LoFP LoFP / legitimate system administrators or package managers such as grub or shim may modify efi volume files during os upgrades or bootloader updates. filter based on known update processes or trusted administrative activity.

Techniques

Sample rules

Linux Possible Bootloader Modification

Description

The following analytic detects processes modifying data in the EFI volume on Linux. These files are responsible for initializing the Boot Manager during system startup. Modification or replacement of these files is highly unusual in normal operations and may indicate an attempt to install a bootkit, persist malicious code at the firmware level, or otherwise tamper with the system boot process.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Endpoint.Processes where

(
    Processes.process_name IN (
        "cp",
        "mv",
        "ln"
    )
    Processes.process_current_directory="*/EFI/BOOT*"
)
OR
(
    Processes.process="*/EFI/BOOT*"
    NOT Processes.process_name IN (
        "ls",
        "grep",
        "egrep"
    )
)

by Processes.process Processes.vendor_product Processes.user_id
   Processes.process_hash Processes.parent_process_name Processes.parent_process_exec
   Processes.action Processes.dest Processes.process_current_directory Processes.process_path
   Processes.process_integrity_level Processes.original_file_name Processes.parent_process
   Processes.parent_process_path Processes.parent_process_guid Processes.parent_process_id
   Processes.process_guid Processes.process_id Processes.user Processes.process_name


| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_possible_bootloader_modification_filter`