From 04ba8e7ad1f2c4c5bde5d1e9abe733ec22f2492a Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 6 Sep 2018 14:40:23 -0700 Subject: [PATCH 1/2] added DMA guard topic --- .../security/information-protection/TOC.md | 2 + .../images/device-details-tab.png | Bin 0 -> 42176 bytes .../kernel-dma-protection-user-experience.png | Bin 0 -> 21128 bytes .../kernel-dma-protection-for-thunderbolt.md | 109 ++++++++++++++++++ 4 files changed, 111 insertions(+) create mode 100644 windows/security/information-protection/images/device-details-tab.png create mode 100644 windows/security/information-protection/images/kernel-dma-protection-user-experience.png create mode 100644 windows/security/information-protection/kernel-dma-protection-for-thunderbolt.md diff --git a/windows/security/information-protection/TOC.md b/windows/security/information-protection/TOC.md index 3eed493afd..4afb579db3 100644 --- a/windows/security/information-protection/TOC.md +++ b/windows/security/information-protection/TOC.md @@ -27,6 +27,8 @@ ## [Encrypted Hard Drive](encrypted-hard-drive.md) +## [Kernel DMA Protection for Thunderbolt™ 3](kernel-dma-protection-for-thunderbolt.md) + ## [Protect your enterprise data using Windows Information Protection (WIP)](windows-information-protection\protect-enterprise-data-using-wip.md) ### [Create a Windows Information Protection (WIP) policy using Microsoft Intune](windows-information-protection\overview-create-wip-policy.md) #### [Create a Windows Information Protection (WIP) policy using the classic console for Microsoft Intune](windows-information-protection\create-wip-policy-using-intune.md) diff --git a/windows/security/information-protection/images/device-details-tab.png b/windows/security/information-protection/images/device-details-tab.png new file mode 100644 index 0000000000000000000000000000000000000000..4dfe33e156642b461e46dc32040130ffd7c0b8a7 GIT binary patch literal 42176 zcmdqIWo#xr6g3v+Z1@TDhMAd}nVFfHnVFfHIoS;}Zy292GvkJ~c|Y}QrM7CN{;AZF zJU$+eMq|%~bMM$uit-YOa5!)vARvfRlA_8WAfQR#WfTVN`z$w$vi{ux>Y^+m3{pRX zclO|H0s(1Cfd4Rp{BFZKN@}@)fS|hmS3tMT2|YnTO4X!9g;YKDFF!qW@g}lQ z;$}Wit}O&!{C2i_x>{IxUZ$s+{N7v(+O55iw|#DUUbaIR!9qhpq&#mzUk3lX(CZ5d zsj8&rc`vS>hOAuE6{cO5ErIrhY6yOh{8{1|Ko5zeuVv&#)#o zBqa{x{Lv@SH<}Om3nt)4`A^ids`T`nwARQ*%&5@6510nfk(3*J_C~Ao9@V0W6Iq+P zSYtdx7e5u9!-+m!Ma8HT6?BlM-4oO|D(LMKco*N5A@z*N(PU%6YUVy5uXp-pXMBhG zP5e^})318*B^tn6lVEDdb?!!czF{wl%UA;KEa`7f!hT5sf<{$d-s_~ zP1-GUvTh~j3{(MIc3FR z{mibj1|XWF)s0;e;Fm!N*%gaIe(ov=+VZ7F<+XLf+`}0@dmjOe`^5W*I2oRT+g`FLMj(#|;TiC!FpW;K9 z$@S*qEHFUP%@M#-XqIt;nC`ZU!5wZUH6aBPUFj0-56`b$p!9XSevzI=0Z~UEYuNbf z>B$Yue_2pMT6kM`mmLYI56;~UfNn0nbC8ypn`z*J6uH^YfK53WIJhvJSlqe&cb*-^ z44lf}pUEl94WXS$z~0Qs7D_}NqYLg_H=0AUoSr6X%tRS=U%H0+4#HR2SlHf5Pgj?> zQjUCYz}35ygPq+0GShV(ir`ga?(bc`G zX#H0N@T4@SB$Otcd>zm*LS{r{B^mt=+sN0A3V$%`iLuHS6~`w8x-PuA<|%NxF5dsU zsvz4;LSl?i1T5V*mfz%Ip*b%BDc(%i*vsv+VgWrpcxbOt02C@@uih+|L0{|g+Fq8f zct@@UG(G5g-HSJW7xxRHgPHheoIe?&rjE|LV|vf1*pxrQD&0FPUFilDL< z^P~DFCQpEelEXUH*o@hGwI^l#w0`vq|<>d!1+Dm6#257c}jF?Z7(#=KTKJ%AwxqUA%1f|;=;FGls4AE zt*@^OJN$j0Dgw5R^6~NT@bC!~tGZ58#lb&=ts4gJ0Pnqs+U4x**S52n!laMcH?NQ>* zWBmd8aa|nqRt>-2(x9~6#~gFC83R@+CA85uPGfF%a#&qc6Y#XGak-8(YA8lR@e-^t zT|94jIqmQx^~3D-^pEn~-B0}d`v>?qB)4CD^kxiSb-S5je}^n`gA+nB%!7hze{m{! zT0;^faI7l3-p7z9bF8c~@r!30(q8=gxiK|ti6KEN6%aXA=aAU+5lrHlsAEuoZH`J+o&FWCUN$<#Ah z{i_ozCy|x0ZBAK5uK$2SqRY_}??*zN?fK{)BgWI8%%`K!*I)Tne}`jv6?@LTlyr4z z(0nFdSVxpj|7l{5N=gc|@Pbav(mB9{hiSu|z&O<}a zfLgpWf2_i?HUE*gL5;-4!r*CIi3f~?#(s-=$6p%EC*6S0#fIS8kob4%D@_`CTiqn1 zD6c;n(JIK+kgGp44LPbAFz@msGQS>%oUrKcE&Jnas?1Su)sO1aj|5I0;D$h9CnQvG zcibh%ABabSx`H75avU6-wHA>0zH}u_JUld>tV1WVj@WQFh#nVMp}|get%5OQ;qE+a zeK>8SfWOzzlvzK78v`2~-`M_amEkpJN?|GA(QopL)Ki7QX-U9FMUVwl-CP?Ev1pu36r+MJS!y zDJbiZZ|JTvx4mK%4qa>V+G2+o(Xu3v!Fw8KT;J)^`!p|!eyvmxG<&4=0W%vQ;xW>Y}4=3F}pf9w84Awshj{)h{vZTWXWh(JrD|{}hNTu%5iWz6PFcZ%?J{N_dM* zNlZ!Lkn_uLSM;sD*bppuoSZn-@(mc-`Q@dU@Ck>hyi*h^Qs!JQs;=53Fjm+c5;;9p$LAl> zKcLeZzuUBv$!H0gByg6P-B45a)|l>pH27>rGr;pbSk>MflsA> zxii{rY~X08V-bQEHcmX+L_Jy6+$!HCC5+H(+B$AAvBHAtKGPVrW_jMc0(m&w1lZa; zIt<<}NbxoUY(X-F0`!6no>x~^09bx&YikgYkk~jl&eBSh&*AqSY?qEKf09W)wiD1M zNw#qBP5KkjXmiSQt;a2cVq4o6@9&*=aJb7^+Y=yE6jtFI4ICUV(LbX~7}N9xZn&yYU-t`Ma1hsTsJu*HJEWy?3njzafS zU&-kluh)|pBvC(qHmoyqcQCVgo}6RG3mM61?jvrNnh}JFMMh5~Q{w(1 zoq7qr=8=Zk+RsQxNN7n+Zfp#&H6?f(N^>CPMc9ZiuePRst^Z8aS`X6F@jN$U-qzyc z-_*&@@D|g3&`Q)35jw;Scr7~ef(nvMp7*H4&&)fer$CKcz-Euw8jKx3;dXt3x#PUpLUC1%!-%Hu%*R3JjWx5TSB$ z)!)H?1)s&8{rL+1KoB@<7`hs1CboU=AGWo7WXAXU8s@t$Vz5}h!K!SSx=Z;YQF;!S zl3e9A@`Z<;vbr|d0?nF>1rp=AAebsoNkop3;*JlM2FG+1{1Yh;!hC4}_a87onMVQ7 z8OIR%y_7pm&wIaxe^-27J$h8)-~hkk>b6RMy#qkcS@Y@%321y&|9X?O=lqMs$rtj~ zi7;o70seO3EEu5o~O)uX_#PQ3qjot`uSLfbIkkMJBZD8O6tknYP@STGQH z+5|-aNRXt!K=9@Z9-{Y5q60pesE;K$SW_f_%3p&O;>*X60D(A~FNBi@@<8QL>Os_f zAa(GLW3>KJ+*h_OLqaq{iwfG?JBLQO`UHklknw)9RZ~JJdMhWJrtjca_Nb!ig8DXb z9qRm!Z~XV6N6-k+#C*bhMe_3b7D~`_T3foeYH*PEF`>sO;lw{qzsWCDSOvuk@`40} zTJcL%hr@*QLkT~%%oEdSFJLJoN2o8rg|Y{ikPj1^-tXyPY-eWXk|s3)Clgq<$!`Wf zqL8$1X7|wm{GGS$8C#zQuSLoiECGyLJDK1rC_h)_IrW}coXCLsZ_`$;f!{} zt)t8198=`6noBPgxjSbTk20S7j(i|{I!0~ywn#k%ZMPtwiNLU!EW#FXr|+N-typT{ z49a18re^I7;$dn#OJW z9xnJ?gY^cycdu_>A;&rMHex{v%FfRI&4!%#u|PGTFQ>UY!GgXWY{i|0p+MyE6{rP` z{578t5%Pb8=`!GqmTwFsUuW<;^zm^$-s4Y6Gh%#sK}v|1|AA#|p+!Aa#{1jH(=(LR zVG;Y3W;gTwv}`kb5h{2F(2eSJ&9 z08WCBpTD^;r{A9pe?x1?jVc5j{1o?Cv!S|Vaenpp)#Wt-9>I6eF#mk|9ej83Z)ia( z@Of)n$0x*Fvf@}i7#6_Z_nSkdXwCh;HTb#+-~&sm@)?upw^juT?$*A{7wHia6z71j zn+6ncg;n&_wN$q9kzCD9DK9SoxhdZ2quOJu(%k&_`Pj_7GBPJ!EVOJY^9Zibs$h0z zt(lo$+MC*+Su;S7PG(S1Q!I0IF;f5nYnd#I$??=zZugJssRz8ukW1aT8i?%V+$56f ziEgOLp3Na(@sSRv-7_7ggAHeS-c28|4 z<0k{>{Bx8D^2~wzDwOmZHoF)0X@+CCd%VIuaE%PpYd@krVCL*j$cW=D>~QDnHmxSh z+KJ(<*h=n8fOs4`B;NkkX1eVNBfX=EF!qDxBe*4BAi&T2eYer9A~khSRwf9 zOCg|_w7jmm3aOj)?-eG8=1xZ(`?32|TsCxtH?QpH+l5X03k%cGY({!|Ga=^>%&=-} zYwa`K5;`InFSO75*=21V!L7sCpyia+=M|MmBsUF3WmyEFi}7mgKr4Ufb0QHYY&~!! z{F1=1V^e&LBSEASz3Jh{>#CyrIwL&3s%i>Kc2HFtx~Takq?G1EUyToykJ1)$atc4c z&(_vfQ&ZD=gT9%msVS{n@@{-C9)QSuXn`i1*jrfNLf^VpZ*Q-a)ft*fi;&PjLBQAV zUj8>W@u*sGW!kIZa{&cg&x>xtqe$>8*E_>*rm{%p`mVYSPl3oc;AxeOjvGgIujpJNZP5T<%DpjK0T; z%`9=~887Hb_kh+V!eMTK%L=Z8%;#3{h;hKYR_5!+xex4bWiVe(+T%Mu=ti8Nz(vM; z)eQ6vqCGWNJ3l+bMu-nfA2Gez*2G4}e7BT_Uy;Z^Vn$HLYambyLS^-X|1B}cOUOdd zDx+Ww9yE@c>vyj<)S-+6W(F$hE-pC1tUN(UT`!*RmkbSU^I;fnfcwAVvR$oY3K|;? zrPsE^Xrm&>)Q`wm9~I#4V5K9e{bp(M9A~|1Yo5JMR9{|EyYT7nre+4~Wf>G6Ex98A zqmbm#TsTy)Z;%n_WZ{&s@Q>;OIuwb^ZnaCb-MBnm%qAiKzJ42;B?suJZKv_Qp zo(L4wR3bZvofw+P=az;kI2%jbMi|+7l_Zk=RrqWujpGW+)Vkv&FDtH*-ssS|+;n94 zr|0Cg$k@rwZR{EI9*5%M;{L~sys!b337y0C-lo`BO)vr-9X$d6k#TphNVA4AGdK$HIY(5W=#$sFYK)f)#0M za%NoEg5h3la)#{ubZ9XH(+#yD&r>lE`=|@a`^6TcZ{a>Tcb*@Y%;wIeXfi~j!#~R^ zN)OYQM#;*=I;+LdUmn}pYa6EJ>1!QlwQRQswXhI4v*#kP1ALKTJV{;%_kDl-hl;4ezt63w zV#*}myRf7&Ry8p{_k!m!+>Y@^}0PU6S<+Wdeuhm-$9vy`w9^X=vOdosewCy0$M0hkK1)c z2mF6m$N#v%|7vLe&${~meP^(NBf#0+-PILg(QE(L(Vv;%kN^3)-L8OfA%BAQQbh|t zZN(k7PicNBi?;X%`i6P~_OjN7KsP2Vgy%fNKJvedF6t+T)F1dx!db{7lovxL zJRlVGQi{aMB+uq9q#+%5OrGbyz$G%;ig@z3W>qH+#-kK{2}H`0z|?PO=0lwe)XyT} zNpZ__@`A4w1{5}gd$ICwb{-`k&rE!