We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Malware reports
Resource Development, Persistence, Defense Evasion
https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/
attack:T1542.003:Bootkit attack:T1547.006:Kernel Modules and Extensions attack:T1587.00:Malware attack:T1587.002Code Signing Certificates attack:T1106:Native API attack:T1129:Shared Modules attack:T1574.006:Dynamic Linker attack:T1542.003 attack:T1014:Rootkit attack:T1562:Impair Defenses attack:T1564:Hide Artifacts
Bootkitty BCDropper BCObserver
No response
Linux
Consumer, Internal enterprise services, Enterprise with satellite facilities, Enterprise with contracted services and/or non-employee access
The text was updated successfully, but these errors were encountered:
timb-machine
No branches or pull requests
Area
Malware reports
Parent threat
Resource Development, Persistence, Defense Evasion
Finding
https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/
Industry reference
attack:T1542.003:Bootkit
attack:T1547.006:Kernel Modules and Extensions
attack:T1587.00:Malware
attack:T1587.002Code Signing Certificates
attack:T1106:Native API
attack:T1129:Shared Modules
attack:T1574.006:Dynamic Linker
attack:T1542.003
attack:T1014:Rootkit
attack:T1562:Impair Defenses
attack:T1564:Hide Artifacts
Malware reference
Bootkitty
BCDropper
BCObserver
Actor reference
No response
Component
Linux
Scenario
Consumer, Internal enterprise services, Enterprise with satellite facilities, Enterprise with contracted services and/or non-employee access
The text was updated successfully, but these errors were encountered: