AN0275
Analytic 0275
Windows
Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=9
WinEventLog:Sysmon
EventCode=11
[AllowedFirmwareUpdateTools]
Legitimate vendor tools permitted to perform firmware flashing or BIOS updates.
[TimeWindow]
Expected time periods for approved firmware updates, used for correlating suspicious activity outside patch cycles.
[KnownGoodFirmwareHashes]
Baseline hashes of vendor BIOS/UEFI firmware for integrity comparison.
AN0276
Analytic 0276
Network Devices
Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.
networkdevice:config
Boot image path or firmware configuration variable modified outside of maintenance windows
networkdevice:runtime
Firmware image uploaded via TFTP/FTP/SCP
[ApprovedFirmwareHashes]
Known good firmware image hashes stored for validation.
[MaintenanceWindows]
Expected time periods when firmware uploads or reboots are considered normal.
[SourceIPWhitelist]
List of trusted management IPs allowed to initiate firmware uploads.