CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
Pre-OS Boot (T1542) — a Defense Evasion technique, observed in public incident reporting.
MITRE ATT&CKT1542
TacticDefense Evasion
Incidents on file16
Detection & mitigation
Monitor for unauthorized changes to SPI flash contents and verify firmware integrity using hardware root of trust. Ensure UEFI Shell is not present in production firmware unless required.