Pre-OS Boot
Description
"Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system." Adversaries can obtain it modifying or replacing components before the launch or updating them later if an update capability is implemented. Detection is very difficult, because defenses are usually working at higher levels. Persistence at a pre-OS level can be gained modifying the firmware in a resource. System firmware is quite static, and it doesn't usually provide detection capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. (Citation: European Space Agency)
Mapped SPARTA techniques
3 techniques
T1542 'Pre-OS Boot' is the direct cross-framework counterpart of EX-0004 Compromise Boot Memory — both describe abusing pre-OS boot mechanisms (boot ROM, bootloaders, configuration words, fuses) so attacker code runs before normal protections.
T1542 'Pre-OS Boot' is the direct cross-framework counterpart of EX-0010.04 Bootkit — both describe pre-OS positioning that runs before normal integrity checks and shapes what subsequent layers trust.
T1542 'Pre-OS Boot' covers persistence at pre-OS levels via firmware/bootloader manipulation — addresses the boot-ROM and first/second-stage-loader subset of PER-0001 Memory Compromise.
Cite as SafeMode Space, space-shield T1542.