diff --git a/README.md b/README.md index b5cf7a3..d4c965c 100644 --- a/README.md +++ b/README.md @@ -156,6 +156,9 @@ disabling should first be blacklisted for a suitable amount of time. - Intel Management Engine (ME): Provides some disabling of the interface between the Intel ME and the OS. +- Intel Platform Monitoring Technology Telemetry (PMT): Disable some functionality + of the Intel PMT components. + - Network File Systems: Disable uncommon and legacy network file systems. - Network Protocols: Wide array of uncommon and legacy network protocols are disabled. diff --git a/etc/modprobe.d/30_security-misc_disable.conf b/etc/modprobe.d/30_security-misc_disable.conf index f82ccb6..9cb1156 100644 --- a/etc/modprobe.d/30_security-misc_disable.conf +++ b/etc/modprobe.d/30_security-misc_disable.conf @@ -70,6 +70,15 @@ install gnss-usb /usr/bin/disabled-gps-by-security-misc install mei /usr/bin/disabled-intelme-by-security-misc install mei-me /usr/bin/disabled-intelme-by-security-misc +## Intel Platform Monitoring Technology Telemetry (PMT): +## Disable some functionality of the Intel PMT components. +## +## https://github.com/intel/Intel-PMT +## +install pmt_class /usr/bin/disabled-intelpmt-by-security-misc +install pmt_crashlog /usr/bin/disabled-intelpmt-by-security-misc +install pmt_telemetry /usr/bin/disabled-intelpmt-by-security-misc + ## Network File Systems: ## Disable uncommon network file systems to reduce attack surface. ##