{"id":"T1542.003","name":"Bootkit","url":"https://attack.mitre.org/techniques/T1542/003","tactics":["stealth","persistence"],"platforms":["Linux","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0150","stix_id":"x-mitre-detection-strategy--74252ca3-585e-466f-8020-ed77ebda3369","name":"Detection Strategy for File Creation or Modification of Boot Files","url":"https://attack.mitre.org/detectionstrategies/DET0150","analytics":[{"id":"AN0428","stix_id":"x-mitre-analytic--7edc8ff6-0616-4fab-a7b7-1bd3d08cc0b1","name":"Analytic 0428","description":"Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions.","url":"https://attack.mitre.org/detectionstrategies/DET0150#AN0428","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=9","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"KnownGoodMBRHashes","description":"Baseline hashes of clean MBR/VBR sectors for comparison"},{"field":"ESPFileWhitelist","description":"Approved EFI executables within ESP directories"},{"field":"TimeWindow","description":"Correlation window between privileged access, raw disk modification, and EFI file creation"}],"live":true,"detection_strategies":["DET0150"],"techniques":["T1542.003"]},{"id":"AN0429","stix_id":"x-mitre-analytic--3d209345-1676-4170-b1d0-d6538bce06c4","name":"Analytic 0429","description":"Detection of suspicious write operations to block devices, modifications of bootloader files (GRUB, initrd, vmlinuz), and unexpected changes within the EFI System Partition. Monitors privileged execution of utilities like dd, grub-install, or efibootmgr that modify boot sectors or loader entries.","url":"https://attack.mitre.org/detectionstrategies/DET0150#AN0429","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write: Write operations targeting /dev/sda, /dev/nvme0n1, or EFI partition mounts","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Block device write errors or unusual bootloader activity","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"BootloaderHashBaseline","description":"Baseline checksums of GRUB, kernel, and initramfs images"},{"field":"EFIFileAllowlist","description":"Trusted EFI executables for Linux environments"},{"field":"AlertThresholds","description":"Tunable thresholds for triggering alerts on repeated EFI/bootloader writes"}],"live":true,"detection_strategies":["DET0150"],"techniques":["T1542.003"]}],"live":true,"version":"1.0","techniques":["T1542.003"]}],"sigma_rules":[{"id":"c9fbe8e9-119d-40a6-9b59-dd58a5d84429","title":"Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE","author":"@neu5ron","status":"test","level":"medium","date":"2019-02-07","modified":"2023-02-15","description":"Detects potential malicious and unauthorized usage of bcdedit.exe","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/bcdedit--set","https://twitter.com/malwrhunterteam/status/1372536434125512712/photo/2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1070","attack.persistence","attack.t1542.003"],"path":"rules/windows/process_creation/proc_creation_win_bcdedit_susp_execution.yml","techniques":["T1070","T1542.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}