Pre-OS Boot: System Firmware Exploitation

Persistence at a pre-OS level can be gained modifying the firmware in a resource.
System firmware is quite static, and it doesn't usually provide detections capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. [1]

ID: T1542.001
Sub-technique of:  T1542
Tactic: Persistence
Platforms: None
Version: 2.0
Created: 23 September 2022
Last Modified: 05 February 2025

Mitigations

ID Mitigation Description
M1046 Boot Integrity

References