Pre-OS Boot T1542

Tactics: Stealth, Persistence

Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are loaded before the operating system. These programs control flow of execution before the operating system takes control.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 20 rules share fields, values, and exclusions.

Fields filtered most (21 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name8eq 5, in 3cp, mv, cpio, dracut, grub-mkconfig
TargetFilename7starts_with 2, wildcard 2, contains 1, ends_with 1, eq 1, in 1*\\efi\\boot\\bootmgfw.efi, *\\efi\\boot\\bootx64.efi, .dat, /boot/efi/efi/*/grub.cfg, /boot/efi/efi/boot/
event.type7eq 7start, creation
host.os.type7eq 7
EventType6in 5, eq 1, ne 1exec, ProcessRollup2, exec_event, start, deletion
CommandLine4contains 2, in 1, ne 1* /s*, *-s*, /efi/boot, delete, deletevalue
Image4is_not_null 2, ends_with 1, eq 1\bcdedit.exe, c:\windows\system32\wpbbin.exe
ParentImage3is_not_null 3
DestinationPort2eq 1, ne 10, 21, 22, 69
OriginalFileName2eq 2bcdedit.exe, mountvol.exe
process.args2eq 1, in 1, starts_with 1--format, -H, /boot/, newc
All_Traffic.dest_category1ne 1common_software_repo_destination
All_Traffic.src_category1eq 1network, router, switch
All_Traffic.transport1eq 1tcp, udp
CurrentDirectory1contains 1/efi/boot

Top indicator values (70 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
exec
5201
EventTypein
start
5163
EventTypein
ProcessRollup2
4117
EventTypein
exec_event
4149
EventTypein
executed
298
event.typeeq
start
51078
event.typeeq
creation
253
process_namein
cp
218
process_namein
mv
216
All_Traffic.dest_categoryne
common_software_repo_destination
1
All_Traffic.src_categoryeq
network
1
All_Traffic.src_categoryeq
router
1
All_Traffic.src_categoryeq
switch
1
All_Traffic.transporteq
tcp
14
All_Traffic.transporteq
udp
1
CommandLinecontains
/efi/boot
1
CommandLinecontains
delete
131
CommandLinecontains
deletevalue
12
CommandLinecontains
import
14
CommandLinecontains
network
13
CommandLinecontains
safeboot
13
CommandLinein
* /s*
12
CommandLinein
*-s*
15
CommandLinene
unknown
13
CurrentDirectorycontains
/efi/boot
1
DestinationPorteq
21
15
DestinationPorteq
22
1
DestinationPorteq
69
1
DestinationPortne
0
17
EventTypeeq
end
118

Exclusions (260 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_namein
dracut
3
parent_process_namein
sudo
3
Imagein
./usr/bin/podman
2
Imagein
/bin/autossl_check
2
Imagein
/bin/chef-client
2
Imagein
/bin/dnf
2
Imagein
/bin/dnf-automatic
2
Imagein
/bin/dockerd
2
Imagein
/bin/dpkg
2
Imagein
/bin/dpkg-divert
2
Imagein
/bin/install
2
Imagein
/bin/microdnf
2
Imagein
/bin/pacman
2
Imagein
/bin/pamac-daemon
2
Imagein
/bin/podman
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 8 rules

Splunk 9 rules