Analytics BIOC Low

SecureBoot was disabled

SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Pre-OS Boot (T1542)
Attacker's goals:

Disable SecureBoot to install another OS on the machine.

Investigative actions:

Check if a new operating system was installed on the same hardware.

Test period:
N/A (single event)
Deduplication:
14 Days