{"id":"T1195.003","name":"Compromise Hardware Supply Chain","url":"https://attack.mitre.org/techniques/T1195/003","tactics":["initial-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0368","stix_id":"x-mitre-detection-strategy--4dfcf95f-0bbb-4ae7-8bd5-91e3e6c51809","name":"Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks","url":"https://attack.mitre.org/detectionstrategies/DET0368","analytics":[{"id":"AN1035","stix_id":"x-mitre-analytic--8ba8d516-486a-4347-9a48-56a312e83897","name":"Analytic 1035","description":"Detects tampered hardware or firmware via anomalous host status telemetry. Behavioral chain: (1) Pre-OS or firmware components exhibit unexpected version changes, signature failures, or modified boot paths; (2) System management/firmware tools log hardware inventory drift; (3) Sensor health telemetry or boot attestation events fail baseline checks; (4) Follow-on process execution from altered firmware or unknown drivers after boot.","url":"https://attack.mitre.org/detectionstrategies/DET0368#AN1035","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=1166, 7045","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Microsoft-Windows-CodeIntegrity/Operational","channel":"Code integrity violations in boot-start drivers or firmware","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-microsoft-windows-codeintegrity-operational"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"BaselineFirmwareVersion","description":"Expected firmware/BIOS version for each hardware model."},{"field":"BaselineDriverList","description":"Approved boot-start drivers."},{"field":"IntegrityCheckInterval","description":"Frequency of integrity checks (e.g., daily, weekly)."}],"live":true,"detection_strategies":["DET0368"],"techniques":["T1195.003"]},{"id":"AN1036","stix_id":"x-mitre-analytic--1c25310b-d8fa-472d-a10e-c327a8fba693","name":"Analytic 1036","description":"Monitors for hardware or firmware tampering by correlating system boot logs, hardware inventory changes, and secure boot/firmware verification failures. Behavioral chain: (1) UEFI/BIOS version drift; (2) secure boot disabled or signature verification errors; (3) unexpected modules or hardware devices enumerated at boot; (4) new device firmware images loaded from non-approved sources.","url":"https://attack.mitre.org/detectionstrategies/DET0368#AN1036","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"firmware_update, kexec_load","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"auditd-syscall"},{"name":"fwupd:logs","channel":"Firmware updates applied or failed","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"fwupd-logs"}],"mutable_elements":[{"field":"ApprovedFirmwareHashes","description":"List of SHA256/SHA512 firmware hashes allowed."},{"field":"AllowedDeviceIDs","description":"Known hardware component IDs per host baseline."}],"live":true,"detection_strategies":["DET0368"],"techniques":["T1195.003"]},{"id":"AN1037","stix_id":"x-mitre-analytic--0834f268-5810-4a90-8ef6-279dc0482471","name":"Analytic 1037","description":"Detects tampered Mac hardware/firmware by analyzing unified logs, EndpointSecurity events, and Apple Mobile File Integrity (AMFI) checks. Behavioral chain: (1) Boot process reports firmware signature mismatch; (2) Secure Boot policy altered; (3) new EFI drivers or hardware devices appear in inventory; (4) system extension loads from unapproved developer IDs post-boot.","url":"https://attack.mitre.org/detectionstrategies/DET0368#AN1037","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"EFI firmware integrity check failed","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"es_event_authentication","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"AllowedTeamIDs","description":"Developer Team IDs approved for kext/system extension loads."},{"field":"FirmwareVersionBaseline","description":"Expected EFI/firmware version for Mac model."}],"live":true,"detection_strategies":["DET0368"],"techniques":["T1195.003"]}],"live":true,"version":"1.0","techniques":["T1195.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}