kevmap

TechniquesT1542.001 › AN0276

AN0276 Analytic 0276

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.</p>
Detects
T1542.001 System Firmware
Part of
DET0099 Detection Strategy for T1542.001 Pre-OS Boot: System Firmware

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:configBoot image path or firmware configuration variable modified outside of maintenance windowsDC0004 Firmware Modification
networkdevice:runtimeFirmware image uploaded via TFTP/FTP/SCPDC0046 Drive Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ApprovedFirmwareHashesKnown good firmware image hashes stored for validation.
MaintenanceWindowsExpected time periods when firmware uploads or reboots are considered normal.
SourceIPWhitelistList of trusted management IPs allowed to initiate firmware uploads.