{"id":"T1542.004","name":"ROMMONkit","url":"https://attack.mitre.org/techniques/T1542/004","tactics":["stealth","persistence"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0175","stix_id":"x-mitre-detection-strategy--c3924c07-255d-4df9-8357-a47e68c04bbb","name":"Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit","url":"https://attack.mitre.org/detectionstrategies/DET0175","analytics":[{"id":"AN0497","stix_id":"x-mitre-analytic--ca649f9b-2a1f-4d45-b61b-33ac38d6a4ee","name":"Analytic 0497","description":"Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0175#AN0497","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:config","channel":"Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor)","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"networkdevice-config"},{"name":"networkdevice:syslog","channel":"Unexpected reload, crashinfo, or boot message not tied to scheduled maintenance","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"networkdevice-syslog"},{"name":"NSM:Flow","channel":"Outbound or inbound TFTP file transfers of ROMMON or firmware binaries","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ApprovedROMMONVersions","description":"Baseline ROMMON image versions authorized for the environment"},{"field":"TimeWindow","description":"Correlation window between ROMMON update command, TFTP file transfer, and device reboot"},{"field":"AdminUserContext","description":"Expected privileged accounts allowed to execute ROMMON upgrade commands"}],"live":true,"detection_strategies":["DET0175"],"techniques":["T1542.004"]}],"live":true,"version":"1.0","techniques":["T1542.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}