DEF CON 34 – Mickey Shkatov, Jesse Michael – Bring-Your-Own-Root-of-Trust firmware anomaly (unexpected boot chain signer)
This rule monitors for two critical firmware-related conditions: detected non-compliance with secure boot, UEFI, or TPM configuration standards via Microsoft Defender TVM, and explicit firmware or boot configuration change events reported by device telemetry. It is designed to identify potential tampering or misconfigurations that could facilitate bootkits or other pre-OS persistence mechanisms.
Microsoft Sentinel (KQL)

