and Intel Xeon E3-1000, Xeon E, Xeon W-1000 product family. Intel confirmed a Remote Elevation of Privilege bug (CVE-2017-5689, SA-00075) in its Management Technology on May 1, 2017. Every Intel platform with either Intel Standard Manageability, Active Management Technology, or Small Business Technology, from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME. Some manufacturers, like Purism and System76 are already selling hardware with Intel Management Engine disabled to prevent the remote exploit. Additional major security flaws in the ME affecting a very large number of computers incorporating Management Engine, Trusted Execution Engine, and Server Platform Services firmware, from Skylake in 2015 to Coffee Lake in 2017, were confirmed by Intel on November 20, 2017 (SA-00086).

software management wake-on-lan manageability

References

  1. Garrison, Justin (March 28, 2011). "How to Remotely Control Your PC (Even When it Crashes)". http://www.howtogeek.com/56538/how-to-remotely-control-your-pc-even-when-it-crashes/. 
  2. "Open Manageability Developer Tool Kit | Intel® Software". https://software.intel.com/en-us/articles/download-the-latest-version-of-manageability-developer-tool-kit/. 
  3. "Revisiting vPro for Corporate Purchases". Gartner. http://mediaproducts.gartner.com/reprints/intel/153886.html. 
  4. "Intel Centrino 2 with vPro Technology and Intel Core2 Processor with vPro Technology". Intel. 2008. ftp://download.intel.com/products/vpro/whitepaper/crossclient.pdf. 
  5. "Architecture Guide: Intel Active Management Technology". Intel. June 26, 2008. http://softwarecommunity.intel.com/articles/eng/1032.htm. 
  6. "Intel Active Management Technology System Defense and Agent Presence Overview" (PDF). Intel. February 2007. https://software.intel.com/sites/default/files/82/9f/41003. 
  7. "Intel Centrino 2 with vPro Technology". Intel. http://softwarecommunity.intel.com/articles/eng/1477.htm. 
  8. "New Intel-Based Laptops Advance All Facets of Notebook PCs". Intel. http://www.intel.com/pressroom/archive/releases/20080715comp_sm.htm#story. 
  9. "Understanding Intel AMT over wired vs. wireless (video)". Intel. http://communities.intel.com/docs/DOC-1129. 
  10. "Intel® vPro™ Technology". Intel. http://www.intel.com/content/www/us/en/architecture-and-technology/vpro/vpro-technology-general.html. 
  11. "Part 3: Post Deployment of Intel vPro in an Altiris Environment: Enabling and Configuring Delayed Provisioning". Intel (forum). http://communities.intel.com/docs/DOC-1920. 
  12. "Archived copy". https://safefrontier.com/sites/default/files/pdf/ACTIVE%20MANAGEMENT%20CLOUD%20OVERVIEW.pdf. 
  13. "Intel Management and Security Status (IMSS), advanced configurations. Part 9 – Intel Software Network Blogs". http://software.intel.com/en-us/blogs/2009/07/17/intel-management-and-security-status-imss-advanced-configurations-part-9/. 
  14. "Intel vPro Provisioning". HP (Hewlett Packard). http://www.planet-lab.org/files/AMT.pdf. 
  15. "vPro Setup and Configuration for the dc7700 Business PC with Intel vPro Technology". HP (Hewlett Packard). http://www.icare.hp.com.cn/TechCenter_StaticArticle/37022/44474.pdf. 
  16. "Part 4: Post Deployment of Intel vPro in an Altiris Environment Intel: Partial UnProvDefault". Intel (forum). http://communities.intel.com/docs/DOC-1921. 
  17. "Intel Centrino 2 with vPro Technology". Intel. http://download.intel.com/products/centrino/pro/316888.pdf. 
  18. "Technical Considerations for Intel AMT in a Wireless Environment". Intel. September 27, 2007. https://software.intel.com/en-us/articles/technical-considerations-for-intel-amt-in-a-wireless-environment/. 
  19. "Intel Active Management Technology Setup and Configuration Service, Version 5.0" (PDF). Intel. https://www.notebookreparaturberlin.com. 
