MITRE ATT&CK technique
Pre-OS Boot detection rulesT1542
Pre-OS Boot (T1542) is a MITRE ATT&CK technique in the Persistence tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1542 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Top products
Tactic
UEFI Persistence Via Wpbbin - FileCreation
highDetects creation of a file named "wpbbin" in the "%systemroot%\system32\" directory. Which could be indicative of UEFI based persistence method
windows · file_event
UEFI Persistence Via Wpbbin - ProcessCreation
highDetects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section
windows · process_creation
Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
mediumDetects potential malicious and unauthorized usage of bcdedit.exe
windows · process_creation