Analytics BIOC
Low
✕
SecureBoot was disabled
SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Pre-OS Boot (T1542)
Attacker's goals:
Disable SecureBoot to install another OS on the machine.
Investigative actions:
Check if a new operating system was installed on the same hardware.
- Test period:
- N/A (single event)
- Deduplication:
- 14 Days