Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1542

T1542Pre-OS Boot

T1542 — Pre-OS Boot is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 5 detection use cases covering it and 1 threat-intel article citing it.

Defense EvasionPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
1Articles
5Sub-techniques
2Tactics

Sub-techniques (5)

Use cases covering this technique (5)

Windows EFI Volume Mount Attempt Via Mountvol ESCU actions · hunting P Windows Registry BootExecute Modification ESCU actions · alerting P [LLM] Exposure to revoked vulnerable UEFI shims (CVE-2026-8863 / CVE-2026-10797) Bespoke exploit · hunting DSP [LLM] Vulnerable UEFI shim/GRUB bootloader written to the EFI System Partition Bespoke install · hunting DSΣPDDCS [LLM] EFI System Partition mounted via mountvol /S (rogue shim staging) Bespoke install · hunting DSΣPDDCS

Articles citing this technique (1)