Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0099 — Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
DET0099

Detection Strategy for T1542.001 Pre-OS Boot: System Firmware

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0275 Analytic 0275
Windows

Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=9 WinEventLog:Sysmon EventCode=11
[AllowedFirmwareUpdateTools] Legitimate vendor tools permitted to perform firmware flashing or BIOS updates.
[TimeWindow] Expected time periods for approved firmware updates, used for correlating suspicious activity outside patch cycles.
[KnownGoodFirmwareHashes] Baseline hashes of vendor BIOS/UEFI firmware for integrity comparison.
AN0276 Analytic 0276
Network Devices

Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.

networkdevice:config Boot image path or firmware configuration variable modified outside of maintenance windows networkdevice:runtime Firmware image uploaded via TFTP/FTP/SCP
[ApprovedFirmwareHashes] Known good firmware image hashes stored for validation.
[MaintenanceWindows] Expected time periods when firmware uploads or reboots are considered normal.
[SourceIPWhitelist] List of trusted management IPs allowed to initiate firmware uploads.

Detected Techniques

1

Details

MITRE ID
DET0099
STIX ID
x-mitre-detection-strategy--e90ab093-47a3-4c05-80b1-1919d2362ea9
Analytics
2
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.