Cross-source coverage
T1542.001 / ATT&CK
Pre-OS Boot: System Firmware
7 rules across 3 sources.
From MITRE ATT&CK 19.2
Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.
System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Capabilities exist to overwrite the system firmware, which may give sophisticated adversaries a means to install malicious firmware updates as a means of persistence on a system that may be difficult to detect.
- Tactics
- Stealth · Persistence
- Platforms
- Network Devices · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonnetworkdevice:confignetworkdevice:runtime
How MITRE says to detect it DET0099
Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
Windows Analytic 0275
Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=9WinEventLog:SysmonEventCode=11
Network Devices Analytic 0276
Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.
networkdevice:configBoot image path or firmware configuration variable modified outside of maintenance windowsnetworkdevice:runtimeFirmware image uploaded via TFTP/FTP/SCP
splunk/security_content
4 rules| Detection | Severity | Format |
|---|---|---|
| Linux EFI Bootloader File Deletion | Undefined | SPL |
| Linux Possible Bootloader Modification | Undefined | SPL |
| Windows BootLoader Inventory | Undefined | SPL |
| Windows Suspicious File in EFI Volume | Undefined | SPL |
SigmaHQ/sigma
2 rules| Detection | Severity | Format |
|---|---|---|
| UEFI Persistence Via Wpbbin - FileCreation | High | Sigma |
| UEFI Persistence Via Wpbbin - ProcessCreation | High | Sigma |
socfortress/Wazuh-Rules
1 rule| Detection | Severity | Format |
|---|---|---|
| MITRE ATTaCK T1542.001 Pre-OS Boot: System Firmware - wpbbin.exe file created in System32. Possible firmware persistence attempt. | High | Wazuh XML |