SecureBoot was disabled
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
14 Days
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Pre-OS Boot (T1542)
Severity
Low
Description
SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS.
Attacker's Goals
Disable SecureBoot to install another OS on the machine.
Investigative actions
Check if a new operating system was installed on the same hardware.
PreviousScripting engine connected to a rare external host
NextSecurity object deletion in Google Workspace Admin Console
Was this helpful?
