>>14259317 (pb)
> Traceable log
Not necessarily.
If their hack was 100% in memory, there would be nothing on the machine itself. All the records and logs would be on their PXE/DHCP server or the router/firewall.
That's why they won't turn over the Splunk logs.
>>14259330 (pb)
> Wireless module
This can be faked.
If they've comp'd the operating system via PXE, then can have the OS list the WWAN as offline, even though the PXE loader has fired it up and put it to use.
The x86 and AMD64 commandset are filled with undocumented instructions, many of which were intentionally created to allow the systems to be compromised by (((intelligence agencies))).
The undocumented instruction set is a real thing.
https://hackaday.com/2021/03/26/undocumented-x86-instructions-allow-microcode-access/