Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1542.003

T1542.003Bootkit

T1542.003 — Bootkit is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 6 detection use cases covering it and 2 threat-intel articles citing it.

Defense EvasionPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
2Articles
0Sub-techniques
2Tactics

Use cases covering this technique (6)

Windows EFI Bootloader File Modification ESCU actions · alerting P Windows WinLogon with Public Network Connection ESCU actions · hunting P [LLM] Exposure to revoked vulnerable UEFI shims (CVE-2026-8863 / CVE-2026-10797) Bespoke exploit · hunting DSP [LLM] Vulnerable UEFI shim/GRUB bootloader written to the EFI System Partition Bespoke install · hunting DSΣPDDCS [LLM] EFI System Partition mounted via mountvol /S (rogue shim staging) Bespoke install · hunting DSΣPDDCS [LLM] SprySOCKS WIN_DRV BlackLotus-style Secure Boot downgrade / EFI bootkit (CVE-2023-24932) Bespoke install · hunting DSΣPDDCS

Articles citing this technique (2)