Techniques › T1542 › AN0776
AN0776 Analytic 0776
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Abnormal modification of EFI firmware binaries in /System/Library/CoreServices/ or NVRAM parameters not associated with OS updates. Unified logs capturing calls to bless or nvram commands executed from untrusted parent processes. Sudden unsigned kext loads after EFI variable tampering.</p>
- Detects
- T1542 Pre-OS Boot
- Part of
- DET0278 Detection Strategy for T1542 Pre-OS Boot
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | Execution of bless or nvram modifying boot parameters | DC0032 Process Creation |
| macos:unifiedlog | Modification of /System/Library/CoreServices/boot.efi | DC0061 File Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AllowedBootUtilities | Known Apple-signed processes responsible for firmware updates. |
BootParamBaseline | Baseline set of allowed NVRAM boot parameters for anomaly detection. |