{"id":"T1542","name":"Pre-OS Boot","url":"https://attack.mitre.org/techniques/T1542","tactics":["stealth","persistence"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0278","stix_id":"x-mitre-detection-strategy--abf6c96c-09f3-4bea-a5b7-1177f99881bc","name":"Detection Strategy for T1542 Pre-OS Boot","url":"https://attack.mitre.org/detectionstrategies/DET0278","analytics":[{"id":"AN0774","stix_id":"x-mitre-analytic--e2ca60b5-82df-4e7e-8528-dd24d9a79750","name":"Analytic 0774","description":"Unusual modification of boot records (MBR, VBR) or EFI partitions not associated with legitimate patch cycles or OS upgrades. Registry or WMI events associated with firmware update tools executed from unexpected parent processes. API calls (e.g., DeviceIoControl) writing directly to raw disk sectors. Subsequent abnormal boot configuration changes followed by unsigned driver loads.","url":"https://attack.mitre.org/detectionstrategies/DET0278#AN0774","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=9","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedFirmwareUpdateTools","description":"Legitimate vendor tools or processes authorized to modify firmware or boot records."},{"field":"TimeWindow","description":"Correlating boot-sector modification with subsequent reboot events."},{"field":"EntropyThreshold","description":"Heuristic threshold for detecting obfuscated/packed boot code."}],"live":true,"detection_strategies":["DET0278"],"techniques":["T1542"]},{"id":"AN0775","stix_id":"x-mitre-analytic--08dd2c3b-e07c-4b47-bae6-aa09c2a86d87","name":"Analytic 0775","description":"Detection of writes to /boot or EFI directories outside of expected package manager updates. Monitoring kernel log and auditd events for attempts to overwrite bootloader binaries (e.g., grub, shim). Unexpected execution of efibootmgr or dd writing to /dev/sdX devices followed by boot parameter changes.","url":"https://attack.mitre.org/detectionstrategies/DET0278#AN0775","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write: Modification of /boot/grub/* or /boot/efi/*","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"exec: Execution of dd, efibootmgr, or flashrom modifying firmware/boot partitions","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"PackageManagerUpdateWhitelist","description":"Allowlist of legitimate grub/shim updates via apt, yum, or rpm."},{"field":"FilesystemPaths","description":"Directories (e.g., /boot/efi, /boot/grub) monitored for unauthorized modification."}],"live":true,"detection_strategies":["DET0278"],"techniques":["T1542"]},{"id":"AN0776","stix_id":"x-mitre-analytic--43834e1c-533a-4f08-b508-8632d35b10ad","name":"Analytic 0776","description":"Abnormal modification of EFI firmware binaries in /System/Library/CoreServices/ or NVRAM parameters not associated with OS updates. Unified logs capturing calls to bless or nvram commands executed from untrusted parent processes. Sudden unsigned kext loads after EFI variable tampering.","url":"https://attack.mitre.org/detectionstrategies/DET0278#AN0776","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of bless or nvram modifying boot parameters","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Modification of /System/Library/CoreServices/boot.efi","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AllowedBootUtilities","description":"Known Apple-signed processes responsible for firmware updates."},{"field":"BootParamBaseline","description":"Baseline set of allowed NVRAM boot parameters for anomaly detection."}],"live":true,"detection_strategies":["DET0278"],"techniques":["T1542"]},{"id":"AN0777","stix_id":"x-mitre-analytic--e64aebfd-8343-45ec-bdce-6681a8255637","name":"Analytic 0777","description":"Unexpected firmware image uploads via TFTP/FTP/SCP. Configuration changes modifying boot image pointers. Logs showing boot variable redirection to non-standard images. Anomalous reboots immediately following firmware changes not tied to patch schedules.","url":"https://attack.mitre.org/detectionstrategies/DET0278#AN0777","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:config","channel":"Boot variable modified to point to non-standard or unsigned image","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"networkdevice-config"},{"name":"networkdevice:firmware","channel":"Unexpected firmware image upload events via TFTP/FTP/SCP","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"networkdevice-firmware"}],"mutable_elements":[{"field":"ApprovedFirmwareHashes","description":"Known good firmware image hashes allowed for boot."},{"field":"MaintenanceWindows","description":"Timeframes during which firmware updates are expected."}],"live":true,"detection_strategies":["DET0278"],"techniques":["T1542"]}],"live":true,"version":"1.0","techniques":["T1542"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}