>tm#xT#a1+$i z$33(@j~X9((o|ONjEr1C2)&u8SysRZpMtiWIM8(;g!JB^t>+`!NbGoCUGJkR#`cyn z(@b*kw!BAW6&6WgX@d&=EVEt57Syv2jPW5Fk7YZufd1`zpg=RY1j%OSp6)GejK&Ca zPdhlYjO3?xsxro7Xq`R>SN`IsyKrHFd@gNgCPne}#PNnt*S37v^|;8@!j$zVTe>ht zMDNOyk%s1Yh~A@7!ho&%r%#DLZr<|VJG)Kn`f8~Ch_y~~ObxW3%kOF;kJNb9(j6Bk zi5)Yqa61pD2X5iSfdz>|Fv=+RjK$v>nZ^vY7xy4S?Zv>=x%R-k_EQ;_w4mku%XBWLKff|aY;0m40Vm8BtLlaH zO_CkB8tN+$OPBT%VJsfiYCN=ns3%I0i}TSi&pdKWW!EaT8fiOo_vRQxAxh*I6finE z(yN#2VYKd$c$^OUTUiP`tLcv~ow<0<-ZET7gRfAGyMIkoySh7+EI_@BTO(nTjjO?) zXJp-4O|~;L+7J}u?3m6ux%g-AAk+>s4Y9b!>u1An>lU zf+hO*ZHc_&NkyO<$lttG`yFfP;?tNG0hw7B;fGcv}l;{ z{cKF~G=b7*9vJF^Q-WvOc3)v8$0RC{@h3pAWJRI2wi2rZZc#a?H0FNdP8iv?&jaX# z?zp;7WM`ep@p%y*P*b{^&_MnHFN=LGHc)ICS3`j>pe7xv>=Q(NJO?kfaT*rvUy`X2 zyQPwYptZXm7RBOo{eJD>%nj@&mZs5D_b9&_=<>1GY<6;z182fRzR;!lkv<4THATh5 zkdUE)fvKBa2In)E;sDmSXAO3VhvmLUX_avvC+Qd)os+{IXrr^*l8cN)kK2>OZD_}C z$UT6f4zfLHUr=Co0Kc-`)#YWN(0)V2BHm%guA3c7l<4GppeTuxa|X0!@PJ_>-Fw;x z4hu*QEhmevp@~UI%Dd*k!JX z%MSJyrv^b#Pbc@{;zCDvVE)C@&_ANNDVVr9qX%VfM$8T|gRkxiANSfJdEWgPofyWc z^S4Eq3147y4{4qM*U^X!XHH8CA1~+J>gtXF>l;fx(1MxsHzr6L_`l|dRJlPxfwlNA zL^yBUVILzKo0yc1Ewa5;p$G5~5g%9Xiqn%KWsC9(_exb9HxFlHuxaPX9q3j*ZcBh5 z5%P9RyWrx?{r&Wi$j95l(|Mik z+fhUTSl`%xtullK*FELx;eG7Gt=IPy(w%#%bQaZ3={YDMqIDbvN$a`b!eWcRl zh)@{NkQvFS485PZH7^KPL?HO>{G7k}vQX?NC8mN@Lb)^aV4=X2hzW#{fppTKh*^rZ zfByO&wxXm_s>jLcp`=D!{SY|z0FSmb^ARHAwo}`rM=#LS7MGKMPA$E?gPr;`^Y4ei zSHV&@fINkYxWW7apqO_zr>$UY^pLZKL4s)-{Et{+Q}zbKUf?35w-lrRt70V zE?niXiKWQIc9y*T&`J(ISKE%t$%b4`;$vF@Mla*466w;JKABs&FLTw-hIL)MN8}6% zGOF=?dDLP4!&*mbcAq$FIV}?UZ&MZq_jh-CU8F4mf<4YU&xesk3~WC9iuYcW6^yXkW+qH89k+&H%ONO%tjd&!G61lGf?y%QD} zKP*B^zk`*yh3hO!4|parwwQ?D+}X`z({@brIl;}HZ0iaRTfO+nYS@Q`43tEPddoxc zaF}gs*~pPwVn}s-+(W`L_fSYX2=+W&{icp~60he-5f&C6cC7Y0hc}ue)mYhAENA^< z3(~-xhd-cMSG~t@EeCqM91aig+oQ2;$8EAl{7+bTxQ9JXDx#?wjY5EKHy!2E6?7v7 zE&W^e0(96u!!IJ2ZmJ5uc;_8`_vWrQz^oiv9|a`JGx}Rob~#YkqbxKVGejz&00;(- zE`Po1R6p;r+hcQ)2MX-;1bW{D4&YIYsVTZ$f=o0!Sa+k}*mbw{A@vzVd}s^ma`v%c zg0w+;ISASb{eoNqgzEec(9sH6UoEe&^Xlw5*)wL=d+eM|-Fz3u#~bi@!*!(s#eLsw zeGVjO zpaG(s8}2aekkD+Ee1~OaS=k-&kDV`oo`E9mzWd2ub;XV!)T&qKmtAL(gl1t^Qf=|& z0=ah#p?fKBQDb>mg@lOsb!2o>DsmEwBTy4RT_uspi2d25D zM<>P0KvU4jFS~?UupDs7x}!E?=bZEE#Pz*=q|0fTGmp$Bb~#fv*f+|NV7(eZJ3**1i^F5`HP(dL|!SXb67@OZ6e$c+3q6164MBW2Dj_LI>a^lYN~*e2rX3X$YWnjW&1%y7xS*=1 zfcK2qBo%K%TVmi?*L^$?xUn%cJ>A;aIJdI0GB-D8TvSz6^=;j#sHljDkTEdaJUx56 z7@ChTv~7#1pqzJTv`f7+%QD&{r6w$CXlj$B_?fg;gx151FUB$)`mZ~WMx*!kPF6ruSDAex#p5j_sQaWoPP6F$H@@>r1|eW(sAJu)pbT`FrJqEJOql7h5~ z`a9xe=O@Ev7S`<l5d8d7uPd)3At7ONvGx`|TC~@+ z?6%3B&dAg8O8Gc{wb9Y{^>#s{QSbZj^CjSYW2d&Rj*F%nTw;3YAme(I$j;F@amrEB zV(aUJX3hLF{%qBe%PwefbANw-ZB0`{Lu38n{`@>UXn^<|>*;MBADhEnLP52j~yRx>K=V>AJGXBDcw$yt+9-Qnlm?~nw8b`trm#&eP5Ii z;{v=Hi-7!J6Ekz|6Jr+R>nLu%KR&@DtE-j|hw*GC_HIuRUiC@IGy>#q?5RxQwLj|{omzI{kMZL==MwFz9a5s|Q6A&_R0BZ|wFJS{iV7DlNEApeh%&x==PAzw&j|l^Fx`C$ zw$@)CK43Tihsk2AY2!q28*NetrVUltQVHwe`AlP(vW3VP+#|%$fkJ0w*564>Izam- zL=;#)6KCWB0U|Tt9*D7qtvFcUKV#B#X`NdKb=Bnk9tv7t4&qC|{7Pyf2g{5?NC?Q*11@Nx=IQcqFD&x&0a+5Z9+#A{2<$Jh zbnGVl6_wIX2(-F6*;spiiEpkc0us6Tc~H>Ofkk#I9_(>>A}g2`gxm1exVi9*DY<$S zD@&^_kFjfIn%F!;fN^s#Ypgn(ByG$0)cO}x(o@+DQ36%pDNakR;FC?nNP zCEVp`b!f&#w_5D-G}Tb|r0&@2aI@Idc5f~!VPxz54=YzSHBwbJaIcKk=N20(Ef8(B zvo0Ck0Z{9R6*-p znO8<5Bzzdb?C8{{UaaZ5;jw9JT^_+?JC^WNf0W;Y{h8m;3o3M3Udo*$IR49GktadU z|1_F-w*kIt$y^|Mx*l9#2JtRam%Q>Gb`^8Xb($9F6CUev+$AtWL64~Ucf`RKwGN-R zaq1u&@Ddgl=5+C(oJ~J7de3(dLp1Eo1>8OMX3Zr$5#>zNP!BWZ2)ROJSIgTeo!mKI z-vl1^(6g(49WE{aa98GMV1M06=m@qw{YHs8+B&)Vl7%ug@a@%oY{q#H83|M4?5=%& zD_))2(R^6`7)j8`=;4nTqz6@DKOsBmW{2NREnH@(jR6#SeY`a%mrnrqITI?GIVCkm zC=F49T8qf0I5>Nzsoq%swgJJOj)@Wr0>w*uO4<#B&#usPxcX}8U=Fwbvs5uMmNo$< zW^f_fC;`)jt_n?rQE`cwQ0`f`NDGM^j=z6l7$t0j5|>!BZRn)wEB@@CBs0MOtR_8Q=^wz0(i%(#1~6U*tyYJrB`EjDF5%-#kth z$mO0B_Restx+3#rXqWzr9%{#m~>aC!90Y?lB&T{y2?^WKJIuv^hj0l zQc}l<^C1O!h^Tnhr>(N~>P2@z%dZ=>A*^B>vb2^I9mSEWv)tI%kL4C~%bJAMQdD>hnlv=O$lYA3(Xlqh8*K?!Jlz$c5aru(PwX zv4MYtZ+i;*mHO=~K3XXFi<#lTIvU~|3`fXXJvt_$g?E0;^xDCHyWq>nM52b^?%emG zpLjoFhW0dV43#u#dMO725rQNEs!Qa%PM2x{2umvw$I8G#x&#`{H&n+=xykgz%>V=jJnyr&!X3+t4AC$C813j1IVtf z)m7#DlYbx5Vp8%$%#zX~gw_|N`^_h!cm#dTt*ub*oKRajmasoMx(D-qK^mi*`&n7R zCP3%y0x&UGnRW?*RHry0BXzV4Mos-Bm-`FMKVr-_9#jPF{44|8!%x(yLZ6UQ?tOMW zFFe50I=d7qu5bJ*MFZ~W(BOd)VOvxZI+sW=hdtnJkb7{7n#lFH%9_pcFPvO}S2-Mt zvB9xbP}z)Z0);(}zMcUJ+I|r}(ONLVmJBdoLOu}zbNGmM1#g!gQBhG;o;&b~W1`SQ+@OS1m0`XK;C^Lz8#}`^6-z2%1GWh*h+gEL)j&LYvuWk^8XcdJ zLc)Wpln5SbsH$4#()}ou%=DeEfqb(A%Uf`s6ciOpcb)7!=*BlVsH`;O7lQlpW{p3# za^r+vs;g(?f=-n+3bdL_+>E>X$6k>{he;%uFVGdPn@fP?eNv?q-xsAX#>zs>Y@~99 zo8P18&mjngt)B%9uhbRpf}r(-6<+Xq!Orbx z`}@f(&2hO(UE<-J-6V6h2eiXp^F7IC8nO} z>92_vHm_O}4{w%vCtJCfy z$lY~3>*DEYX%S%`Szk}zb;w2!H|118LE-_rC67!NnhTF?I>6f<-^#zM-DG4|5_c(o z#E?rYJJ{zp;vzTrhOT!uyqSg;XRF0S08?Xg0K=2z_721!#a_TEqNS#;zWmHpgX~8} z!=OL&^GYZlK-$mUoT$|j<+G~WVe){Q*8A7@54Yw~_UNvks%pE>7mg!2qtlnX7z9uB zSr$9_^Ly=}IX%0%Jh8%bUnw}~QD-pQ6G575gjO2^nzZj>#vFbSEhZOC6bOx|!22G% zGp|>lFFyJtTtw(pWgx;_ZX))Y2xU-o^(DgTYT_84Z>m?;C2jrEUlc|vCEm(nNW;6%m>Z~(7*B~ldAn%vRw1SmK~ec|^%SUREvfo(5}!cxTdWzou^ZY} z22z_D_XJGAJlcwLDU~Gd&y4tAVX*0myTu|^4B8_eoojYNwLWHVQ`~C@NlXXDA z&dT%AvF>46BLrP{M`!+z8{$u?{QkZfFavekTnH;)8gg<`e&Jlb0Tf?jQ@n)BhKQB!LFbkRqHyYyRG8E0+iGA3NKZGt1r|id#Rk!^@WB|H!UH79E}kv- z_$XQz{b;%tU$n^{3d71mm+5yZjp=5lRL-qlC-FoD)pYNfnG8?n2~GLGrixYIsph6w zpE&2`WMrkoy@Mg94CGFUOW2Ty6|#^tGx-IFJ<0=PWt`!i!{cnXMA>r|!>!tc!p*fv zukB9_U3*{oE0MLCqAraFbvm*O3aw|{FrdTuG>`paI1)}kpx}ru@h2uC0(}FDM@Tq7 z@$IHy;A}$CTWE+RNU=p8!@zt7LGPzmu<@YN?d8V@q*XEF;?Isj^Hv%lHFE-^f7QG0 zx>SUUhbn?Hj|}0ao=FQaF_l1{diIOsv^^x9|Ea9c8`HL|g;b1K0Iosb!jf0Vf$@{p zl?I8FQ$o{_#RGsi8n4SjMaAZ^7!Bf4IbVP0cG&`}1&6_~p+byIOor&Y$7PIq5M$R* zS}K|Ff|=*XLA`ELE8ZNPZyaQ`Ri*_N4fq7oKCI~}XkiZNf(C;fAt`BLGy=at zSb(uG(G9Mu=4BT?QQ`{>Iv|wBH+B%{PuLic3-Pz^^)ytBBq@Fy+Q-Ky7eL$x$q*(+ zo-z<5??njW%QKj8$rYhB;|Pv3B7^vga_@0(ei2u%G; zv$eJTz8yL;xekFn#$~aj1T7+0z`8Feq(_h1EyAh)O=lM}u#uClmqu{^W{OwyqVlzB><*2&26@ZfX7 zW&|sPO-uL3N2mIaLyxa^eBIGh&eD&U7r;hKCqVz743>nZ>iOHfFQN1ecmDMG9^&OZ zwm|!tuI6`!gb6AeD=%|nliwQV2^)>z!hkX%Obwjg+nfL5 ze>i=8z1=nZ#a?HPJY;=V)`*3xqTZ{-$5;2!-OYMDus1*dHo1Q{PmHBW7|4eN_X8=& zKxpa_ljoAni0ZuYi#(ul4@J$+ym0T@R)3TGb-keP)UK}4;|_U0CHI1Md}>NII)UBA zaivY<2GwW?utJb`W?jk6$iA?(6-K7?T&c=!65x>VgB{{=90Cw1XUJ^bl5fkDNt6J5 z2zD`I%0e*m4=W1#3O@C*azjHP@BGVpPVYj<3Go`_?dj_KYqoSjFh!Nyr9fPy;9R7F zMUa6N2V?6p1bl7=rP94WssuA^r1SckTcSMB z*)QM7RcO{YsckSp*Z@BYw->`DIQ(vq@Ki3>0K zJNxyPRaI^+G@Be=T-uX1(DF9G@bxh}z^`A<{tVUuIhNy66R}NHySs$5n^9CfT;6`} za6L|0MPoTWMM{AV?h~M8hM|YJp0$4W@8dnKegfl}x&c;3Y6n-gs>aVLjjrSMFgO^j zxVhSGneODA1>aA^6vAHCBOP#T;VNIx-+fbKc0Q~R??_MUU?R2y65zq{G7~=7eI3SV z5fbS$6Hh;*9ghTFcNj~1S=z=|t9m_*nHDWGZdEyzQdtQD@;#OBTZjTXUFPRFAvHSQ zlgaVza51T087K!d!Po~F$by>$xPjq5Ma%N$4knN|mxR#!n zl(l*F_sV_^DV2~>K|~)l%?)K~^+gqxAJxgfClU~*X(2KGY$2p#l`;{yC17cUw7&`a z$@su>EgxSBa>>QWar;%Z%mL@Uyi&{!jXgM;`?nR>=O;h>)w_!OHC6!T^hN7m?7*34 z_8$q(1f15u4XsV3c4@?BH+Q!cXK&Y8)xo9B<2MX{c$2*0dwFavEfc=9FRzb+-dAk{ z`R3l5cY&{0Hme-?L10O8T3tvy(zC=H@MkOA-x2iMTH5?lfQ|NV7DqIFDKCxsm^DqE zxA3y@DjT_Fv(xO2=&cX)Ql^`@!SB5ZNWv=Skxy%eCaUX!c})wJdg894iXtjev7NnT zSxQ1;X$K`1u0*DQ@9&p<(w^I0+{EUMG$EouD#et=1U4cs&&xrfrL3*4sOsrdSl(Rx zlYv7;U1@vi?uhT5fi%5}Ad`=ai;KJP0*5P0dkf?9I=Zf{Ek5Xp58BSrA0siXM*eY& zn=>BiK}|_Tb7xo6SxD2B%Zmkq%jeKiaJ|AmKyQ3rNV3O8xZIS?