Pre-Os Boot: System Firmware Exploitation

Persistence at a pre-OS level can be gained modifying the firmware in a resource.
System firmware is quite static, and it doesn't usually provide detections capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. [1]

ID: T2041.001
Sub-technique of:  T2041
Tactic: Defense Evasion
Platforms: Space Segment
Version: 2.0
Created: 20 April 2023
Last Modified: 05 February 2025

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.

References