LoFP LoFP / legitimate system administrators or package managers may delete or replace efi bootloader files during system updates or os reinstallation. filter for known maintenance windows and authorized administrative activity.

Techniques

Sample rules

Linux EFI Bootloader File Deletion

Description

The following analytic detects file deletions in the EFI boot directory. These files are responsible for initializing the Boot Manager during system startup. Modification or replacement of these files is highly unusual in normal operations and may indicate an attempt to install a bootkit, persist malicious code at the firmware level, or otherwise tamper with the system boot process.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Endpoint.Filesystem where

Filesystem.action="deleted"
Filesystem.file_path="/boot/efi/EFI/BOOT/*"
Filesystem.file_name="*.efi*"

by Filesystem.file_path Filesystem.file_name Filesystem.user Filesystem.dest
   Filesystem.action Filesystem.process_guid Filesystem.process_id


| `drop_dm_object_name(Filesystem)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_efi_bootloader_file_deletion_filter`