  20. "Intel AMT - Fast Call for Help". Intel. August 15, 2008. http://softwareblogs.intel.com/2008/08/18/intel-amt-fast-call-for-help/. (Intel developer's blog)
  21. "Intel x86 considered harmful (New paper)". http://blog.invisiblethings.org/2015/10/27/x86_harmful.html. 
  22. "Archived copy". https://www.kernel.org/doc/Documentation/misc-devices/mei/mei.txt. 
  23. Igor Skochinsky (Hex-Rays) Rootkit in your laptop, Ruxcon Breakpoint 2012 http://2012.ruxconbreakpoint.com/assets/Uploads/bpx/Breakpoint%202012%20Skochinsky.pdf
  24. "Intel Ethernet Controller I210 Datasheet". Intel. 2013. pp. 1, 15, 52, 621–776. http://www.intel.com/content/dam/www/public/us/en/documents/datasheets/i210-ethernet-controller-datasheet.pdf. 
  25. "Intel Ethernet Controller X540 Product Brief". Intel. 2012. http://www.intel.com/content/dam/www/public/us/en/documents/product-briefs/ethernet-x540-brief.pdf. 
  26. "samples: mei: use /dev/mei0 instead of /dev/mei · torvalds/linux@c4a46ac" (in en). https://github.com/torvalds/linux/commit/c4a46acf1db3ce547d290c29e55b3476c78dd76c. 
  27. "Introduction — The Linux Kernel documentation". https://www.kernel.org/doc/html/latest/driver-api/mei/mei.html. 
  28. Joanna Rutkowska. "A Quest to the Core". http://invisiblethingslab.com/resources/misc09/Quest%20To%20The%20Core%20%28public%29.pdf. 
  29. "Archived copy". http://www.intel.com/content/dam/www/public/us/en/documents/datasheets/celeron-mobile-p4000-u3000-datasheet.pdf. 
  30. "Platforms II" (PDF). http://users.nik.uni-obuda.hu/sima/letoltes/magyar/SZA2011_osz/nappali/Platforms-3_E_2011_12_14.ppt. 
  31. "New Intel vPro Processor Technology Fortifies Security for Business PCs (news release)". Intel. August 27, 2007. http://www.intel.com/pressroom/archive/releases/20070827comp.htm. 
  32. "Intel® AMT Critical Firmware Vulnerability". http://www.intel.com/content/www/us/en/architecture-and-technology/intel-amt-vulnerability-announcement.html. 
  33. "Intel Software Network, engineer / developers forum". Intel. http://softwarecommunity.intel.com/isn/Community/en-US/forums/thread/30235057.aspx. 
  34. "Cisco Security Solutions with Intel Centrino Pro and Intel vPro Processor Technology". Intel. 2007. http://www.intel.com/business/casestudies/cisco.pdf. 
  35. "Invisible Things Lab to present two new technical presentations disclosing system-level vulnerabilities affecting modern PC hardware at its core". http://invisiblethingslab.com/press/itl-press-2009-03.pdf. 
  36. "Berlin Institute of Technology : FG Security in telecommunications : Evaluating "Ring-3" Rootkits". http://www.stewin.org/slides/pstewin-SPRING6-EvaluatingRing-3Rootkits.pdf. 
  37. "Persistent, Stealthy Remote-controlled Dedicated Hardware Malware". http://stewin.org/slides/44con_2013-dedicated_hw_malware-stewin_bystrov.pdf. 
  38. "Security Evaluation of Intel's Active Management Technology". http://web.it.kth.se/~maguire/DEGREE-PROJECT-REPORTS/100402-Vassilios_Ververis-with-cover.pdf. 
  39. "CVE - CVE-2017-5689". https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2017-5689. 
  40. "Intel® Product Security Center". https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr. 
  41. Garrett, Matthew (May 1, 2017). "Intel's remote AMT vulnerablity". https://mjg59.dreamwidth.org/48429.html. 
  42. "2017-05-05 ALERT! Intel AMT EXPLOIT OUT! IT'S BAD! DISABLE AMT NOW!". https://www.ssh.com/vulnerability/intel-amt/. 
