Potential Suspicious UEFI Bootloader Changes

Rule Info

Name
Potential Suspicious UEFI Bootloader Changes
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects suspicious UEFI bootloader changes via bootloader registry key modification
Date
2023-03-17 00:00:00
Modified
None
Id
b9bb0bc0-3fbe-4104-9a1c-7982f3052939
Tags
attack.defense-evasion attack.privilege-escalation
Type
Nextron Sigma feed only (private)

Rule History