Meta tags:
Headings (most frequently used words):
pre, os, boot, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
boot (16), t1542 (13), the (12), att (10), all (10), firmware (9), system (8), and (7), enterprise (7), #techniques (6), efi (6), ics (5), mobile (5), none (5), software (5), detection (5), pre (5), access (5), mitre (4), are (4), data (4), defenses (4), trusted (4), changes (4), not (4), with (4), may (4), version (4), 2026 (3), use (3), cti (3), mitigations (3), sub (3), tactics (3), process (3), retrieved (3), unexpected (3), patch (3), modification (3), associated (3), updates (3), from (3), for (3), bios (3), prevent (3), systems (3), network (3), integrity (3), operating (3), corporation (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), secure (2), windows (2), april (2), platform (2), module (2), booting (2), november (2), 2019 (2), image (2), tftp (2), configuration (2), logs (2), variable (2), abnormal (2), binaries (2), nvram (2), unified (2), calls (2), executed (2), parent (2), processes (2), unsigned (2), loads (2), events (2), overwrite (2), execution (2), writing (2), devices (2), followed (2), update (2), tools (2), strategy (2), analytic (2), description (2), name (2), necessary (2), permissions (2), privileged (2), perform (2), these (2), services (2), mechanisms (2), limit (2), etc (2), insecure (2), persistence (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), adversaries (2), this (2), can (2), before (2), control (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, microsoft, 2020, computing, group, 2008, tpm, summary, june, 2016, wikipedia, references, uploads, via, ftp, scp, modifying, pointers, showing, redirection, non, standard, images, anomalous, reboots, immediately, following, tied, schedules, an0777, library, coreservices, parameters, capturing, bless, commands, untrusted, sudden, kext, after, tampering, an0776, writes, directories, outside, expected, package, manager, monitoring, kernel, log, auditd, attempts, bootloader, grub, shim, efibootmgr, dev, sdx, parameter, an0775, unusual, records, mbr, vbr, partitions, legitimate, cycles, upgrades, registry, wmi, api, deviceiocontrol, directly, raw, disk, sectors, subsequent, driver, an0774, det0278, m1051, ensure, proper, place, help, adversary, accounts, actions, account, management, m1026, file, shares, remote, unnecessary, include, concentrators, rdp, gateways, resource, over, m1035, technology, being, compromised, check, existing, determine, vulnerable, m1046, audits, scans, configurations, identify, potential, weaknesses, audit, m1047, mitigation, live, permalink, last, modified, created, linux, macos, platforms, stealth, drivers, such, basic, input, output, extensible, interface, uefi, persist, layer, below, particularly, difficult, detect, malware, level, will, detected, host, based, abuse, way, establish, during, computer, various, startup, loaded, programs, flow, takes, rommonkit, bootkit, component, home, open, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, advisory, council, learn, more, about, get, started, detections, technique,
Text of the page (random words):
pre os boot technique t1542 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise pre os boot pre os boot sub techniques 5 id name t1542 001 system firmware t1542 002 component firmware t1542 003 bootkit t1542 004 rommonkit t1542 005 tftp boot adversaries may abuse pre os boot mechanisms as a way to establish persistence on a system during the booting process of a computer firmware and various startup services are loaded before the operating system these programs control flow of execution before the operating system takes control 1 adversaries may overwrite data in boot drivers or firmware such as bios basic input output system and the unified extensible firmware interface uefi to persist on systems at a layer below the operating system this can be particularly difficult to detect as malware at this level will not be detected by host software based defenses id t1542 sub techniques t1542 001 t1542 002 t1542 003 t1542 004 t1542 005 ⓘ tactics stealth persistence ⓘ platforms linux network devices windows macos version 2 0 created 13 november 2019 last modified 12 may 2026 version permalink live version mitigations id mitigation description m1047 audit perform audits or scans of systems permissions insecure software insecure configurations etc to identify potential weaknesses m1046 boot integrity use trusted platform module technology and a secure or trusted boot process to prevent system integrity from being compromised check the integrity of the existing bios or efi to determine if it is vulnerable to modification 2 3 m1035 limit access to resource over network prevent access to file shares remote access to systems unnecessary services mechanisms to limit access may include use of network concentrators rdp gateways etc m1026 privileged account management ensure proper permissions are in place to help prevent adversary access to privileged accounts necessary to perform these actions m1051 update software patch the bios and efi as necessary detection strategy id name analytic id analytic description det0278 detection strategy for t1542 pre os boot an0774 unusual modification of boot records mbr vbr or efi partitions not associated with legitimate patch cycles or os upgrades registry or wmi events associated with firmware update tools executed from unexpected parent processes api calls e g deviceiocontrol writing directly to raw disk sectors subsequent abnormal boot configuration changes followed by unsigned driver loads an0775 detection of writes to boot or efi directories outside of expected package manager updates monitoring kernel log and auditd events for attempts to overwrite bootloader binaries e g grub shim unexpected execution of efibootmgr or dd writing to dev sdx devices followed by boot parameter changes an0776 abnormal modification of efi firmware binaries in system library coreservices or nvram parameters not associated with os updates unified logs capturing calls to bless or nvram commands executed from untrusted parent processes sudden unsigned kext loads after efi variable tampering an0777 unexpected firmware image uploads via tftp ftp scp configuration changes modifying boot image pointers logs showing boot variable redirection to non standard images anomalous reboots immediately following firmware changes not tied to patch schedules references wikipedia n d booting retrieved november 13 2019 trusted computing group 2008 april 29 trusted platform module tpm summary retrieved june 8 2016 microsoft n d secure the windows 10 boot process retrieved april 23 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|