AN0474
Analytic 0474
Windows
Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=6
WinEventLog:Microsoft-Windows-Kernel-Boot
Firmware integrity validation failed or boot configuration tampered
[ParentImage]
Common legitimate flash tool chains can be allowlisted
[CommandLine]
Flags indicating silent or forced flash may vary
AN0475
Analytic 0475
Linux
Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).
auditd:SYSCALL
write access to /dev/mem or /sys/firmware/efi/efivars
auditd:SYSCALL
execution of known flash tools (e.g., flashrom, fwupd)
[ToolName]
Custom or renamed firmware tools may require pattern matching
AN0476
Analytic 0476
macOS
EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.
macos:unifiedlog
com.apple.firmwareupdater activity or update-firmware binary invoked
macos:unifiedlog
boot failure events or SMC validation errors
[UpdateTimeWindow]
Firmware updates usually occur after OS update; out-of-band patterns may indicate compromise
AN0477
Analytic 0477
Network Devices
Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.
NSM:Flow
large upload to firmware interface port or path
networkdevice:firmware
Firmware update initiated or bootloader tampering detected
[UploadSizeThreshold]
Size of firmware images varies by vendor
[RebootWindow]
Reboots outside of patch maintenance may be suspicious