Windows EFI Bootloader File Modification: endpointEndpointNoneversion:2
Detects where a process writes to critical EFI bootloader files (bootmgfw.efi or bootx64.efi) within the \EFI\Boot\ directory.
These files are responsible for initializing the Windows Boot Manager during system startup.
Modification or replacement of these files is highly unusual in normal operations and may indicate an attempt to install a bootkit, persist malicious code at the firmware level, or otherwise tamper with the system boot process.
Windows Suspicious File in EFI Volume: endpointEndpointNoneversion:2
Detects data files in the EFI volume.
This is sometimes indicative of an actor attempting to bypass secure boot through vulnerabilities such as CVE-2024-7344.
These use vulnerable boot loaders to run malicious system firmware code.
Windows BootLoader Inventory: endpointEndpointNoneversion:8
The following analytic identifies the bootloader paths on Windows endpoints. It leverages a PowerShell Scripted input to capture this data, which is then processed and aggregated using Splunk. Monitoring bootloader paths is significant for a SOC as it helps detect unauthorized modifications that could indicate bootkits or other persistent threats. If confirmed malicious, such activity could allow attackers to maintain persistence, bypass security controls, and potentially control the boot process, leading to full system compromise.
Windows Registry BootExecute Modification: endpointEndpointNoneversion:12
The following analytic detects modifications to the BootExecute registry key, which manages applications and services executed during system boot. It leverages data from the Endpoint.Registry data model, focusing on changes to the registry path "HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\BootExecute". This activity is significant because unauthorized changes to this key can indicate attempts to achieve persistence, load malicious code, or tamper with the boot process. If confirmed malicious, this could allow an attacker to maintain persistence, execute arbitrary code at boot, or disrupt system operations.