Cross-source coverage

T1542.001 / ATT&CK

Pre-OS Boot: System Firmware

7 rules across 3 sources.

From MITRE ATT&CK 19.2

Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.

System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Capabilities exist to overwrite the system firmware, which may give sophisticated adversaries a means to install malicious firmware updates as a means of persistence on a system that may be difficult to detect.

Tactics
Stealth · Persistence
Platforms
Network Devices · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonnetworkdevice:confignetworkdevice:runtime

How MITRE says to detect it DET0099

Detection Strategy for T1542.001 Pre-OS Boot: System Firmware

Windows Analytic 0275

Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=9
  • WinEventLog:Sysmon EventCode=11

Network Devices Analytic 0276

Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.

  • networkdevice:config Boot image path or firmware configuration variable modified outside of maintenance windows
  • networkdevice:runtime Firmware image uploaded via TFTP/FTP/SCP

splunk/security_content

4 rules
Detection Severity Format
Linux EFI Bootloader File Deletion Undefined SPL
Linux Possible Bootloader Modification Undefined SPL
Windows BootLoader Inventory Undefined SPL
Windows Suspicious File in EFI Volume Undefined SPL

SigmaHQ/sigma

2 rules
Detection Severity Format
UEFI Persistence Via Wpbbin - FileCreation High Sigma
UEFI Persistence Via Wpbbin - ProcessCreation High Sigma

socfortress/Wazuh-Rules

1 rule
Detection Severity Format
MITRE ATTaCK T1542.001 Pre-OS Boot: System Firmware - wpbbin.exe file created in System32. Possible firmware persistence attempt. High Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.