Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1564 | .005 | Hide Artifacts: Hidden File System |
BOOTRASH has used unallocated disk space between partitions for a hidden file system that stores components of the Nemesis bootkit.[2] |
Enterprise | T1542 | .003 | Pre-OS Boot: Bootkit |
BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence.[1][2][3] |