Pre-OS Boot T1542
Tactics: Stealth, Persistence
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.
Events covered
7 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 3 | Network connection |
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Sysmon-for-Linux | Event ID 1 | Process Create |
| Sysmon-for-Linux | Event ID 11 | File created |
Authoring guide
These 20 rules share fields, values, and exclusions.
Fields filtered most (21 distinct)
These fields appear most often in rule filters.
Top indicator values (70 distinct)
These values appear most often in rule predicates.
Exclusions (260 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
- Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
- UEFI Persistence Via Wpbbin - FileCreation
- UEFI Persistence Via Wpbbin - ProcessCreation
Elastic 8 rules
- Boot File Copy
- Dracut Module Creation
- GRUB Configuration File Creation
- GRUB Configuration Generation through Built-in Utilities
- Initramfs Extraction via CPIO
- Initramfs Unpacking via unmkinitramfs
- Manual Dracut Execution
- Persistence via Extensible Firmware Modification
Splunk 9 rules
- Detect Software Download To Network Device
- Linux EFI Bootloader File Deletion
- Linux Possible Bootloader Modification
- Windows BootLoader Inventory
- Windows EFI Bootloader File Modification
- Windows EFI Volume Mount Attempt Via Mountvol
- Windows Registry BootExecute Modification
- Windows Suspicious File in EFI Volume
- Windows WinLogon with Public Network Connection