*Bt8rMh1r8RrB|E%Kq~90CwdKFXOaj>rFjnFlONDf7 z;Qd3YDH`C!V-jf9w5jv6bTs+k9GTggJxy!O%`9qas%TYAB=D-TiY`F7HEH!3Uc+=t@B#S51BW)r?(AI;X>C_$eaItlJ2>3S(j49h^e}d#YI~+ExvUF8fIkGRPe|g13WW0=e+9-Werf)6D7%2h1 z-c}nRUd6yooGIb)osK@Q+dC`9Vrh7pDU4K(6*m)h;w~o4nzFTy)+EQ~1^*Pgj+CNKbm!br z(M3-$FGo!2?dV|#WU6EC7YDqP8*HuRrsp;`CR+Ym%k0myDLyBU)!R&S=uJsR&%LUf zw$G=QdF~o@VQFdBlTVJ&Q1rJm%PlC7&=$hXjTOpifV0urp^o&k{PWD)H{r6ic5-*d zf0Um2{N}j4wZuKRkBsyWkxQiFxVC?%Weu<{_T-ngB0vQhqUGAwg#2!jOaadD;%XvPm#FE9Q9U1q4a8?fu$E>=tL zE;MDE(mw(XgvQct0-jv5F#`B`5guB517?T*8UgamkUHV@ZP_w|>A(@i0N^p$3np9pm!y@C*In%yNV(dWHx|*g57; zU!Qe9Y@pX5D;xW-McMwL2o`mZ(6u^%A_FSK#v{N)haXZf)*$hWnqHtG?rk`coQaUa z{`+fdB=igHKXUYc4F;hx)Eo2p-<^zU<83<2xwIheT9kQtfbp~ST?3>KhZAV{R#jIe zCNGXNA$_T=^BaaRB4&sxrY>w@krfJI!=bP&h=BTDp#gsXsAWSc|K^D`poVVzgD4lO z`P+HHzsZ>b7iUR~^hJ?G6@RUiqHt#Uvz$!as|n9>FGan16${i8E^fTT(s>D(`9_hu z*GO``lg9|OM3oMGMpz9CDiJy#NEHC5$3ZTG0Tn3&1 zckf(e(k!V~gP`uucn=V-zFBti8x_M>yN z7!Q(>WUe^X^ZGYfym-b6q)ABUJt>NsAV{IDsvPx^@hv7j+37P_!u5lEo&9nh4V=D*aEE6T!SQ(sfwe`uJ>3FW2b@28VJqC`}TL03>9Kw23YaXk(3 z6$h4r&C>0y2PFr5YM&;>L}xW6Bz2|+{$f3_+~K2L=I0%okQPzbO8VvD`*|E!JgPA) zQKH;BqR)GI_6WhToUF>FpMe}IAWn^Xjix107nS}@?4`W36zLqTsk08`AHQ{OJEKlO zO999*c+N2VM8U)*p`rt*&uOC`P*BihtuonEQj-%Av#>0@?tC5b{4eaiQ;=jq_b)na zd)mgdZ5z|JZB*MfrakTMY1^!}ZQDI<+niJ1cTW5xPQ;D-d>?K-Wn|ReRgsx{ugvws z(%xmt-m4(y!vPXgJWY3Y)TPTEO-{F9*&R2dj zzPzZSU}r>35nNy0K$a=T{Je9Kka)%KY(Vpv;-8u|RhavGH9ubv)DAk+QoJc^Ppc>i z=bnU}GnM1^DQ8g0(f-(;Dr;{pD|53lHy05Z0H+t=6X46c4sFHB=@Ht}l}O0OrH?(r zOu#zqS>lu}mwUK(ZOkEKHSM~rTVT-ilqeQ|1y=BOCE9pUjh{!P$-8oN4fLxL@lu54 zqsYfNEsiU~vL~jcB_#E{ZlNG*TqL9|YU$|UUHj&2@!Rgk3p%RH&#(;dERRn`*0E;o za3aXmk#tWNDrWPq?ci6%=ogZ|r(gB|8Lr#wEB~{4D&KA?7YnR^5cH}tamK&+HMl6+^qfv~o`&>#QSOn?o)7ZbXID8o1xt=1(`9 z=XHaM9w?uEQGG<)s_elR$e{Bo4hjZ>tdzs#G)cfgV+_HCU5vo2aBxPI>O2cZin1Wz zhTVlBcK)d;I%#_|8W48^Q1A*N7d>k$kU9h|Z!rWa)urLR)@Gg5a{_Hf$T%*Cd${NT?4)SIc03stKW%*8dXl4+p*hY6JV z0Y&mGj2QUhVq<({A&TsOA|yFC#EJJ1{&_jY7F$alu-Wm>Q;9vxd1i5bdAN7q`gdVu zM`qHH0Duqx zu|Yr*?Ax0g-}lRwfX{Qo(vlKxbtX6nuADXIu?!I&HYfN4Gg5~saliTgXeqjGwvs0g zo;Hs|^nS90F;k2rq}VBtBtr|_%i6rFuySN{^rW)3`|a!fx>m34?z!h5p%uXVaB8O3 zAD{ZWqsm`L_s#&=EFQE6rZTuHP7$+c3~W9cz%~pgvS1nuj-vy`EC_y zEK0If5l*Vw7bkChK%;lUmqtlT4fBQT9cbvM`62HXIt%OG-rgule{;=k zZTZz;r8+8YYiMC$V4S0lX5tVM3TPt8a#MrmgeZQ*s2-A^=s*N|vS9*@n?5`V!iX6X zoM_UNS&KhN9fpCl4v?3D?dHVIj~oFNEkgRur#o;-u%i$=5L^jkwYNOnLMt1b&9O@2 zTjK~eAPBS9gdPh-V#P*aa#VXhPyZ}{^!6A+}Fg@%rn^*I<|%H!_n{{u7m49!19ZjweJ;YCDwu(ynD zZvLWAT$)%nao6yHOsZ^@3-&`mG5Y&=R3gLPYEwsvTM>QL%E&(CkKkazT^jizxL{x3 zZ1U(VXv4ZDkvcaxGW1^_Q?BYuvA^(j`wT2Z3ux&)O#%zcvkExF8*gW~n0d%kB97x4 z8x*AX#6(E*Gr3+;9q${0!A0hv#A4f!#H@hAe{IIebS!c*&4S~S%L+ZTtP32xy;?F8 z7I@wuM{uF)||`SKCbXjTxr#*>`^6*WquFNin*n65mTE2<6B{J zeAKufY;TK_vlRu;Y1G!&_ODZ%=Ro`<*!Bw-}`Zx3*Q}xR&wJ#&zj(6-tVb z%vkh9HPxi+>!6Us6%Jn6uZbGlj|t0_@!YUiA^2+|oo~uf4ZyYiYD7|=|JyXzkidoutfb_J(X71 z7%6PoL}e}TQ_@lXIDZeVyo7Gwh4d98~41CAf$nw#?nC_;J(oQ|hf)B$*zt~(lH8V1s8+Xk}g z40Matt#*x-O%}%XiBh5tmOcY&68-y5?#{lh_R^JPKzWqgC-+DT+UW-B_2i-&(J<8T1b)L33jL|a$gBwB8hgrVa6%@(y@CAg*L z4%V2fc}Pu=#TZPwxU_U+XvpbkM{2NNuIXUpyZS`ghOuS4T<89UKE(3TTP%Utka_IL zMg?K6#U^T^A^s`zQ?zE%fuU|j+QPkiL-UVaO^F{2qWVobFeNP9iIEjI@D|ycKTShI zb#saRv(&yu70O+pHw*}pG}!o8RITx{l+f_gH+X3(OgPuGh_h7S!fA$hXq*zBp$?|T z6F=_PN6ZGp*ghHfhBdP|%uIqW@F`b5r&25<&G>^3jt)B6l>leNN#C)}OBsBG>PLsx z;eo8AHAjvseRzm*ke}=1$Kr7O96}P|Orj)g_DYae8T(YuxO|CB)2UaB{2B+fRV{!dy_E=YYtUa25Ay{GJgg24WF9YO}3JvrWSP+#YGzqVKlHQWt0lgksE97o9rE}C{6SVS9H_&bk-werR$uJ_l@Fa6~MEq zBGA!E9&1p+bR@Ff-9pCg)SpLB>4$iNlkzb*8JS?k_^~bQ5&DS$Qcf>|;3;Moe;k45w+N%`nvj-ny#0A>3%{ z+F2``FTBmm*~mD{$;r7qiyH#uRWyi#ewJ0(d`lxJcVdCqzvm{XX=n%2s|rN((opgB z+qs#a)UtQi(Ds{AvQ%|85p`9Y{GhF&;A?7f$Z81Ua(v*LOD?i=Fk+#5l;1LXTp!=8 z`iQC~{1f`;i;Ajh#gjP116)B&HVKmPd0Og}iS1(M5jz(fJ0F+X{I=l$ifQGqub$SM zjXd&kn9y|H>#dGM)vHZTk}(8UHj}yKstXgs8ZovkqZzl?P0$e5&^s1;Jme~17@N~^ zTzQt4a3*Q7>eGKED0$B0o(F+Ar=OH@uKosEsH1!kVgHB6@$Eki z&_1RhSk%3w9dtEV@^X{2GwNt%XLa2;*~Q9}0_uU%82`a91^p3p5Uf;we#M9>GHo?! zdhp-to7eJ zTxqDwN6rCG$A};bp-ay@cc`cc2g{3@l&{A$8h7#JX>v6*URI>xTE5yZw|?-DXjNN7y1 zJ1H?IrO7zPTr*w*qVIuYE)4}qn8M2>PIWODXm`=xi9T+1J;5=Azrk;*CSk?X$-A24 zQ)x7Y!0TVQoq5B^i_wWf2sjU)V9WoPKqjw60?u=m`Fu^bt)XCGZ|}G9b5);-$zkV- zfr5;h`$WW%99cRR8Nu_rL5LVDTO#qGIOYsNGL{+S5Y?f=wI-)pNxVv_^{?1AZR}f2 z4CA-&3-2*n&s|k~&8U6?)uF4uvCvH{YcPoMb=tyPx&Is;m1511K6h5lJ2$Y7C=3vJ zeqTwYa=jiDyp^rBg$JyArV=Rw-7PGPmt@2x4LQ(C6j{1vSeCgnyrlldDcbDgy#7@B zHAB-{dLr8Y}hV3ZjAQyMN4vUo-bO`8Yqv*T8k?^jeqV>@6F5ovBwO`{p1+`8i5 zTYK-4t_Qqi8F{S^+yYhFc4?h3`2I5*D;3+@J|aNPKL@Pv@g5PUE(CLg#>%AS+X7Yg zc1WEtJ04j-8chdKZ;Y9!iF%@joQ<((ljwt8~*bUZ@`})92}gS;83RfX9aTp@8=x>yzTpch-?3S z;r(BY8)#!fQIeiGP<|^mHdZqfYBfmMpTm{`%m5w%+$&z#*pH-)nAs0e*w`ssfR>{w z?5}p%yAe%S8YC~2{(@Cw2Fk?82Y<>E$9Jq1<11wcaR!s+l{8Hu@%3I)ibPH1lauYO zjSYN!`~iRA@Q8@~Izd!nt(F38xYb9L0ZugXlsgqI&~Il!5kpc}p^WgsMhjDb-FOl} zLxQ26GlR7EBic{0dKy|<1VooH;vhKyJq|r`({X7~|C=MI`=v=j+6m2zheoV4@93kH zV?b75sa}UO$n!&&!->Y&7%uduqO7%-HK|kN8m8JXH^DjrU5E^BhzuM97!U`sgoCQc z*a%two+|J^_mj~g@#l9{%Fx;vMEf=7UqW+hEPYxpiLCfjoWFFK33Nj=tcZtAqNGSq zbbmW5-*pW|F>yUNA~EKA=B_CpOJ_LZf3xA5q81hwa*{fupUSqHB3k6%m!RcA5>b}hEz4i7naqTN*omC7jeW6H*pikZPOSRm$r7M zhZsbqRRycc1aq?}VUJFZuYG*bgYiSfKlq8VzLtB1nCG?i^^fR3elYTRj_kut$VMA! zA%`oSSJKg0MF0SKs%y3sTssgXPtc=z(E^B;-Mz9{+8F7Hg2NOed*Dc6N47R#uMF5hI+| z^TWZ#;dm(w%sW*ntg~~YqEsz@8T%U=pl@xA^!@}XI}a(#;3V4)(eevX&$NEshzKaF z5RcO9hFW=&u6~0j1%tTU|H<_*cywXM`FL^S_z%@~NLJw~1BR-nbC1c%y??Wi1!Ydk zHV@yw&&hV%Su?NW;-SFLveXKYm0>tS6VkL(*7*6n_!r;H`bO9O?$A>rsTLf|$vF@R z!MnQ11%NwDkBq`f_xy;$Tg@UMtd~(lIT3bpK!1KeNLMIid1BJ?_8!EV2l*okZtjSA zkX@QQ?u3SfgaC6_F{&a^>rDrkZo<=>RE%yt+$LC9EuT2tb;-rIqIT*=w3Oa4V&&B7 zG-f|o@;7!S7_4324^a1u-@|llg<>T)hL?5kHk$)D5lohC)dL^5Wbgn(F3|g~a{9S7 z*?b=C37VJNsHOp&8=uWF<^%o6R%UJ>jM^FcqBx3~VK)!&0g$}p&6e+QahJ*ss9z<( zv$6(k70oecD_3|F0WC7JpuRzKPKi8S?|eK8b)(XIniq3952w?ubl!WsKR7W1g|th^ ztKZ5n5$-Ofx6c$KwA{7{9bri(r??|3r)O@n3a}p}$88{wl>)}Mn9|4V+pbc_xHT_^ z&GKHSV5(1w|LL-%Fxq7NJechKYelyvA7t2DkJb_E?b%*YWSQeUs{JxSpt!p3SuEd^ z0-vz8bgXw`&;sU?Mtm%Dm`1N(T^Y5{F zIpjxbY~!4o8%<5 zuLP@M=cmnNoxIOXL@>lSAfD2H+1MRDJu@_-zb`NC2nn-0Jg&QaCUqE^-$hoOZeiC> z{V84|0_Gl~WMkmbdTz5lmiXD1b zePDiM@A*+qe-99NvRzsejU6TE9fH_=ro91)K^cDBfDW_dYmVI~ts(qd3sx2MyN{?i zdHgazK-a0pxaiL4+R*owq^IYO``|{9?WGJ0a`>Iasj#G&vdzxNY1Bm0q*Xv+X6HQ5 zLPyM@jT8@3>B%6s;_)ic{FQTbwxGivj#W&8?N=$&P$SVW<;dWREbK2&^}xKChmrD= zu%p5V{BFA0xk*xXK@N^d@oDBf+cOh_%rTFH$I(@bZ;Exj@zC1$5pH>T+qFbK+LNP2E8dl6c8K3%A{&`q3zqPt~m4a>gTUE3wC@b7!2{6Lo zEXsJ#fu-3L1%3&&20wmoiD*Y|S)^1R@UAdOPsw&vv(6z1ER|)K(X6?@)D5nfj)#w^ zqf7CxSotd0C&*1*ZV<_pXVy$&dHjYH+ID^q;N_~yA&F=$jq?b`;}k)0LlK`s*AY3g z${(IupCm{3WEYklW^Kmsk+bvIeKlk~dLA&j8{yh{8r7wCRzYjN4B)V+KaF2hSBB3L zgOd1p@67DCKC!%PQ{5BUZhj5Lp_~b!E*9OQMe4&jGC%sypscz;d6Ahnp!wfNQ26Z@ zECNbq@|`j!ZL}GK+b1O!XZJf)l3f zVp88z@LjugNC<Lqck}fv~9W?