Splunk published new endpoint detections for suspicious changes to Linux EFI boot components that could indicate bootkit installation, firmware-level persistence, or tampering with the system boot chain. One analytic flags deletion of .efi files in /boot/efi/EFI/BOOT/, while another monitors processes that modify files in the EFI boot volume using EDR telemetry such as process GUIDs, parent-child relationships, and full command-line logging. Splunk said both behaviors are unusual in normal operations, though legitimate administrator activity, package updates, OS reinstalls, and tools such as grub or shim may generate false positives.
The detections map to MITRE ATT&CK Pre-OS Boot techniques T1542.001 and T1542.003, which cover malicious changes to system firmware and bootkits that execute before the operating system loads. MITRE notes that attackers can persist by overwriting legacy BIOS boot records such as the MBR or VBR, or by creating or modifying files in the EFI System Partition (ESP) on UEFI systems so attacker-controlled code runs during boot. Splunk also linked the bootloader-modification analytic to CVE-2024-7344, underscoring concern that EFI boot artifacts remain a high-value target for stealthy persistence and difficult-to-remediate compromise.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Splunk updated and published the "Linux Possible Bootloader Modification" analytic for Linux, which monitors processes modifying files in the EFI boot volume. The analytic is intended to surface unusual EFI boot file changes that may indicate bootkit activity or firmware persistence.
Splunk published the "Linux EFI Bootloader File Deletion" analytic to detect deleted .efi files under /boot/efi/EFI/BOOT/ on Linux. The detection is framed as a way to identify possible bootkit installation, firmware-level persistence, or tampering with the boot process.
MITRE ATT&CK published the T1542.001 System Firmware sub-technique entry covering firmware-level persistence behavior. This reference provides the ATT&CK technique context later used by related detections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.