Malicious Secure Boot Bypass Files Dropped to EFI Partition

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-09-23
Updated
2026-09-23

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation of the cloak.dat or reloader.efi files used by HybridPetya to exploit CVE-2024-7344 and bypass UEFI Secure Boot. Writing these bootkit components onto the EFI system partition indicates an attempt to load unsigned code during boot and achieve stealthy pre-OS persistence.

Related detections9 linkedT1211 — drag to rearrange
Malicious Windows Boot Manager Backup Created by UEFI Bootkit
Suspicious Renamed GRUB Bootloader grubx64-real Creation via File System
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Suspicious Bootkitty Rootkit Component Drop under opt via File System
Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
Suspicious Staged Payload Execution from User Downloads or Pictures Folder
Malicious Boot Configuration Tampering via bcdedit (via process_creation)
Malicious Vulnerable Driver Deployment for EDR Termination via file_event
Malicious Secure Boot Bypass Files Dropped to EFI Partition
Pivot detection · T1211 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.