  43. Dan Goodin (May 6, 2017). "The hijacking flaw that lurked in Intel chips is worse than anyone thought". Ars Technica. https://arstechnica.com/security/2017/05/the-hijacking-flaw-that-lurked-in-intel-chips-is-worse-than-anyone-thought/. 
  44. "General: BIOS updates due to Intel AMT IME vulnerability - General Hardware - Laptop - Dell Community". May 2, 2017. http://en.community.dell.com/support-forums/laptop/f/3518/t/20011662. 
  45. "Advisory note: Intel Firmware vulnerability – Fujitsu Technical Support pages from Fujitsu Fujitsu Continental Europe, Middle East, Africa & India". Support.ts.fujitsu.com. May 1, 2017. http://support.ts.fujitsu.com/content/Intel_Firmware.asp. 
  46. "HPE | HPE CS700 2.0 for VMware". May 1, 2017. http://h22208.www2.hpe.com/eginfolib/securityalerts/CVE-2017-5689-Intel/CVE-2017-5689.html. 
  47. "Intel® Security Advisory regarding escalation o... |Intel Communities". May 4, 2017. https://communities.intel.com/thread/114071. 
  48. "Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Remote Privilege Escalation". https://support.lenovo.com/us/en/product_security/LEN-14963. 
  49. "MythBusters: CVE-2017-5689". https://www.embedi.com/news/mythbusters-cve-2017-5689. 
  50. Charlie Demerjian (May 1, 2017). "Remote security exploit in all 2008+ Intel platforms". https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/. 
  51. "Sneaky hackers use Intel management tools to bypass Windows firewall". June 9, 2017. https://arstechnica.com/security/2017/06/sneaky-hackers-use-intel-management-tools-to-bypass-windows-firewall/. 
  52. Tung, Liam. "Windows firewall dodged by 'hot-patching' spies using Intel AMT, says Microsoft - ZDNet". http://www.zdnet.com/article/windows-firewall-dodged-by-hot-patching-spies-using-intel-amt-says-microsoft/. 
  53. "PLATINUM continues to evolve, find ways to maintain invisibility". June 7, 2017. https://blogs.technet.microsoft.com/mmpc/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/. 
  54. "Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls". https://www.bleepingcomputer.com/news/security/malware-uses-obscure-intel-cpu-feature-to-steal-data-and-avoid-firewalls/. 
  55. "Hackers abuse low-level management feature for invisible backdoor". https://www.itnews.com.au/news/hackers-abuse-low-level-management-feature-for-invisible-backdoor-464499. 
  56. "Vxers exploit Intel's Active Management for malware-over-LAN • The Register". https://www.theregister.co.uk/AMP/2017/06/08/vxers_exploit_intels_amt_for_malwareoverlan/. 
  57. Security, heise. "Intel-Fernwartung AMT bei Angriffen auf PCs genutzt". https://www.heise.de/security/meldung/Intel-Fernwartung-AMT-bei-Angriffen-auf-PCs-genutzt-3739441.html. 
  58. "PLATINUM activity group file-transfer method using Intel AMT SOL". https://channel9.msdn.com/Shows/Windows-Security-Blog/PLATINUM-activity-group-file-transfer-method-using-Intel-AMT-SOL. 
  59. Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB. https://thenextweb.com/security/2017/11/09/researchers-find-almost-every-computer-intel-skylake-cpu-can-owned-via-usb/
  60. "Intel® Management Engine Critical Firmware Update (Intel SA-00086)". Intel. https://www.intel.com/content/www/us/en/support/articles/000025619/software.html. 
  61. Newman, Lily Hay. "Intel Chip Flaws Leave Millions of Devices Exposed". Wired. https://www.wired.com/story/intel-management-engine-vulnerabilities-pcs-servers-iot/. 
  62. "Disabling AMT in BIOS" (in en). December 28, 2010. https://software.intel.com/en-us/forums/intel-business-client-software-development/topic/285926#comment-1503750. 
