Techniques › T1542.001 › AN0276
AN0276 Analytic 0276
Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.</p>
- Detects
- T1542.001 System Firmware
- Part of
- DET0099 Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| networkdevice:config | Boot image path or firmware configuration variable modified outside of maintenance windows | DC0004 Firmware Modification |
| networkdevice:runtime | Firmware image uploaded via TFTP/FTP/SCP | DC0046 Drive Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ApprovedFirmwareHashes | Known good firmware image hashes stored for validation. |
MaintenanceWindows | Expected time periods when firmware uploads or reboots are considered normal. |
SourceIPWhitelist | List of trusted management IPs allowed to initiate firmware uploads. |