{"id":"T1542.001","name":"System Firmware","url":"https://attack.mitre.org/techniques/T1542/001","tactics":["stealth","persistence"],"platforms":["Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0099","stix_id":"x-mitre-detection-strategy--e90ab093-47a3-4c05-80b1-1919d2362ea9","name":"Detection Strategy for T1542.001 Pre-OS Boot: System Firmware","url":"https://attack.mitre.org/detectionstrategies/DET0099","analytics":[{"id":"AN0275","stix_id":"x-mitre-analytic--59d44906-a35e-4b0f-ab84-df3bfa6df8f9","name":"Analytic 0275","description":"Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.","url":"https://attack.mitre.org/detectionstrategies/DET0099#AN0275","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=9","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedFirmwareUpdateTools","description":"Legitimate vendor tools permitted to perform firmware flashing or BIOS updates."},{"field":"TimeWindow","description":"Expected time periods for approved firmware updates, used for correlating suspicious activity outside patch cycles."},{"field":"KnownGoodFirmwareHashes","description":"Baseline hashes of vendor BIOS/UEFI firmware for integrity comparison."}],"live":true,"detection_strategies":["DET0099"],"techniques":["T1542.001"]},{"id":"AN0276","stix_id":"x-mitre-analytic--ceb2c722-f9ec-41de-980e-d8848b1cb20c","name":"Analytic 0276","description":"Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.","url":"https://attack.mitre.org/detectionstrategies/DET0099#AN0276","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:config","channel":"Boot image path or firmware configuration variable modified outside of maintenance windows","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"networkdevice-config"},{"name":"networkdevice:runtime","channel":"Firmware image uploaded via TFTP/FTP/SCP","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"networkdevice-runtime"}],"mutable_elements":[{"field":"ApprovedFirmwareHashes","description":"Known good firmware image hashes stored for validation."},{"field":"MaintenanceWindows","description":"Expected time periods when firmware uploads or reboots are considered normal."},{"field":"SourceIPWhitelist","description":"List of trusted management IPs allowed to initiate firmware uploads."}],"live":true,"detection_strategies":["DET0099"],"techniques":["T1542.001"]}],"live":true,"version":"1.0","techniques":["T1542.001"]}],"sigma_rules":[{"id":"4abc0ec4-db5a-412f-9632-26659cddf145","title":"UEFI Persistence Via Wpbbin - ProcessCreation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-18","modified":null,"description":"Detects execution of the binary \"wpbbin\" which is used as part of the UEFI based persistence method described in the reference section","references":["https://grzegorztworek.medium.com/using-uefi-to-inject-executable-files-into-bitlocker-protected-drives-8ff4ca59c94c","https://persistence-info.github.io/Data/wpbbin.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.stealth","attack.t1542.001"],"path":"rules/windows/process_creation/proc_creation_win_wpbbin_potential_persistence.yml","techniques":["T1542.001"],"cves":[]},{"id":"e94b9ddc-eec5-4bb8-8a58-b9dc5f4e185f","title":"UEFI Persistence Via Wpbbin - FileCreation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-18","modified":null,"description":"Detects creation of a file named \"wpbbin\" in the \"%systemroot%\\system32\\\" directory. Which could be indicative of UEFI based persistence method","references":["https://grzegorztworek.medium.com/using-uefi-to-inject-executable-files-into-bitlocker-protected-drives-8ff4ca59c94c","https://persistence-info.github.io/Data/wpbbin.html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.stealth","attack.t1542.001"],"path":"rules/windows/file/file_event/file_event_win_wpbbin_persistence.yml","techniques":["T1542.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}