1200KM / detection
T1542.001 System Firmware — Detection Rules
Detection workspace for T1542.001 System Firmware: 2 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- UEFI Persistence Via Wpbbin - FileCreation · test · high · {"product":"windows","category":"file_event"}
- UEFI Persistence Via Wpbbin - ProcessCreation · test · high · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0099 Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
AN0275 Analytic 0275
Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.
AN0276 Analytic 0276
Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1542.001 simulation workspace
- Drive Access · DC0054
- Drive Modification · DC0046
- File Creation · DC0039
- Firmware Modification · DC0004
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.