~Q@YqV=xED!g7UY65O0XC&cT! zjZ2wiZEk+JyIbGZW^H2wU$CTz)V)2bI9wGbW(K?riY?w}_U7cdh<4LZgM$%6P&pJ3 zJa1%BYEGZHUzu_EH8DC4@`WFtkdYpIo;@{P)8OQNG-?&T3b1vU`?UIYq|H~dCC7*K?q|G*_O&FE?aeY+Ogz*Whe6G zJAI&}P0oodq`K|5W~_xSwFA8d>RRzLAc*`|=U74`Bcb+aJuwW}Psx5|4#MON^y^FIY_!Ref{eRc-7OACaR(!r=qGg z)`}LB+;_7L0nS38krrnH{y;BZ5}24GN8AE8G7+9P^eHKLplzxKz26T&twCRpfd(YPqWTXqh&V{2^siOVDUgiX8- z7y6v@?Re*HxY6YP<01M&j^AZ@#pLo}KfiQY^U!pf$>Kd<1jTY4wiWRkKr;&I+OttvxtbVd5bjKXAm6#!$D?>ymhr+D^BXq> zhu1$xRdGp4ow+BcEh4Q`SBBvi1uZtf{cxhaAHd*sua0Nk+O5Y<4H)}Z#_sWh7=wGj z#dJmzh3Y6>L!1u!wy4h*yqcNKP?uGh_;;mdElikTH2c84XX6MOp- zxeC^&YQRG6Q#sc^V`fA|=Ut>Hm(9@G;k1O;4C2^a^v$8YIaZXnc`xy5Ma3epI@3xp z<)N-erG2fmTiYtyWAjDd{3!+QE&9tQR!d(IRDM8hTn@trcfa1B)RfF@s~)F#X$|ok zKe=->#?&FFk~>$lr8i2CPs6D^YiY7}A~A?lw;9mxrM6)!K>JKguti6gO}b-6BRa^u zXqqUtco$v`KO}PVd0H}RALHj|c|C0+#PzywC9uXE+iHq21$l{Q)BQed+tchsjI!E7 z^WE9`MFifFrM+v}Z<&o!@OHcWtFrew97T6lY~QG`6iYzTJGVmnr37`>{U$P8CVYE_ zCE8Bj2r`;v3xxvlN;46weT!jefl35yKXUosOJVQ^`_0qoB)PVKm`^o{0*d$qAnbsc zbYwxBQB+ec8hbXoUQm#ewcVNJkKFP4wrhaYck442E8=ka7p9Wk%l}XBVTm z>_oM1Cg+L(cc_7%!xAs;t!3bEftQDhKwYZKl>O{T05It&g+*T5n7F)kdKj+%&9izg z<$BA7O8A;86GFuM&c6*n1)TF+o z(n^*|X3nVZ5b;u^P9vA0O<_^WYExL&U*e5z#4<4$2#!8*NhhP+E03^qgquGtsLCQt z4@lGW3AlrjOi1-B&nrwU8J2W2mTM7D{tcVSm}tt=>*RsJ>5)Ho4PU^jGEv(&HFPyb zEi*EoLXmbEf1U~KEfH(P-w)EHKs}ah>%1#MX?_W0ShuInf4To?@teTiY4SxT`njEO z2CKr}HTY51aYtELR0z3qf4Hq5oXm5&GjB-i7AH2bJz-TK)%sp1a=?4@Y~dl#r9F>n z^YphY#TAkw{o527ne;I;A2NLK34xh9;r{n6=`7EPXdOz9+kkqp>vX<9N}I}Wj_Wo1 zj{#)%8aQ^Wr)!?;w7p_XLYO-Qx9bd#cIwa)m2SU zP~Yn+d`w&KQbAYOr>+4G_%HEe0!7rKqy`Mf2 zC&9o^hGi5wmQ0_j{Mj+m5E07&OfSi7fAo`+-)kbqIjp$s!xK!fGdO&@x~s4KS|c49 zVzmU+OnDCITGe|qJ;(xlMGkcVmJxk+3p_9vV}f=`qhH2U?jf&l)`3m%Zva_D2KKk0&d)iM_2Ykg#`^!syp`ck&1| z@JgZ0D=^*wUtvqf?hY7%pbwUlgnrgYaZ_zq??JPR`kr7RUNew+l+vt$)3G6b5Z1|i zmA}#xm-hJ{r@O&M7gdBD-hC%td-gjb-bpN*PwRj?K^UQ*u-GC4ffbyhU{5!1zQbPq zi`~(L2v|gjT_a^+-N1Hr;3wg7yuMQrc4aP6;MMBNg=LvH@~WY7ZeB-BT}Oa-br3A#>+zf4dY7aoS|wsktc3R;J|UiV;1r$|r&p)4iRM6To!o2# z*Do3u2sc4!0w$_np1;(*9^^&=X_wM_2)8*(V<$6Tj=DZs;HlWk*hY?vE|s%l4@0^6 zy#%HR7ku#6U8DnBH0}QH>P}gN#DQXWOFg)CPb;r)f#h+b%?1~9#oz$He|0?c6_)&A zY?4s7feJAA{)q0kyKoiyZxTygP+neMBs$sMch6+snHQZM9j$D<4=bKZJ;f%2g-Lo` z+_Bfse8RQJ+v1UNfF!7+rI0b&sIUjB;KTH=kasj-rdW{RugNb|)4KE|pnmdjjC$co z6M=0o@E~D98*Vg&|9(%pH&Tn);*(!jR~IBHy)Og_Dj?DaS&+eB1^ObjYKQ1)Q{a)| z_=yx>(qE7+`;3?ohbIiL{~Zw!5E#|3?zqGF+1|B&?|o5R|B4R<9c)nPxRv+C`goxI z`KQ4L;CmyuPArZ7U8J$ygMlfKB>W^+p9EF1fboei-2pKU=@NbxDNz%rh;E}l(coUF zPV*mRe`7&ty;c3Ctwx*Ow`wVH8agISyfZ=*P^)C^Ln1kAVE0aCf>jqW#tKt6^HMKO zA9Cu$K7Dcc`kLM}Ye3=`5%C-s`0H0_RbxYntkLzyxniD)i}&E>dQs;sn&WEZ^3CW; zYP$**Q|>P2vJ0AjD)CTNw1QE6yx>+W@HfJT+9Wt%T-%HW%=nj}%eAIwj_ilrWWnW} zp-w>Hm+SVz@PE2)J$8g1t|2sra-tV%qs?^le z{Yln6&e&;hp8=xmw%BaHkH7Zb>P)EP9T~6pEPz&iN$DAccaz;GmH6gPakEFrU&=`W z>dzsaoe*L+Fs1Q|$oKv9UoY3W+WeCg%G953<|w|M0)F7RDel*V*_Y^8XSy3O_|A(l zlO3fi5gk#Vz5-Wo(3%`5dLM^ZJlLjKvD0~pX~e4lzt_WOQ8F@7QBiQ;PSGgdp=wja zqeD*I#i8oj$;nz<;GNJwrU@2it5tJ{(#KoVIlpgzzi2SHsA%WB0qGdP>`cl{xSPcS z%q!%ZdYaR}2oST3oCJ20ntrs_!bpFKZ^DRmC#|>d6oX68?YLtmbkVLf($#TYs7MtA zVSnx#{$rr7wn%gG-7O|3MpMH}2{p{k)+JMQpMHKBAp(}M<7GGFURN^#_M-ENvWSTD zd!~gptC^aKT7eV@5Az!EupSTDyH^$O zL02{1U_*8gMn=qBtLdoN887UlY#{8TihFQjVC~V~L}4HL(x{VERa(E=8`j0S*9iX` z==obWW#ufX;#d>|{y|nyjE_@Pc=liuvmK1_wZOKF24bM^tK@D6pr<8dB;C_fas+?@ zog7`6=d?2t_1Rn44gcVupIvzhQCiz(53Z6felHy!q7?K?pJi!oh1p{+O)`wrj^e$N z-C!b0ajZi#Gyi)}K?Q;iS9b1N-y=dHTlGFC3}bv%HA~hJo9H{1Gh!~660=_NW~H9_ zFC2W|S9+_CGHO^MWHbANEyFdISrm!K?{C_KVrs8#F9`5=EIN0e%Rw{!YeMa#F|&Mo zYn8U{Vh z;v((`H_qReo|lVmrZ@C77#SOz6A!o?Fj7qG@b`)pNEU#$%hWPVINQDYd+Ju(P#-T@ z$|UD1hz!bIx+pSMQeDp9x_nyGzzswX`VAW>`Y9X8Kd<+TOUkHiCas312j8ysS&orD zF)Aqk{oW+8)jMTIDd6nxf~+`^Jzy8CP8sosDBP2mr+u&#s|Jme3Hdp2${|Ku?#Mg9Heq4}@3;VHi>WZ<;BeRZ`o5=~kAH5T8MH)%}oiU!OQ%a{ifgn!4V znpG5vD@yAL-!vPl37TIU)wR(sj%=)rvC&?>u2W_=2&QDFq-G~!d9HAf@OycOAr2#9 z2rwvKzjko9hf7*2R@*b9JVjPwWT1%<*%P6FIHJz7^|~>3d%pg|s+Jz5Ft^rhFQB?! zda8HyjECBCs{$T7zmKkNx8H1uJxW&>W%f8jWcrp;DMR*Wn8+$DEmGQMP5|@@Q{&^m z5S*Ovy|-E0CG?&+&^}j$d{0x9B>h=PURF)9aJsK-r@6<+Uws}N z+3|BYI5n-N_xNlMjc(~_$s9_V`Le*y%E3RUt18-H>5$MSSWHHHlA)XE1bjWNwAktS zeO&Y2`hRj^PQbj5^%ba~$6|QmS@SS)%rA`049q<(w*YJ)fUb5p7*rIgB?tlLctUU5JN0ZIm|F06S}Adt0*$`~=RH z#+y;;l^+c@F7*?7vJC9JI;Tf&%H{(90>8Nkyv_)9q-bxSIFwfGqQ~tB;CT}T$cn#t z?dVB-=wkv=`OO)6g{9S082DM*>e@{lE#MH38Kdq&QPH%3Xa7lahvpP#4Me%6k>2ji z|82nKA9YdumhShs#2|~!6hMrfUuih@2l9X-ELyMY66c2c*h~6(br#61$OE--g}ZkP z#_=AM6dbOvEYeWWY2~!Deo9JynUfG?I4^El9&_?o){s*_%s!`U;&r)D<*4!33UD)E z_{CUh>cup>Bdq;Wd0jjY4?lT0r0!ac(U6m}yfRa>XYEs!c3b~ap58Q*mpbD0c^mML zFP?;V8hsC&gVW>k)Xr&H&ABtJQDkeUUqOd@)KgGK8p(~*Io^tK<~JtV_oO-d6D#*c z)yLSexF_b%BV9qCnGO$u3(xK^y$PBU<{?EbnRX|{tn$FbKBeTgMQsvLWiMP}J9GQj z&Zg(`T6rV2#M1oGk^RjnI~jSAJ$<174{Xc6b3>bL`M#Ltv9T!V5-!3EJE}LlXx#QG z6D}W{hR^F)A8+r8y8tTl-IXVPF=@SB?TLpm(k6;=iS60$;%bG{Gfd?l0z!4QP3D5{ z`%|42&<-wMEI{FY&aRe|F?pixi{-X1`IyR}ytuBGu*O*=V~Jd!=d4K%!GF&^L4`Er zlQN6FrdYD%i0VSjWnrD{R`WMijHWLt`zyKBQ8a&^TIcq0>&}Sl(}y7sFJ2n zwwJIVANyvs85`R95DH9n=oOl^FX)z{#`fdoROoeA@!B;Z2Kr60SKLb* zx%OFy9yw}S(zM{OG|)4s8Am$q=&LL*W}>0Y)tPVSXS=X2t1$Dft!&bh7XPcPbAMq} z8T9a6L3Eo$_=8o&V;-MsC7ia{Vf!wQPFpKo8s2GPb}kt$@iv-i2%}Ct15LxePo9ua zyS%My0Ko-g>JJ(J9py6%A5+i5M|nEbuy$L#K=Okh7jkdw4eDoqDp)h_xn)sV)%hY< z{i}VZ6sSt5HKr zK5mv?QSP(n4L z=}2)lz1+XK2y&C#*#J?|hAB&aCT|HimUpyt@C&Wa&o8cVDQtsr+A>WlOf%G82Le14 z_6Y(p{3$IyDfMEsZKb$Ge{wSn`+}7pu+Z38IKrqLKz~EZ#|K){@)rdGY%9ok=5qiebK?YGpQo$d zbKm2Jq(`JzPCnSLJp@a&+^1th)$Y-DeC zbFDR!p7c9H7gdw$X!01_Cn49Ndhc>~ebBPYk%)uK$=R9?F+_asH zdFJHcil3%mI5FyM65!*R1sU>j@yq51%NL^6M+@jz%TF=vvqc-_8f=#LP7{yNf2+go z>E>sHp>TCFEqCQb>fqhj-d^113*5?^JtcXY3+$(|zzXd5pgCwet>^fFzPTaF?iSHI zKL?YNdfuc>=$@f4!J@LX;H0)HwbE6i4U56Y&mBx`wpy%y9kWLKlTSYda_HadRp_Tz zXyM>+Lqt?4uo=9tMYpghsTXf_x>(;Eyx3c2jBV^*U7O!r-VkD8;{mpcu91PP{SlE6 zg<%>~a%@tU%EJW??4|bDf zhlxy+<%n(2D1xRlgCfAMjGaKvC_OBSxz zUnW?ndq+o<%&@=ER|mUq-%P))Lj0Zd6%NF>@%$LU0`?;Btv>61Qy}W4G8)hLSM-hV zyST5Bkmc6`jP2YL=i9sSQ{TJsH)Kfr1NUFw@F4JqBIW71M|y|Sp{9jkU}}5t&OD~a z;NF5khV@e4>R@^^f`q@EM0!-$Hz9Y^F>?HAErJ%fOL0J134gxcN2LEIF_OUkuOvnw z%YUf=z3EV()Wr{@|KvY%(U~noNPa6u23({|)G8=4RTH&tR_BiRVDj7^5+;$z=HORU zSX)<&x-fHbva_>tan$a3JU;zWdP?UUn1PUhALk?&e-@IZ%EI@5bU^&x`0i(aP#-mejj?s8SYV`d;k z5RnG-5$765w$R<)t)q*bovM%AuMRQcN!~D*_~$dFkjf@)Uu_f@{C9ftdN=R^#sDS) zHm-$&4?91i$%I*bce#NT%;We@Cow^gV1_07u6J~mtMTUV18ju$kA%8~!Y#jjpp@n4 z_EAhzVp-H-R~QmrnbhE9vqxjxbZvns&sLjdDOT1N`^M|$;;KDPi*Aym<_<^D63Muk zenC~TnGl+BO;g4xK8K>6GZqO*xS0H>=6sX$*xz;UXIOr_{|38t1?g*ep3dHzh$q^1|4b%i2>mhZ)5&x_wf z{a+?pw(B{v`qKz%8DpB8TV{-YUc3$vR`sL=XB_XB%)3fhuVv+U4L?-?!&`&3d+8%F z73*D$?xl`2wMIU0;aY;J_R>n;_}-=5xlwR7L8M_@YwL_0T^Q&q+rM>1Q=5)He%GU~ z8FN=x+p&adM8zyu?FxO#YzId1n>#DpJlryC0f)1?#PsSK?D*uw4VH>DY}33IksKH# z0q)|N1eez5r$d*HWb2IP)g6_^9Ukco@&ob7kvqH3QH({iJm*9z77WQl1Xq>|C~J&- zWz(KU*Z9)nTV9>r?Az;eoFSxnveU@*>FWGoY#i$ge5_EMzuLO?Dt?e!Vll^(qTW{0 z$;McHzExNz0k5D;AzwO!dEhvWxl?;jHi0cA)$qS5ORj~pQsFT({lvs@jTPEe zU+>n^{CvZ^FjU`Umz^<&0waK5zqtM$lc7PtZ)GS2tkT89jwfi%uczFS=fsSNcdf~F zEF{~1H2!