Sub-technique of T1542 Pre-OS Boot.View on attack.mitre.org
Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.
System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Capabilities exist to overwrite the system firmware, which may give sophisticated adversaries a means to install malicious firmware updates as a means of persistence on a system that may be difficult to detect.
Rules on DetectionCode tagged with T1542.001.
| Rule | Level | Log source |
|---|---|---|
| UEFI Persistence Via Wpbbin - FileCreation | high | windows / file_event |
| UEFI Persistence Via Wpbbin - ProcessCreation | high | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux EFI Bootloader File Deletion | TTP | NULL | Sysmon for Linux EventID 11 |
| Linux Possible Bootloader Modification | TTP | NULL | Sysmon for Linux EventID 1 |
| Windows BootLoader Inventory | Hunting | NULL | |
| Windows Suspicious File in EFI Volume | TTP | NULL | Sysmon EventID 11 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareHacking Team UEFI Rootkit | Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems. |
| MalwareLoJax | LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems. |
| MalwareTrojan.Mebromi | Trojan.Mebromi performs BIOS modification and can download and execute a file as well as protect itself from removal. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.