ME Analyzer: Intel Engine Firmware Analysis Tool Discussion

Indeed I didn’t have that, thank you for using ME Analyzer and for your contribution @ahui

you are wellcome sir plutomaniac

This is cool programm, thanks plutomaniac. In that window is Size field. For example - 0x11A000 . Is it size in bites ME region ?

examplemeanalizer.png



That was size Intel Engine Firmware , anwer me plutomaniac. Thanks. I have dell 3570 with i5-6200u. Skylike-U PCH . I have four bin bios file, want to choose ME region on new clear. I can’t understand what Intel CSME Firmware Repository need to use for my platform? Sorry, I only learn work with bios and ME.

That result unpacking another program . Size of whole file section_3_11.8.55.3510.data 1,93MB.

section_3_11.8.55.3510-data-meanalyzer.png



That result unpacking ME Analyzer . Size of whole file FTPR 0001 [0x977774].bin 668kB.
[[File:FTPR 0001 [0x977774]-bin-meanalyzer.png|auto|auto]]

FTPR 0001 [0x977774]-bin-meanalyzer.png

Nothing very special to report, very good program. Two days ago i downloaded the newest version to try it. To my surprise Windows 10 Defender marked it as a virus and deleted it. I just now redownloaded and everything is ok this time.
How …??? I did see a newspost about some ransomattack on github , but anyone know what’s up ?

@ Homer:

I don’t understand what you’re saying at all. You’re showing CSME 12 firmware, then CSME 11, some Dell HDR components, something about firmware size & FTPR, cleaning… What? All these make no sense. If your CSME firmware is corrupted, read Section B of Intel Management Engine: Drivers, Firmware & System Tools very carefully and then follow [Guide] Clean Dumped Intel Engine (CS)ME/(CS)TXE Regions with Data Initialization. If your system has an i5-6200U then you need CSME 11.8 Consumer LP firmware, not CSME 12 or anything else.

@ GnarZ77:

AntiVirus false positive obviously.

need link for repository R26

-redir : Enables console redirection support

How use it? Redirection to file, for example.

MEA file.bin -redir > output.txt (check -skip and/or -exit as well)


Thank you, all working, even without -skip and -exit, no pause.


Ah yes, I forgot that MEA automatically enables -skip and -exit when -redir is used.

First time I did see plutomaniacs tools in a bios package of a German manufacturer of customized server systems (Thomas Krenn): Their bios package for a supermicro X9SCM-F contains text-files with the output of MEA and MCE for the corresponding bios!
Bios, download page.In the zip look for version-microcode.txt and version-sps.txt


Ha, that’s cool. Thanks for pointing that out. I guess more OEM/ODMs could be using MEA and/or MCE in their workflow behind the scenes. Cool.

bios link https://www.dieboldnixdorf.com/-/media/d…63_d611_q87.zip
the firmware not found in database

D611Q0163.png

Hello, and thanks for this great site . Im getting some strange error messages with a few bios dumps:<br /><br />Error: ME Analyzer crashed, please report the following:<br /><br />Traceback (most recent call last):<br /> File &quot;MEA.py&quot;, line 8714, in &lt;module&gt;<br />OverflowError: cannot fit int` into an index-sized integer

Any help please. Should i include a link to the bios ?

Hi everyone,

Is there anyone who has a high core count CPU such as Threadripper? I need its processing power for a few (hopefully ) hours to determine a value for ME Analyzer. All you’ll have to do is double click a small utility and let it run until it returns a value. If someone is interested, let me know.

Since there are multiple Intel ME related Threads I don’t know where to drop this:

https://media.ccc.de/v/36c3-10694-intel_…ngine_deep_dive

Is a video made by the 36th Chaos Communication Congress (36C3). I didn’t saw it fully nor known if there is anything new for those that already deal with it.

plutomaniac
Hii, my dear friend!
What You can say about ME 9.1.40.1000.bin 1 568 768
At first time, this is Corporatve 5 Mb,
I take it from China`s mobo.

Hi , why t see such message when i want to know me region of a extracted bin from .exe : file does not contain intel engine firmware !

i get this error with v1.121. Does it mean there is a problem with the dump?

me analyzer.PNG