|zwqF;#xLH4M&SfW}C)i9~8bct^?Q5zF-E5swE*pSJU8iH)sj1DcKc=li zM0L*2Yzecpzja)C#uEgrq-*wfx;Rp7ue>xTJ5BH#I~0%T?X)%mBK7}q?Y6{g=b6t6 zyssD>gKStXE-!Wa<8# z>(yey3B?r_b58HBIL1464M&B6S9fdT#VVs3bP_;{%^S7Cwp^*<@zvKUbLrhT!uC7= z+qm_}BCC4Y`|GCw3)=Hd*4kP|C@Pb@DnNVt-{PY;>!xZg1K9yq7C#@KE)E6-MTPEy znjPbKr47;S;+l?*y4r@`b#<-T!FOI39@Vr*wNOLB4&yxPWmUN)J9l#qp?+zZ0VgX$ zzhMvU#>yIx!6SqXL4IO(i|nkdz+VueDh>_~pnXkGPfuH08%Uwv+}s=<9$ryV5fufW z4&F=Op(iaZog5Y#3OU=>-p=dDTiRwAjsbLc*C2@bj(#?W*>NxC*+d}SaR4jDmV0tM zcqnM6T;AK*ez}!BRx_UWccgIPe%ByeP*LUMBKg{!Ggw`QOyD7F-#`z7uozM&-IEH4 zl6@R0sN#-dpoc&hnBN=CK*bQB)>6Yt|jxUPV86SfVG-D5+)@42JGgDwTR^wsj95(>WG?)6iA? z*5Rm=+PI>gf%QcVDa@&Q`Y!z|ih@gyScRo~I7(9R_F>@DipynX#C)*WpWHelaB$p? z)~%s~_r&1j??FEX6X6Vn>x(1-{hp>$^;I?)c~q0z-uOpeL~K-1a(Pcrwdqe$l`>$7 z3l6UZoYaZys9J03BuP_w0HB)hV9E!_4jYq4h%#Q!VxzV+g zVT%uw#bGCa_Hg1(Zv7w;gcMO7UEP7bn}>lk?8$E*j!TL|^y@nD zq`$N=3rU1_vS_K8G`WC&?hU67l@@qe{zR|K9S!WR96lN+Bo@|mbb{qL+2^2&gx_Zu zxrixkEw@1j@tgNn+r8-Ba9T?N|M*pMiUjgLn~ zN8jJxZnZk?XF7C)fmL>O5o&q)evIQ@q^(|8mY)*n@N=)))zA=Wi$u`2W^7x|oIl4+ z!zOhphFoDU$6m6vR7CFy@NZrTd2vcXr$tc-Or?AR0d`^a;TBivU2GTPQWE>KUL$hj zI?_&Gkg5I+Y}aOa&sElOz`&s|&RZ|<;M$IeG(|^kw~;;;scyARId>b7r9oPRqLRHE z*FB`b8EavGC%-^vCqIAJ)em!xzcg7BWLTDTY+H&UpPRm)2XEbTICG}j$DZ)yzAzWpbNV3v$I;V+k*wJB z$%7F80w)jh$0tS3}$L-wRv!x;Ov4h=`fO_OI9bK&U))Y?-Kv8zv%M z&!6O68p&}Ch1e^Vs+aL%egYrhGV9QNv?DRG>+@#B#C4CPv0bVoR8)mX=Fgu*ZZi#1 ztpuZVh0-i2n*w@bqU7sRSgR3p+eb1QGOd|umU8a68BW0j%9-af@7i?e*x@eY6=RdY z>et&DTgp-b%iCx0luvr`Sk(NJOUSX8D0po%E`fD@S^2F^u_LXXYm2eW9(RZM+LQw z(4m9UJ_CP|N56&I(9r$McX!EWw)6P(2#AQ%kzN8SC4?Rz z^xmr=z4u;23;pCj=ggV;F1|D8^1JxTx^SG|We| z*Jdm)PG(GBt3%`Uv!w8Us9^mEHs;ic>NL z{I5knoHs~viC-OnA@=rkB!zFjtgNp$o`*06VwSHDo9}lJrFVB&mHs+!P;J2V`PM66 zo~st3iH&Y+JtqjpbeUc0=fJneR*qXCKSh~SMkziD#>1W?{7g@$qq#io zO~}Wl@luVqgWQgZy5m;EKrDiL$i>s;K`4miPt)zW@h83l1mgN=x&7e4i9dC~@)xVY z6P$-);Xfw7V!oGwNH+YUQ=Qnh8iDQxVhOoIhCMLUcSDx zIB>NOb+aH;iY~CN1RnZ*Ksk;Z#o|FNru8+FWW)0CeKz}GO^tO z7dY6*Ae?@;izpyw+zr8FCazA<+u(i*|!R4^KvhQH+sbo-6 zU~gN%ztJyq&qOTOZ6*SYlXx40_A3+Ehl+D~n%=cuNK&j>{Z{kkFoFeKC*K>lw@LN% zpYP~Hw!M`oUgGv4(ls2ivi67Q;L13;BCU_7-!R`FeF8#z5!02CLnXz1K z9-j1dE~$9;(fHD|4rK2syEKZh4Dr=-RTEjcRO_0 z*?Bft`rYt<0uNrdc8qu6i|}IS^ks_KRRKB2TmzsBl!Ddk{npI*bP{qwgPaP(f~>G; z$u~UMwTIwZ*Vvf|wApZ zUZ`RC8|GNlqc6oHBO@`a&|rF~hm(`9trc-NI6XBhB_j*m9rBSH?+0$e_;zo^cB&Xr zj|K17+N#{#&fIm1p*e-u)RK&-3PBlZ>GHCMuieXUhHuI5hH)&%Ryv-$DnH_oPM%B}`z zcL?9%P!#r)}=MYcB-n@b92Y5JpSJHp;u1FIxy6B zn7x~a29ezs$s5)$yEw2^2mQUOK)kV616OD?e;ExRqq@2QYd9y}T;_kESmtl%>Td^S zoVO`sl0_o=6UbMQZiHJH+EAma>N-gwp+>;@%FSK}PJdj2wpu?zjnJ(~?5D~*tT0J1 zgusGeV6bAormn7`rshfY7QOq)@l@EQ?cY8Y60&}>C78mwruC(r?MF&#z!lz8!wlG? z(A(NDc6SYT-r|Q;{Z>RM%7yj!k^s4C5OyhO@JqA5dpd zQ-J)HT4ZwUTz=`weNk%dkz!>X|IZ11(c1T;@SNd=cyn7q&2tes4_u3w90mFZUnC?+ zC1m!jKpel#Gg7Fn3z!RScK9Sk77gNIN%2=8iHiu>8N-9Hn~jew5y}fw^848iWcZ?H zs$fmbAfh3zcw*@vBYmt{2!+LRC&dU0Ys@Tm2vWMjq!AAm&^|31hr~>2HQm@Y5Qw z#k&wL^UVAjO>>Fp)x>lCMO&T8N`7pbr+;!g11?yhD0%$(ekho7_K6cS}2`f=0o=gG5`srEmBseaEQqdG6QOp@P~9;UM|1&QU!EfABCw6yj=B?K@F ze=0QJoc0&wBkV|rQ)*ake?F}nhX+2k&=3QY2XOlY&@H|=o&08;PWPpx?yX;dn2+Ob z$#xZdL6w#L<9in|U7udw`}5TKgq7ZEGAUhKF)JZrb}?CLc*kf`-@v^fRp47M5{`jp1`k4rpm*iTspXTuuPSs>=_a2GRjtd* z{~6osn^9_gpv6Wag7TW^qIGA-DGpfOOiBi7Kk{iJiw4LC@Slml%@*h(fAQ58j z^v{CyK4Kkj7YC&MQ!DBtV8rG8{M7`;2I*+j#Dk}N6Z#|kE<33P?8TakUVP;G;{rl@ z`XflEJs9o~8(FW!*#1@IyBxX@6?R7;A?t`vLd$5{-~gf5g+XszAfY&8DawBMQ{Xs(sD z18T-uTDdV z{cS}$sz?5{Z`(&Glaa0M)|EPGb+t04Yt9DOM@-Hh=p(kR)VtnMJYN#>nvbFp>kUnf ztikz)r>3U1y}gZvn<5YhZfT2os0X|ohZ-3Tdla5nBfHx2L~rOvQAVa z{}t;D3Cv}Mp|h)<9?>u> z=MOaXUr5Pqeeyr&%VtrwvHT)?i@Lwbzpvq8h8HnoG4;2}G69{}uQ)}^ zho&D_|1Cd?>h)P+=lrd`Aj~f?=TP{{ijEpa!NAPP0$Y?6l$o(D{q0~$o{>cVlDmx; zluMEcZWNU=N=nz&F<7(C2Nv5N+U8#lq89r&U!hGd$#9-fSR5X}6+ZE^Iy=0F&obbS zu%IZ^>Nr0CC>Le1O)yB^;eGKZD>Gca76cxImF*zRVQ zq0ClnjW?s(YjiqL5^CXXJmbYTOz#_eV(yddiV%4#;ZrF`M5b4M9_=Viyitg7?mvo_ts*Aln&=ceR{e9-Q#YGM1!C@tV zp*B*H&AQ6*^@fB#KV!7}*cWdMF2-pw?t>7|E-jPY(C9mo8n<*1f%e!L*{-(tvg?V!75_ZtKFSyxdbE9guusTpG;m1*c212I+nYahDv=5gblblMqDprS{GvfiFYDBZDmxCJgamoXTe(-zUFUt>aZvx` zjDLhbw@ekU6UA%$k|e_Hi3W3Aa@Xu!)N?0rrC+#z zx`XN1FmHuk!A~{X3ui-fdy8E&XN%Qs7}!&5WHzhDzG|OJc&%XA&2`aZFXT%cuy@ln zQE@adXjfml8Ui}SH`&_|^eP!n7IGFrXfppRu+(>Z>N_<(I}56;a#0zAlXwXhx!&(V zq%Xbnc_GjAt)DHHWmN3I`bQs0?(Z>VIMUOHuz1ZoQ!Q{yAM8_^wkJzBxNvnWjpfE!*8%tuR3jV#z67q;~&#W-a`Fw;Rp zZ9}YEV=;;P6&Hc%()-hVpYtYZ(`Zl4IEjC>vuWh0l8Q|0&9YBT)@GQPs{LCd z1z(4)@7Pv0Vh;%K34hQ~+8n4!wG@hzAKg_`GgDVnCpsnOJeAOua5fIsltoIXMU;jg zrU(tjb7Jv^&T@^JAtJg`SksWTeP_$75VHnw4s&y59z|GNCD2)~C+$*R$cIVeH7p4l z3Fmte_1aNcQ`$CwM~r*Bpc1L%b*(N<)$H@rHhlxT zWfGM6i_s@N(PruPUm?+$$y+II^t%vkIQ!+sTaZz2XD)s>r>-qh zVk7%j_lH~!@J|y&M!*JU(^8MoVcS|e#>6{q|5RKy-zbF;MkGRFj1YL9b@^;M@x!v8l7BEkzzJzsVe zcskf-_8RG1GZ%Rc9()ME^!x<@vhmY!0fMqfz~`6$7C|Qv;G#vL2jKHF;oCu9I8`{W z>%4En9tEmJmGOD4L>A0z;fBn~^nKs}Eto-{>@(Id@IMnaN72uk4_N9(cCbwoSm zWq`1?(}ZLB60{4wHT4f(pHvbNOBAPNQ`g}LjQ)9Jl2LZqjNMp23`ypJFzz^6BVDyC z%t>IKfR-ND%_WHb`oTRa=+3ftLoo9=C_pBq(W|N+@~I0hu;?6f(+}COoTEH(rYDU0 zUa#%K+0)Byx0`c2J9)c33}Xa2{Y4k*;dv_^Y7D4r8PSscG;z0np5F#&>2SpkZc3mH zCEza(_EVaA5VEVQ%e2w=486X!2zdzb&wf8j%)`=bca_fm+$&QGGB(;puKLISqX=GT z>&?{@w$X0MRydNXlZK52U$`sx4xTZQs)c2^ub^>S6Gz724;+Ma)dL=`Cj~=N|D<4-jeo z{_gm$;=AD#=)*5XK5~YtbGOIcVxH$}sNDI)a>wsY46`BwZmwyEdsw#Hk=tZH2Uq)o z)a>TWY|w$(VWa1yQ0tS@dj<2h1zgQ&!i-FlBxi0%ful2CZ7if{Y8D$&-A%|`a^4R! zSt0{Pp}TuEEuFnDKkcX5(ZEM*8w9E~qffvY%}4ly1v~3>T@@Aldvo)9bN(`@<5~X| z#Zb!iHZ!O<)E3#(O`o+qepeiq!^g4nc*?1L32WSYglQXVU&IZ}Jk5qt&?#Ox&6e>u zu?eleYbngsrLDfe^)rL)tvDmKHZzX!XIe-YrtYiThKZdMmn?$b-dS?%;diHkzW`+m=2@1&!_Ybp*|E^OgF}k&ibsh^o4S5KWDfQr-+|8YFW^Ff_+|vYd z5#t}5l0wjG^`9b!soVl4nSiy)7Zw@|gXexyzl#H$vtHnZUSb6N(iOh?&)AJOl#rgz zQ#=(;=r>yR>JsKQ2JRuqhy-nWiXD))>rKjD`P%o&j^c~*dRJ57WC2$BS$hi|s^H0g zTusq?+_mb$3waj1^~8z(;LNs4^ExfLVKWM?>vzKE2HnC~Egb3A!BLeiLz-$<-goDM z0aAvF=+$0@i3rJgi7C0s^Gm{y)R;|Bf5khJZKZf`kB@5alhsgiut8P*nV(S~94P)UneTS!X)oO$2i_8NGAI4Q(|G3{VF0P$nh3$2KD? z+4T`%=MNu4G3t| z%xAR~KIGR22@={UrRnmHOlLipSyK^0n~GWJ3S@sAn)JNha6eg?ESi|mLl2wUk6}5_ zb90fNdnnQLVQe;X*2MpeTA*}9e--ZqK>w2)i10ZHsLnO`rCiM zVuqwvEY{OYhE5GbYPi{(k>L%n)cSP}e}_$H3E#W?wuA={mc3?ji@jWv>v#;v0}6CO z+Hp_Rfj@-QCh`*@(zTOL!MnXbDDpm>nTRDX9guoguLP?WAM7VR5tqPyi_e)B=a%ZGR5ro=%BXOXKQt2i%Hlz%+T_KMYr%Uk$dRZ^-Y05l&SX zr~R16B42OD{iciYnv8PS7$r17V<5%6Ep654ebZGk`u8U_YLk;n(lilih!xKc$|T4< zif77xy3Q@R&+Ws?JUBD3z=lh0vC_MJA)2umtzz{lcDSUH={$_r@OW^U@6qT99z*zWnGCq?q%LVCKM@ZJ!vQ=oF1MVrneD zIbe;_ygq_1SMMJS#dNCXzWuGIlYD!$-sd4UY1cdXXVK;RHaJNV))|{tIk7OuM76!S zxv{%TPEmiT7f`RtUD_0P@3Ce6jHx-1j zA%wuzpl;5qr9Z$c;c)!Hhd}wj-`8hfc@mqnoibTtcWI(b@5gHL6QlyJbP(f(#rhBk z6AJOtr2M}{>EVBY0Z`CF@k8*(wFm$}{NK&T{dY|B;FTPxSsohzd#NaB%9p$~3;7?O Ck`mhh literal 0 HcmV?d00001 diff --git a/windows/security/information-protection/images/kernel-dma-protection-user-experience.png b/windows/security/information-protection/images/kernel-dma-protection-user-experience.png new file mode 100644 index 0000000000000000000000000000000000000000..8949c51627bf76c26781cb01f3358ffef0ce0d65 GIT binary patch literal 21128 zcmdSBXH=72(?3cP5fDLX3etO|sPrx%RS8H4y{Ysry(0o5A|PELfPfGZdI<&PmkCCbXc)@qmR#Ct!?!CVXyt!sAuOW|zR~AEd_L2yAPvW9#;D(2H z>*v)Ue!FwN1s9dFZ(dXmrg^?aA%ECY^N|lPR&v^hMM=>bJsLq7zYd z^6kEsV`V}IcI0D&<5_>~zTe^R{ldzWliSVsc_!fN8_F3X?fb@xlq^pOSo%4hyt5Ie z576`255SL-9f)c`_Th?)adqeQ>_TQ%mQXzpsHLUlMbI`8+XJZw4|ZAC&Ud=}kFk9Y z_yC6%($6uqz2HTo1uVTDXg7vt&Jy z0gjFu7x(`AMcfx8n_3U^zbmjQYd~YaEz$ft>~>BbQdN7G^xt*9-$sDqF#d$_yepyb zI6Xyvz`=}SviZ-5+Zz0i?Tt463n9@A&|p=LcT?P&TJ2K< zV*#7KD_K+~W>cikpFi)Adn^4=TJ(Z}nBtw|rxwA4y<>xXV`Zmz7K*{znAF4DxN`olnT zBNX@7neVX{p~IeRzWvL*EIT`Urk=30cOhhBh4%nvUk|0yH!