Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.(Citation: Wikipedia BIOS)(Citation: Wikipedia UEFI)(Citation: About UEFI) System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Capabilities exist to overwrite the system firmware, which may give sophisticated adversaries a means to install malicious firmware updates as a means of persistence on a system that may be difficult to detect.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Boot Integrity
is blocked by Update Software
is blocked by Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
is blocked by Privileged Account Management
is blocked by Asset Inventories
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identification & Authentication for Non-Organizational Users
is blocked by Cryptographic Module Authentication
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Non-Modifiable Executable Programs
is blocked by Criticality Analysis During Development
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Developer Configuration Management
is blocked by Software & Firmware Patching
Impressum German English