ESA SPACE-SHIELD
T1542

Pre-OS Boot

Description

"Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system." Adversaries can obtain it modifying or replacing components before the launch or updating them later if an update capability is implemented. Detection is very difficult, because defenses are usually working at higher levels. Persistence at a pre-OS level can be gained modifying the firmware in a resource. System firmware is quite static, and it doesn't usually provide detection capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. (Citation: European Space Agency)

Mapped SPARTA techniques

3 techniques

  • T1542 'Pre-OS Boot' is the direct cross-framework counterpart of EX-0004 Compromise Boot Memory — both describe abusing pre-OS boot mechanisms (boot ROM, bootloaders, configuration words, fuses) so attacker code runs before normal protections.

  • EX-0010.04BootkitST0004
    addresses
    high

    T1542 'Pre-OS Boot' is the direct cross-framework counterpart of EX-0010.04 Bootkit — both describe pre-OS positioning that runs before normal integrity checks and shapes what subsequent layers trust.

  • PER-0001Memory CompromiseST0005
    addresses
    moderate

    T1542 'Pre-OS Boot' covers persistence at pre-OS levels via firmware/bootloader manipulation — addresses the boot-ROM and first/second-stage-loader subset of PER-0001 Memory Compromise.

Cite as SafeMode Space, space-shield T1542.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.