};@b$dsNTTBzxIPV~4 z94Q!ebg1F!NY$6VXp-8}4+YItQ!vs~gul5hzWkRJUsz{nr=T+t543!5hwZ?`0a0wP z->w!g?2>h0)^Jaq8hN7_npBjX*_VMrp@Q}|>u3{^+nTqSKJoFf81?Y~-CI+uz`zS- z=*(>VLH&;pUg~K$hSaZEzLYOtzU$t5&ZTqv8}?)B6F%Ay-HPDQ6P5Pp^JT$ChwXgM zz^$TcI$FBef+fnoTG4kWO1Z0m025>6d+r8Aa5sK z;<@eb{z4rvmEMf=(~<_eM>em{CY}kN&uT`u&AqV^(ffxrDjW*2mB%zO2c_e&8fuU_fwXO*r0nS$XW4A_ga$pXO%c(?=eJ2nh*w z=*G*FS5#K&yhtBDD#73vtBJ1H+Grdc;G_mx+=GW`OoMf3_zkxf#>t+A!8$vMHxEGS z@bgVQ)nDb8d1u%wcFOWHK@Y2v^FkjQHqJ)No@Mp$t7Q6H-S|h3ME2JVtn=;8b{ftn z2@6?D&)#Og^FP3;K>IS0-6}s^kZ92iy}7;^l+5{%ok#Dj`JX!53Oo6>xH!kzS2H?- z{l7=NR;_vgJ?|9S5G!~=Ir`S{rKM$VcCBo+0u3wbW1em)|8iQu*-3Cnz)$v8{RNJG zU%$RpbB)7L+ISS3Q$>EA%<*X1i5vD@IP2+`?2NhSPj8uIX1{W7(hq!ny0V$@0o~i# zHpOedxB7@bJ0g3UzK3LBQ110FyvWNxo|a1OU%oiqOBg`5F3wQeLaV|egCUU_7x<_2 z6=UrgZbdXGd7H$q*Y!)49fSKeICYyZ{_=&w^f1_pYg1^CGqz~C=8i>mq9x*e%s%bWKgL`7+~Gi9m4mZFvl z8kP`V43SbkQ6=KWs*WurUTZ{jM(1}cTQz)aaOF13A@~|*=H@=5wC-e zty}NxQ3iokf~;A25I_%(>Z_-g4Ea;%Q>9Q!qZl@w*fdx8d&oCVNM`j80G)=qE*`cZ#!BX;BtHNLQ@wxY<`s)D23b{WN=&cM8yn;oRYaOR*p1g+<;$*ZXjaSm zDDEYL8Nl+3wP;HFT=<_X`d3iYv$(vlC}=@ciPF^Yy5Sg?Fc!ePs8M0&RofF$XsG%s zVphiq0?h|x&yFFQK$1xNa8+EH3w$w4%F8cuPa>4@iJFgNz)BOmC&|-=OSK@~WU`@_ zuQUXBDxB{|_u6{hnfnV5q#cAyC*w;TgwU%6sTFUs?vbXU^a_-oY7U`IOWOeECw`uf z@?qwC%|OAl_QSs-tGZ;GLhr3Db4b?GVadYR_ifSh+CD2z&Y7B(z755_K3N}++NSC` z^@=~B!<=L*!yqDQ>RHHYFgcv78bNJ0*E+@LXh&<8Cn^Gytg}F^wk@@Bk%`kRggKxA z9a5Gz*R)Uc9e$D(rY_I@C|698kdV-|;zw7{@UQ|2^q1IS60E5BjgP$f66RS8LO1Q> zuLKDcH|(GYqL@#crp*IL$F7Q3$#WI)5)zvx3tIu?#ALLgSOKu|DENJzm;l|9_BW<) zSO#oxO3FRG%t32#mrLk@O5^}Trn4YslD{j>s4JJQaJM>wZ1%-&opzy$4QhJGut)7` z1C9I+P3;}niqJi-%&Cz0TWg%~>wYaQdC!5x?G!xvT1_YO=3bR_B0g#;H6d8quQ8;> znDVY1NEYioDxw{5yYagvT~f-cu_Slj>6Fb@#FgV^yBie=ScCB!w(kMGva<5R zd*8^}?QOH(Ibv&92EeYoG6YHCI8oG%L|4cp0z4rpLgJw!iVX#EBBex{^Z2T&#%Wns}cP; z%hm4wKEMCV+s|{y{ax*zS-3f+^ki8s`1=F?L|osE+aaxhC`b4n(a+u2xiJy_%zX86<7<&oH7juNKn2 zoK&cQZ6E@+fqbFRKVi2=R$70>{lxyv(s}SxxX!*M*lGu(&@cGyLXt}&9PEZL>EjhpfkbDsI+8JNa;`>^@&3sGJqhocTE{V!lL6=F znV#JaPOYtu;7z5xN9?N!&4PX9)hz=@(FgAi7oSKusYi@8x>%0BG}BGo>Q`+G8oq(HFy+=bzSo-lGsvcWP|udkylS(1N!J>2;RFTlaK z-{#=@iC6XzQnW^pzoBHJwBfPsSn=!n`tGl>743VgDD*SSI)NwyhjBeS?T1flC?K8{w#|! zmSbD4EM;AMY2JMyQ+au>JEHb<@kPLsC_vkj^+E63uwNb1zkE5`(VYqkXQ^&(H=!%g zWqbhW?uU0x+ukq(EKxgZNv94DK5jL2wOeu0U&yOZ^r%xG2c@XAA0#JifDlqr>Z`oF zYpzxRHS&&e;r&8f?Z zzWO7fJ~^{*+nF+#1jmWJBpLpvXXgWNYW#|S8TRVg#8`@Y9>?G1drkio$^3ysbvMq{ zu?n16V9B&7q!^MnE82!tJ$N%axwQZ1T~oTi{ju1aQ!eLaTU3^t~ckH6~1Rhys>V%^#+Q?R!MFda4XuD#6yDW%%$Alnko7|-f0 zNmI>RQ&35PAxNrX5L+7fK+aVA@{MDi@rC!LjMY%Y$i7Gd*lFUWbI?1@$XjSSFyjxg z^0ni53rJ+I(_*w-O9A?-YJfW83c7&W!u4_ljI) zr|coEpq+$`A()@v8i;-2kF@^AjenRq|j@OtnPEr zr-uBhS9V8d>a!RTBX`>{(NCMD15pwWfo7#Tr$2@tfNjMz417=YEx*Ow8GiP9Cr+?t zSKlntbuGbUKUZP`flWvQtozMc!ZKo#Aq2axoonyVJC7w>&?#p>@BBXc0H$8Es&h%j zxnGhzY%gkAv+Ba{C-Izjb+3tvb7S9Y^f$%+-Qm6OkkuoEBko8{@V+2!LfAm7_e4(i z@}jfPsa6B;V9}rEXGCP#oM#^GNl4sDi+`$`j>#uMgn&6;<}bvY-LCo5?+{6BxuM1` zH4uuDtqUqGffLL~0Rcs(`@9WqFXuz0ZyplI;CE=~4&?))j~T!BqQWE)2WqsUf>jqV z%0Cfv!?s&vulW>dHl@3kKCO*-TcW)Sou7y&N+Tt(-v5Fi;G#}R5k_db9rKFGZ_p+Q=0c)QQ76wuS*<@( z$h1_+pYt7?0_RKnV!<2Tp@#Qdmf+UAjG6(Mzyhu(@K>(W#+`}p-CUq|cvikPkUHW6Q zOsP#r08VXX25s3{D$X`=U9ZIV2=15vZAL4EX?2d~x{G=azqXACpOhAlpG z#5egYn#lvBC*f6$|MWw*!D72VqPPS^7(ZJ|<^~;S5(H3G#j>F@_L@lnw(WQIq!xgp z`^gCCMiHK(G^{W?Y3`q!8QRLDx}5?C(ah#U<1?m5BE-)v5+#!#wJ5C7e#RNZDI`Gakb+N$KeqQV z+f)G#D|)JT$eh2i!l$#S;EK!Y;s+3QSsH9y%+d$k*7>gf@u!#d=nhkjDBhL|aKPqD z?v}J)(;O2;d*7DNVxOsu$!Pn7-%^sAL5sJ6Loy)*^{&aOALK|#XV))$)OGxsjv_%K z;(E^nf?6J*vDxEH4y-{)5k%fc4fRoK00p5N?t1DSROTr z=p;Bl6|j%$3dAG?POb3q_j}@W_4D38=Ve92&%kyT^r<*7wB_nY;D=Zhjyy+u` zZSRAAxGkK`;_?!up2-y1%A=@Zl;1|==9c@USaRR4#yhn0K$FBx*+{wavD(R#hZ0ss zWas?CS^mXu%4DGHjicHo(=3NI{i6xHC=XCt=iwV94&Si>HWUzh?qP@2d(QA+RsaKq zmjn|5a7Ni65d(j;Y*($nRR0sACYxGh=7$hZY~i`VcZg;E2BC69nyfE^)00Fsk}~p~ zAximqdpZ-68l{N140=%wZW-*)5OD6&(SXr%<3+b=q^mTuncrq^P~GV@1_42%7KsyL z@7v6JN&ld(y|r};a`Gs6&kE0~gWpQLo}M0{qZ!gePGdhTvTote>)F)c_R`wBea@^Z zGTd=gCz*FPg}XeEKFC>}U85uad0X=X+A{p#?YAn`dw3XxIUx|p4!JFGBo5l$AMqgR zG)GoQ?gt}zHEj7lB|o>Fl$&Yz;rrquF{~bP9BKYxC?p)DbzhlWI6v&O)C*qfoLVtBFkBO*>mWKogRt4A6NF-iINU;P{f_x@VytUEh z^O+)W(9n2DO-q`;U|631wN*W(I!nN<8Rn~}7s$V_< z!|z4xUD~VWQ~cPCwqv=+C85@LZ;Z9?Y0#56p#wv4sP_vpKRC|q``e-hi%y;ZTBDjy zMBB2qzU;VnT{?uaMWDk?%Ik}QgL85^vhQvGZJA zJrG4{Xd*a0?@zhnhG{)~oMH6`8^7YzR6whxRDK@&KaMqtNUCHY;V~TDV(o;9dx@ig zk7NP^`yN~#K7b?0tfoI3|7qT@V$N7U$}S!nF3fXnSS8-_Y`s)UJsf>Zx_O5+;(j>K zjUO9NO1HOX$=b)n{ibqCV-GbkO2=jnEcdi_2hj+GV~_f@hkC5p8HZ5Tj(IfohC^*8 zXxv{4j;2(u?0wnEqrq@2a9%K-ATp(}rY9@rR-+w4JTwGy0~Ofki1{U4kljf$(a*{X zG3g21vMVSuSS{EM%8*XUh6&OoRzZ?}=`2N}H8dW>HlMLq5{(87>wrZjH8u2WJmsJ? zMaMZ*a;i>mZ)dZVV(irQ*K!9sS`h9JA?(cGF?Np%T#!*3sL1+SNJRyL4MSZG2H-Mz z7On`c+(IbC+hXqnN;kjwGgA}vr`w)u>_(Pn=CWWPbFuWR6MOKxpr_ZXz z9SX6DS-M!gmc=#du0ZRkY6%!Mkfq9!gbrnB9E~9ovd`=2z~__JX1W?bE9y6y@4EFe zz+F$ycHP_H-IYHoe?+d1dHd|2-4@-9);z?u=nk8A>kL}*CirLHWCn@lzkgttdsy}@+en*ts zs4Xtb)v`=t$ou{yNbgH#$BcL%0C>yrR-&bxh9}oSjQx^~ixS&|YW1(Pch98=36T(` z8x@0I4M1+mHcR_^CxUvpI9#%B)Qgp<1%cUS1TE6cf7&#)J&rs0{i9AV9i$*;AA9A3 z_ue(}g6UB4t&a2({Ua)51z;N1ZUCIMqu)L1}g-j%? zN672asqt|oS%7H3C&>dVb2yRIzQ?$K;S^vCi3wPernk+ffJi|FMK)I(OG$fUREG@m_gQSMpO^bEM2 zdZ_`;X?zA7S&8+1Aa~`zT%i*)>lw2xN2_HQQsc$g5n-w*BdJ zneYcr)0)Q#VD`)K-JeNf$n6%D{Sr60p@TZB>(HdN4xH;7ob5qw{|+XL-qh){PXboX z_lMPsr94mYBvd;n&^JE05l*s-*&RP1OB`g1`s18G3qF7TN-9g+y9d$L)fKdJCh7xX z7Uw?u6{paO@W1y`^J2tad7QYp_A>-u&^)&s8mrDTngHlf;9M?=ct@-SH2MD zzd!R@9U|#b*IYa}m(o^N5amJM18D7-{=+xHFX|uDmSQG{d*AU|ql`~!X;w_Tlq z*|SLgg2gN|HQMB_V>`I^^RH6d{Eq_cPRXK-nUT6pEAr17w}GU4R2ZaUKJMFVa)9WBabv z*=TzpOA$xR)FXjKSD8cD_@G=oI&W^6*9*5cnRd7*?eVd%CTCK3(O{KZJ6BmZbw!6= z6T4I)4ecKL82#LSByiuW>{t!JbOFZ;%Mo&k=yZ-lWOe!AQs9Co5Lb>Y)P+oU8r5%) zPiaD_^Xs48{8=%fDS}9LPHTYX#Z>r2-cawqJUXTbg*euoKEDkXaX`P6xj2#Bm#sfn zG@G#NIFe6I04BPY7*QyT)~U%vFCc-bXe;V7?Sw`}UcYuw*mBeF4G`MU{&l~W7A_Zd&L0!DPJ7@5ouJ{ z^|_BNx4;H`&GbL=Uiw-^ONewr@q@<@>m17Nhj~eY>C~4ZSLs8dy+*ZVHMiZ}%Q^l! zZpb8+gKFuS=A(>-PPU8RKb@x-@88RWvE6Q)+unnvR>oo5Ps2ImKb%oou~*2 zR+uuvGI#IFWj>I*Bg-0wex=}$$P-o~1@(X@H)9D)X^khzFNeFN=nK;k`R$$j_4mV zLKbs7s$R!b7-fjDWxG3{-2WRFo-GUDTNczd^So4?OJ>fLF90 z<$BB?9+Bfalt?iShr`shROB8@UQELM_15)%F-yA%_YZ0uYZSMg=e?DE z<>Mn!UfMtIkydH9N-0BobsEo+blJKXed_J&BpWwp1&T#L78C9nN~}%$kU85{#zTkQ6#&!@e zT4AW&<5<($qCde>3G6%v@d83l-m3(z?f;}bx47@CfRF`&;+~zv^ASuq8hfhy|43Zo zG2pGUvnRIL+0xju`r4pdK%(}81SH=?WdFH zV$UR>sMB=p5{L#auT2g6A|NEFFkTae`%L_Ol`Ze7)4pHt#qjVySTfqx*#wIYeb2Y= zwieU?(p1ULbZZG!!{H&@VP2lc$)UbElBy~3Z)D8tsD2qsB!1oeQX89_t3O>I>zuq^ zp~{n^RX~pz;``2PX~OX+6YAGbDxU8)8u!DP&<}xiq|ELSP&@B!INxWi-ijG|BlA<4 zo3n9`ts?