Detection of malicious code being executed or loaded into boot memory, indicated by a failed memory integrity check.
ID | Name | Description | |
EX-0004 | Compromise Boot Memory | Threat actors may manipulate boot memory in order to execute malicious code, bypass internal processes, or DoS the system. This technique can be used to perform other tactics such as Defense Evasion. |