  63. "Are consumer PCs safe from the Intel ME/AMT exploit? - SemiAccurate". May 3, 2017. https://semiaccurate.com/2017/05/03/consumer-pcs-safe-intel-meamt-exploit/. 
  64. "Intel x86s hide another CPU that can take over your machine (you can't audit it)" (in en-US). Boing Boing. June 15, 2016. http://boingboing.net/2016/06/15/intel-x86-processors-ship-with.html. 
  65. "[coreboot] : AMT bug". May 11, 2017. https://mail.coreboot.org/pipermail/coreboot/2017-May/084250.html. 
  66. "Disabling Intel AMT on Windows (and a simpler CVE-2017-5689 Mitigation Guide)" (in en-US). Social Media Marketing | Digital Marketing | Electronic Commerce. May 3, 2017. https://mattermedia.com/blog/disabling-intel-amt/. 
  67. "bartblaze/Disable-Intel-AMT" (in en). https://github.com/bartblaze/Disable-Intel-AMT. 
  68. "mjg59/mei-amt-check" (in en). https://github.com/mjg59/mei-amt-check. 
  69. "Intel® AMT Critical Firmware Vulnerability". https://www.intel.com/content/www/us/en/architecture-and-technology/intel-amt-vulnerability-announcement.html#usefulresources. 
  70. "Positive Technologies Blog: Disabling Intel ME 11 via undocumented mode". http://blog.ptsecurity.com/2017/08/disabling-intel-me.html. 
  71. "Intel Patches Major Flaws in the Intel Management Engine". Extreme Tech. https://www.extremetech.com/computing/259426-intel-patches-major-flaws-intel-management-engine. 
  72. Vaughan-Nichols, Steven J.. "Taurinus X200: Now the most 'Free Software' laptop on the planet - ZDNet". http://www.zdnet.com/article/a-new-free-software-laptop-arrives/. 
  73. Kißling, Kristian. "Libreboot: Thinkpad X220 ohne Management Engine » Linux-Magazin". http://www.linux-magazin.de/NEWS/Libreboot-Thinkpad-X220-ohne-Management-Engine. 
  74. online, heise. "Libiquity Taurinus X200: Linux-Notebook ohne Intels Management Engine". https://www.heise.de/newsticker/meldung/Libiquity-Taurinus-X200-Linux-Notebook-ohne-Intels-Management-Engine-2835910.html. 
  75. "Intel AMT Vulnerability Shows Intel's Management Engine Can Be Dangerous". May 2, 2017. http://www.tomshardware.co.uk/intel-amt-vulnerability-me-dangerous,news-55499.html. 
  76. "Purism Explains Why It Avoids Intel's AMT And Networking Cards For Its Privacy-Focused 'Librem' Notebooks" (in en). Tom's Hardware. August 29, 2016. http://www.tomshardware.com/news/purism-notebooks-avoid-intel-amt,32576.html. 
  77. "The Free Software Foundation loves this laptop, but you won't". http://www.pcworld.com/article/2879086/the-free-software-foundation-loves-this-laptop-but-you-wont.html. 
  78. "FSF Endorses Yet Another (Outdated) Laptop - Phoronix". https://phoronix.com/scan.php?page=news_item&px=FSF-RYF-Another-X200. 
More
Upload a video for this entry
Information
Subjects: Others
Contributor MDPI registered users' name will be linked to their SciProfiles pages. To register with us, please refer to https://encyclopedia.pub/register :
View Times: 2.8K
Entry Collection: HandWiki
Revision: 1 time (View History)
Update Date: 31 Oct 2022
Notice
You are not a member of the advisory board for this topic. If you want to update advisory board member profile, please contact office@encyclopedia.pub.
OK
Confirm
Only members of the Encyclopedia advisory board for this topic are allowed to note entries. Would you like to become an advisory board member of the Encyclopedia?
Yes
No
${ textCharacter }/${ maxCharacter }
Submit
Cancel
There is no comment~
${ textCharacter }/${ maxCharacter }
Submit
Cancel
${ selectedItem.replyTextCharacter }/${ selectedItem.replyMaxCharacter }
Submit
Cancel
Confirm
Are you sure to Delete?
Yes No
Academic Video Service