}Y0o>?S;xO6eh#Srl9+6S$5d!?sYlfHDj6;6(w*T3X%oeOcTf-pXZVmT1 zM~RlE3ON`^x;Ao+`md8|p7*ESICy|e3~p$C`KCIecHE-+#cuF;%Pb-VI6{qpga(k5 z9G%Vr#*(VY*J9sNme_iVLx}ni7kE7 zH`xGJcZXLm-#i-g#=sPr*(A^PrNIIvh4%iZLYgv~$A3C|OF$tq0U;bZlKJ`ZmR@Ob zX7{^@Yjryx#Y2Yf*+HX!5AJkW9?w6Nas}z-TzJaHYjmWvAXHY&%03;}+qT7ky%O|@ z+uCxqhB~!&@dG#*9z8LP5-@RgI8F>0r-<9)`%ax`_QhulKlg5yND!*eh6)DK%@&M* z>F?&;xp>mQGRndDV%_w8$g;rSJH=+0Bu{#(4TK?Ud<=8Er$eC$=)=!6D&Sl%93PE3%Tf#%Dcy*2sfX8WJL1fsOKS_@ zsLl?>nDTxvm@)1{=gvBqx|{$e4;W!e#cgX zDQ$C1nr&OshfBdiBP$FF+*F0r@U8HQ^xFa1cgG${i3L?imU3(ML2&1RA0?8^-)jkh zXx~4KYY%CceCGV#ux|5H?5`tlRbCyH-`KaZ26i5@3YP;WG64&Ig6H=?f49|8!20>L z_nF@L+G}Xz@#ti>2$^n+b==<9GxMw2!*z^4O${M*z2%0pE&>uz@?b|xu*Oi{M=g|~ z_sgI5V9u2SRkM(=RwdlcPT|JWv){CYK70)o%QHF78O#h670x#_wa0?eEBd|SZaFO0=XWL>kzz8SRFuM7>#PM<5g;hJrw*VIXQXtR6U|5>En^^suq2 z+ryM1VlzN;8js@iD}$kdJinpiP6At>wKn99NYW}ye29Pl`3fQNRPHOm8_H5dw80mf zw`BdgUu%w>0q4JqbL+tJ%RSU-4qwWv8XeZn14O9Wfq>QVe4! zjZLrMV%&+DhX`;nTKG}s0k3X;u?mk*9moC(whjG+iUcZc-juQE60Svr$y!Msd~L8K=ZI@Cp>kDoea1)QH+aM(%Yoa?LDl|ym>Qbrx}0OwUQB4Ij`X; z4&41BAwm_r6sSJ|uWtLhe&dtmS*p-h{{hO{iMyAO`23Yp^3i=+*5S{d-b09ML!d@# z2_Y#l(R;;?n5km*-A!h>Ae^sB*NsL=URT6BGZ=>r z;TK&!UD}+1tl3kuT)rEHGOt)$U|u^Te1mxio14O zivBe-j`Sq63UQ0`H)OBXassm&;`V@iF6YYSlP%wsPZ{8WVqKBTu>$LheIPg6JLDX2 zo>HGsbFuCwX!vQd_p3(k5w|9DcGTr`#_{T^pxx#qvo#&}@uaNJn?c6<+iL-pMp|B{ z*C7+TLUGSzy1|wzteOuJrLlKg&|H;^`~|NBTYX0fd>gu+ZP<5lTo-&l!jduS*4Ym+ zvWd@E)IrfZZ2ZtNwGa_o$^UM6`$s@^rf2gkJkaa9BkV4hvRQ4=MO7UcL7HO1u88t) zn##KVE9d-DD;}`A+KnQJfYRbJaBqD?a$F#ip8FOeaR9bF{Yt(@Ni@ZSV5pIs8lUvS z?c$glE*@DHPY2+RfF#4CLt;lzs~;Vj;rG^Ojs2H?1Du{{wQ0(#Mkn0oZ@P3qQq#g9 z!Ietq?!Y>xpCvxO4DTFz=I%4MGYqvA9NQU0ytmm2Rj8eSra_&$1lcOee zK9-@wBzSJXmXC7d&K+gcCCun<-kJeBK6|c74iChP$_mHFYM9V4c_H6Qs+LzR=ew;z7uOynHD+#QoA z-&}gvG}qbDTnSJ|Jg$oK{iSc8g-w0GL}eyi{zHpnZyj9|*F5x$(^5Dta9*P zfx5Q@QO}4S_+lcBWC^!knREDr#G!%_kFsaC3fm^%jk6EBy?Qqiqe+ua=ro!8qU{t5 zcHK{)FBp8QZKFM(7+Z>L3Jdi`w8tM|4bL+wWwTHb{*evemJ|efe@WCr_OUyeg|lKU zF{Nxj&pJ7)@YDkI>Fk=jY%D@-+)k9MCO1yONr_~;RMS({mleL2l_s;KGKQ33pk{+e zE{^v*#5zoC>=DFamJW_9Wt?}-W&ebE%E-g}v4N@heU-MaPKGt@3$drapQVAV2@_t{ z6|t1oz)Jj^-im(rHq=vSC-Mtb>(Z5T&YYS^r5Vfea6viA3&@##t~Fka8$__RRz{as zrMxyQk~BB+zh-7G;J<672vHF`joK!l@$F`<+;*?*k2ZEj*Rr@2&oh*4oPXyszjuEo zZhpKCk*X1C0yCZJkg9iAe)L+7z=G=tnMU)QvYWB?M45{ z`egXLf=yza+#s%J>bR#Uq9EBoiopkYBmV3;*z#a9Fu`N)J_CI4)ngfv>_a<8o_>t7 zhNDHk>u%&7N#wq0>d4)q~*^9H!}SjXPXHcvJAnV_TbDY#$~{r>i(nD`T~ zzrOhFt-pI|Qi5ep*;*!~<)Z(Xh}nyGc9YncY%4rV z4qrOWTMTJmY7H3uXX6=7Xhv%wHR_h!4ivc(cfb zuxPrnxB=x+wW-`M^zq;unVv2EI={+vpwhv#{4Hb>4`yhgwS}C1hXX??#jWKHQYn#L zYxB#L<6^@dXYV-ncNBl-jHK6w7m;}Anwkj44Tg-dSJFqex5Gd;&WwmDPzN@P{&Yt+ zbsmSLiEkmZI-i*nGJTykx}D|Cf4erws=^kC)UvRD_PW2a8)CyiLOLa%F4d_d3x5rb z2K@99ym9v6lp?g&&luY4Wi+D$6mt>nq^xYu`v~0NLm%IosFRbG;ADDeKF?ae1tIBz z4STcO8}gTsE;!qKIr7Qe?ko*=)`P!4NRAdb5cbR3zmXn7XRHGwV< zz#{j?r-Tww#`)zi=iBKGH={n)AHAgUX{~-!ldbko`7p!q{H~E!q3g?NQi8Qb|8}mQ zIKt~Y?B~Sx78(T!MRB@aNLSH0Lt}I18oAz3T*$WBZv{Wi=Cm3mDgcwmvR0}y5V->44?~x;G`pZos3}DwPA7&pYY&U z24BSTA#iPBW_R6F?X8(@UxaS1mP&gMA#$MWSw3sN(#j2EePe&tx_3=~&nqW?*zG0E zf~LCh05`NxP}sf=hW-^?bl`+y?yQoPvJ&B)}tCy2}`Kju)f|6gz51t>Ak}Ma3odhU8*Z9wz7?>(|dmj0tn2;j5=h^`Hz|5E`!d_tJ4?X-qbr{8$A7ZYT1?Zck1d*-{I}tKP z?TnSSU#=;JD@mA1jDv68!efbPLS(%2=<}7IX{{tB04noe z$HzmI_vQ1*_hfiqpw!0#Ol(f=bU82uG|j)gPE)j$$jOaOG$}l#KR$X@Hu_Y&=v@8buBlNq623=%A+gPv$g^_?SQ>q*(P#;?Wb6~@^?)Ui~fk8 z+0iP+1P1;Ih31cx6Q>)Yc;e3+IINc9%P#vWvH! zOTMJ0hWf5rR(6#l?H|(&xz=A5&_P^LZQIXegN;SaE=3K;be=Sr z(cblCqF@H4#g@w*?8q&X`V9SEx^@wlJL1^+KeDZN)gihx(jNSnaStQuGI;WC;z6>gt0B18kZwRX6!nRC;}1(1f~-tlz7c7v5LOCPZMcFSDc@d;ziW%3hiY9+)Y~zPBq8 zZkQnHjvMB6^xbh!`(7FC*~{!+uB!4_A~70wv{T-#H8A(}NfY8C+u6oq8qUA=9h;!} zMORD=Zf$irpQ1ZepOdvqh7trGw+l@DFnm4i8qhy>ez*x-mwz;E$G2Kux?FnB;OlM8 z0@r?)gOYC!hMb4FApP-oBL4n=QvwRc*V3BN3BrdiEQ>SHkaVLi9e#OMuvZUJ4>D<;;04l5+xv z;8uiNu52(*9 zMr^OVF(jSs)G0TIn=jy;XoGVHo*M~^A~3=6>UBdNsw z9n1iSsld;>xqJgVtT{Q{cTRlAmM%v)C+eppfIF>T6TZF5%g*4Lv$G%mByZWTwzMbV z2Ds;r5q$h`UuNU-w86@KPl{^*kw^7(YUX6@=FUIT42GmP4wJV%O+u=?ajbjQ)cWSP&g!fVRDK?`D37EGORLbC^GAN_tG(7qWj+a3HXRRXz4 z{8i0ed|Pd5N4=WgVlJpK6GGLefVP0=a_O2M=)GS^Xu)6-{2B1T`2VQmA0ub*yJ=s- z|4+(#K>+r+DUMYG)ZxzmgKg~ggc&hn8o8BKD44Q3*)c7yq;KC5T&*WE4YaLZ&V7d# z2>QPh?Gwaw{O2ny{v8OE19AMG-r&C`_m&f?6bCe`{*TqA%U?B<0$r;AV`|p@SA&3n z{2%+e>LA75`Y|RW-b6ExZ4i-9?KWm@`dSSadR< z)D&UEqvLP-qC>N!kbLiu!r}O5!M`j2iGXynGo+l5FFt{iMgF)(26 zOpSmxN?-(EzXFb^MGQP?Y-U!1I7C4-gJ^K;xIE84irMO?58!w_Jizw+iGk>i3?t7s zFhXV`p6;FyDHctlCcrBM%~HXgK11~M3UFten5td@yQ}6~z?Gbb1;J{|YYoZap6)NC zfTmq>z!3pn=JFbh^ew;!uo?S6gDRdl(AN9^hmX^EVjP_KlTB5>IFnTAFMP1HQhviK zo!Umc;bZ`|_p1Uri|_!*3b;o*Dg(*H6xRnj84u+i4Z7JC6M%`XEE#adqEQ-Ll*~MiIXyLkix%mXn^w<&62=&komB6>~SRyKlAxEt0VBjNwxtmNDYj2=V|HB zC}V0x42LbMk6sVGZmCe{@MJI%e&c^}`5v;L{M>NqY_L#Lz$8V=4h$Vq7x}c$!<>We?kH3=(+7;}cbCI1$T`Zm zb)oNa0;lSiPFlOfyj@>5;d$J8|5*^1`Cr;ENdE7BT>JAO)<=KXj>_w^N7a&x!?5NZD1z|DtWaNZ;wMR&4fU+UbmaC>UmyzmU<%ILUCLtxcq1HzIq zTQLKj=ztpp{Dwz(7Ch$p=j;ZSUAEPJ!%5lwxbi|4L9}4HoxbjHzvePrf9Sswt^KL$ zq;4;AhIvLGG`A@XL)IBIbjt!Q?l2(A(YfGmvDfgnhIT{Lifsi_yblvJme*SZiTcV){4qaY--E=Y zi|*Y%KapZ6R6|3fq^N|O>9sJtyy^lGGmd>d_)Naevp}@8s!F*&s`l_di@nTJZgg7) zcUs0sdAR!n*ZDpHAq{S>?L-U=3{Vt)j1-ECGNyfGH9=t$fCpF5CWrvc&xcvBcAg&d zJ1%ckG$nP#{pncI=4;c2)=b}V1?9e(^2GJvo(R`IMSx&9v%g-;P~U$J1Kdjt23 z#Kd^r_Cp{*JGfpa01q37g0k}UvqGV(+QaHgDpf%hxm=*${Ypdz>|8+>rG|acEaJ6S}Nul)togtqa z>{CHC{S1cSpK(WM#GYdbg~*7AF!nkbD*h{Nf-9k)9f7S$AFt(NU;Cf77nCvX5RQOVp<+ciD`lp1)pSO$%4T(0Kxzh zO##0UaTV+T7Y%f)=tGO7hga9*fP7k@ zGc%zvNo7wis%npZ*Nx5vWd1K;-hbnY7HLBGcpwEZT0YLJuzq+R7UKdOdQoaW&_pgQzKTw;;_z6UNAZ7T4kV0qCDMZ{AZ#IoE^Z*$BZ4zCie>syPo zq#|-dmM$54SIeq!_BjjR+#1D{o=tXH2WYzq8#x-K>{m4wFq7u@!KbQ8j9YxbiF6x2|`o?rDWw?S}&-6 zXb(JjiI_HNI;xa@`Ws@(ScoLAtgHfSYE~qPc#e(yZ$XJK=^S%2wdAyv+pT~tsoEqf z$di{4hBj7-**%U6-H4o=oJ7>~-1Y{WlY!M+UG3jNOfuN*UhAIc#UlIXgy;RBe`((P zKSf-5Ae3ttpWM1`B&FiwTCRQH_bf@WuQOv8#aISmYQ{P(RJMFv3|S_UF}xVYmW(AT zVX7<3SW>y%sSww$8B5=z-0%B)-uKLN&U4Q5zQ6PS&JUjlr*xT;S2FW(+5VIX4$(-c zr5HMD?7T>Zx_ac??;QLjhnX4<((-_dZG)k=0{L)L4C!w|{ai}Q;o`zmKf?GqM1|~S zMj=A!`qNL-{AK!2ZJj}pe!cDQ=JFLOmVC9txp?+CS#+d_&6UzGTro&gGCFm*N(1H= z6Mk93lZ?Y*U55`|F!XuWxnye>(QYs{Fjl?$VTo*?W6>g0r(@)jb=9H5UP+AlCYuU%piH)^Pm*dTZ^u zKT57<07GcHnb#rYdY^)t#kuhA)NxO~m7R$PEC>uPRgAdU;$;4cTGD)5Y#$Y}o#{Vn zPbMhew}M6dvv4hBXj@(^sc7zuW7>e=Pg_<>k6(1a_QNQwO!fleCuE@kzNok@6++Tj zVLn{)cO40R%(Dn6`bjRQSPUr->3_noQu}8gr`}~(iCgdy?OWsT0{jlT{+;|auYJ@_ z32}MHappqft||Ms7zo8fn&4RR#)QeJ%U-KsyV~@cL_SY75K0Lr z=NIQD#V&3@%F|){<=H|1UeFQHtz9o~f%uIX9aaD`+>`!rvU1zh!>FbBmJs#td6U;5NH<*yC1-CTDLyQCw`{-OG79b)$4R3?q9;WU?Qcn%(vL0C_#9p?Md&V- zc1Jlq)~!sj-X@^(CESOvSnyA*ylgtW312Uzsb@4Jvnx9V0=T{l)#i1%1d%F?lv$XT1NjPDRwnk7QN;P z`44esP)&Bm-`K0a0OCbIiq`=YF91T<7NYR@ciwj5ii*-NMBF?`S5NgCi&pnllq)$&E zsJgXwyM12}blO<$Ye8c6WK$W4Jq~{qAVG7+VjU* z)INDSt?l?jzwEy%1=BQs8QK}{`N+_t!lA+F0_k;M&MY=o;X30Be z&KMo_qmE6+OBotz9>2eF!Pf52!S~OnBPZZjYWuiEl~h#$rJ(UH(_1vzDz!2nFbqkz zRu9i261)aSO_s)A{hSsW&u3AqqpkCZdO`&Qh4R5*WBQXdsv&VuDOUF(phMZ9W5kH&mpy;iNMt{xaqY=_UDOMER4p?~5f*0FndBO44N!u@mX z6rKP^Kg$Apl0-Ca>ocgt`cJJAYxdw_J*y=^-Od9*=K+7 ztJhV?