High-risk tools in Nevercheese Pcileech Memprocfs
6 of the 37 tools in Nevercheese Pcileech Memprocfs are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
device_reconnectExecuteReconnect to the DMA/FPGA device after a previous device_disconnect.
-
benchmarkExecuteMeasure DMA read/write throughput in MB/s. Use this to verify the FPGA device
-
fpga_configExecuteRead or write the FPGA
-
memory_writeExecuteWrite bytes to the target system
-
signature_resolveExecuteFind a byte pattern and resolve the operand to a target address — all in one step.
-
tlp_sendExecuteSend and/or receive raw PCIe Transaction Layer Packets (TLPs). FPGA devices only.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.