Pre-OS Boot

T1542

Technique with 5 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.

Adversaries may overwrite data in boot drivers or firmware such as BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) to persist on systems at a layer below the operating system. This can be particularly difficult to detect as malware at this level will not be detected by host software-based defenses.

Detection rules12

Rules on DetectionCode tagged with T1542 or one of its sub-techniques.

Sigma3

Splunk9

RuleTypeRiskData sourceTechnique
Detect Software Download To Network DeviceTTPNULLT1542.005
Linux EFI Bootloader File DeletionTTPNULLSysmon for Linux EventID 11T1542.001 T1542.003
Linux Possible Bootloader ModificationTTPNULLSysmon for Linux EventID 1T1542.001
Windows BootLoader InventoryHuntingNULLT1542.001
Windows EFI Bootloader File ModificationTTPNULLSysmon EventID 11T1542.003
Windows EFI Volume Mount Attempt Via MountvolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1542
Windows Registry BootExecute ModificationTTPNULLSysmon EventID 13T1542
Windows Suspicious File in EFI VolumeTTPNULLSysmon EventID 11T1542.001
Windows WinLogon with Public Network ConnectionHuntingNULLSysmon EventID 1 AND Sysmon EventID 3T1542.003

Sub-techniques5

IDNameExamples
T1542.001System Firmware3
T1542.002Component Firmware2
T1542.003Bootkit9
T1542.004ROMMONkit0
T1542.005TFTP Boot0

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References1

  1. Wikipedia Booting Open source
    Wikipedia. (n.d.). Booting. Retrieved November 13, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.