%`7oL7O;C*mQvLBs(V^xGCfT`E6UQq%<3cboS5-=Fx9?4Gcg#oUMh0vdjE5+ zW4h-4jZ4kTQ`Fa~Lb$)8)X^ecd(vlR8GV%@^Yb<~)H~&j86STww(E6-%&OXbjJ(@# zZNtvU4|+zLvZ*`$AHl^ijdPKZ4m&0`Kqnh9BKML$92BERK&s?iC#(`I5N1qkrw{ry zLW%XT!iUCK1%Ux$>1Bt>0Wjrv$I_WI=^r|GXG=a%TJt6UYA-#;{Ls|&JgD)(dSuOHF6kvACzM-UB#qm*K~b7xe?yoA0tnaOq{)te66an zGE2I$ft_91vc?Te2Hpc?=u&>43*}`sr7~Y9ZfjjHHf#boK2-4GG$r{US%JGwiP7t` zE*(4(0kIt76J#q3@bI4OzzI6U0rK$5>T&A<_bjdlKp1XJ-i2IGgF-?;T>6&Q(jl1p zi|OBKb$Wy?TU#kTq?K7*6#eAT-w3}0%d+tF-LRs9Yq8dQL&Eit?>|qBaI#o=nJmQk zo~qoLk8VV3$JXZW)N?&Gt!*S}K^5{i8>vtnkY6fSQ8)#xu$&d=LgGxYj@w=#t@fu* z^u&!%e3|L;Ba(E5h2FMy4{369r`7ZS+|C0mj>+rTOE*;4*1pKg`}9#VDwdOioY;mH zDJJ?TevE@o^W zD{0~DysWe`T($`pGa50a4KYSE1p}DHe(GN9AVo5TvkVAsOkJ12fKPY+$siy(Gp@h! z8YbNkGi0z_f``(fGY;P}k0~sOEJ#vVAb7opH|(V?wE#v1FV#|_gMWS=^Y=EhF}ItV zB585{L{q%K)3R_Lx#Z#%1p0=i*p@+Kw z;2cC(HL~8o%_FkcfdI@=FEk5+9<<4f4e9FXm>!-xvejj>yLE1otOjKJZcJtZHi{>6 z(`9D)Yj?K0R*$6Ou}V?jn@JCM@|;3%!!A+d{y8ZR+oY>Fwn7jYvpP4*4EShtwWsY)}`I!?qD0lIm?)c zgp-X_s_E>zl@$!&dGNX4%O@5V6+CDJQ=6Ep@d;m;_r)^?UEVam;UB~eG6r>2YpZ+L z5Q`_k{h2m{Sm=gy_4ZLkmOOu&vdVdRmSnKqpD N0N57#hJVN*u^x_wMJD>`F_* z9x9hDPc{9a|t){9GNJOE^1D1 z&TNK{oiyG{09OqhbmntPA7KkiG~2l3[!NOTE] +>Kernel DMA Protection is not compatible with other BitLocker DMA attacks countermeasures. It is recommended to disable the BitLocker DMA attacks countermeasures if the system supports Kernel DMA Protection. Kernel DMA Protection provides higher security bar for the system over the BitLocker DMA attack countermeasures, while maintaining usability of external peripherals. + +## Enabling Kernel DMA protection + +Systems running Windows 10 version 1803 that do support Kernel DMA Protection do have this security feature enabled automatically by the OS with no user or IT admin configuration required. + +**To check if a device supports kernel DMA protection** + +1. Launch MSINFO32.exe in a command prompt, or in the Windows search bar. +2. Check the value of **Kernel DMA Protection**. + ![Kernel DMA protection](bitlocker/images/kernel-dma-protection.png) +3. If the current state of **Kernel DMA Protection** is OFF and **Virtualization Technology in Firmware** is NO: + - Reboot into BIOS settings + - Turn on Intel Virtualization Technology. + - Turn on Intel Virtualization Technology for I/O (VT-d). In Windows 10 version 1803, only Intel VT-d is supported. Other platforms can use DMA attack mitigations described in BitLocker Countermeasures. + - Reboot system into Windows 10. +4. If the state of **Kernel DMA Protection** remains Off, then the system does not support this feature. + +## Frequently asked questions + +### Do in-market systems support Kernel DMA protection for Thunderbolt™ 3? +In market systems, released with Windows 10 version 1709 or earlier, will not support Kernel DMA protection for Thunderbolt™ 3 after upgrading to Windows 10 version 1803, as this feature requires the BIOS/platform firmware changes and guarantees. + +### Does Kernel DMA Protection prevent drive-by DMA attacks during Boot? +No, Kernel DMA Protection only protects against drive-by DMA attacks after the OS is loaded. It is the responsibility of the system firmware/BIOS to protect against attacks via the Thunderbolt™ 3 ports during boot. + +### How can I check if a certain driver supports DMA-remapping? +DMA-remapping is supported for specific device drivers, and is not universally supported by all devices and drivers on a platform. To check if a specific driver is opted into DMA-remapping, check the values corresponding to the following Property GUID (highlighted in red in the image below) in the Details tab of a device in Device Manager. A value of 0 or 1 means that the device driver does not support DMA-remapping. A value of 2 means that the device driver supports DMA-remapping. +Please check the driver instance for the device you are testing. Some drivers may have varying values depending on the location of the device (internal vs. external). + +![Kernel DMA protection user experience](images/device-details-tab.png) + +### What should I do if the drivers for my Thunderbolt™ 3 peripherals do not support DMA-remapping? +If the peripherals do have class drivers provided by Windows 10, please use these drivers on your systems. If there are no class drivers provided by Windows for your peripherals, please contact your peripheral vendor/driver vendor to update the driver to support this functionality. Details for driver compatibility requirements can be found here (add link to OEM documentation). + +### Do Microsoft drivers support DMA-remapping? +In Windows 10 1803 and beyond, the Microsoft inbox drivers for USB XHCI (3.x) Controllers, Storage AHCI/SATA Controllers and Storage NVMe Controllers support DMA-remapping. + +### Do drivers for non-PCI devices need to be compatible with DMA-remapping? +No. Devices for non-PCI peripherals, such as USB devices, do not perform DMA, thus no need for the driver to be compatible with DMA-remapping. + +### How can an enterprise enable the “External device enumeration” policy? +The “External device enumeration” policy controls whether to enumerate external devices that are not compatible with DMA-remapping. Devices that are compatible with DMA-remapping are always enumerated. The policy can be enabled via Group Policy or Mobile Device Management (MDM): +- Group Policy: Administrative Templates\System\Kernel DMA Protection\Enumeration policy for external devices incompatible with Kernel DMA Protection +- MDM: [DmaGuard policies](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-dmaguard#dmaguard-policies) + +## Related topics + +[BitLocker countermeasures](bitlocker/bitlocker-countermeasures.md) +[DmaGuard MDM policies](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-dmaguard#dmaguard-policies) From 69c24cfd266a9724348d3ec6d217bf19ed069f32 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 6 Sep 2018 16:26:08 -0700 Subject: [PATCH 2/2] edits --- .../kernel-dma-protection-for-thunderbolt.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/information-protection/kernel-dma-protection-for-thunderbolt.md b/windows/security/information-protection/kernel-dma-protection-for-thunderbolt.md index b6ea92cd47..fc494015d5 100644 --- a/windows/security/information-protection/kernel-dma-protection-for-thunderbolt.md +++ b/windows/security/information-protection/kernel-dma-protection-for-thunderbolt.md @@ -5,7 +5,7 @@ ms.prod: w10 ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: security -author: brianlic-msft +author: aadake ms.date: 09/06/2018 --- @@ -105,5 +105,5 @@ The “External device enumeration” policy controls whether to enumerate exter ## Related topics -[BitLocker countermeasures](bitlocker/bitlocker-countermeasures.md) -[DmaGuard MDM policies](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-dmaguard#dmaguard-policies) +- [BitLocker countermeasures](bitlocker/bitlocker-countermeasures.md) +- [DmaGuard MDM policies](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-dmaguard#dmaguard-policies)