Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0150 — Detection Strategy for File Creation or Modification of Boot Files
DET0150

Detection Strategy for File Creation or Modification of Boot Files

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0428 Analytic 0428
Windows

Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions.

WinEventLog:Sysmon EventCode=9 WinEventLog:Sysmon EventCode=11
[KnownGoodMBRHashes] Baseline hashes of clean MBR/VBR sectors for comparison
[ESPFileWhitelist] Approved EFI executables within ESP directories
[TimeWindow] Correlation window between privileged access, raw disk modification, and EFI file creation
AN0429 Analytic 0429
Linux

Detection of suspicious write operations to block devices, modifications of bootloader files (GRUB, initrd, vmlinuz), and unexpected changes within the EFI System Partition. Monitors privileged execution of utilities like dd, grub-install, or efibootmgr that modify boot sectors or loader entries.

auditd:SYSCALL open, write: Write operations targeting /dev/sda, /dev/nvme0n1, or EFI partition mounts linux:syslog Block device write errors or unusual bootloader activity
[BootloaderHashBaseline] Baseline checksums of GRUB, kernel, and initramfs images
[EFIFileAllowlist] Trusted EFI executables for Linux environments
[AlertThresholds] Tunable thresholds for triggering alerts on repeated EFI/bootloader writes

Detected Techniques

1

Details

MITRE ID
DET0150
STIX ID
x-mitre-detection-strategy--74252ca3-585e-466f-8020-ed77ebda3369
Analytics
2
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.