{"id":"T1601","name":"Modify System Image","url":"https://attack.mitre.org/techniques/T1601","tactics":["defense-impairment"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0170","stix_id":"x-mitre-detection-strategy--536eed5d-a4b6-4377-a936-90283bb1b25c","name":"Detection Strategy for Modify System Image on Network Devices","url":"https://attack.mitre.org/detectionstrategies/DET0170","analytics":[{"id":"AN0482","stix_id":"x-mitre-analytic--868abb22-3d6c-4172-bf38-9e3c1aba4dae","name":"Analytic 0482","description":"Defenders may observe adversary attempts to alter or replace a network device’s operating system image through anomalous CLI commands, unexpected firmware updates, integrity check failures, or mismatches in version and checksum validation. Suspicious behavior includes modification of image files on storage, OS version output inconsistent with baselines, unexpected reloads or reboots after image replacement, and changes to boot configuration that load non-standard system images.","url":"https://attack.mitre.org/detectionstrategies/DET0170#AN0482","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"Execution of commands to load, copy, or replace system images (e.g., 'copy tftp flash', 'boot system')","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"},{"name":"networkdevice:config","channel":"Configuration changes to boot variables, startup image paths, or checksum verification failures","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkdevice-config"}],"mutable_elements":[{"field":"AuthorizedAdminAccounts","description":"Defines trusted administrator accounts allowed to modify system images; deviations indicate possible malicious modification."},{"field":"ApprovedFirmwareVersions","description":"Whitelist of validated vendor OS images; unexpected versions may suggest adversarial tampering."},{"field":"TimeWindow","description":"Correlation window for detecting config changes followed by firmware updates or reboots."},{"field":"ChecksumBaseline","description":"Baseline cryptographic hashes of approved system images; deviations may indicate compromise."}],"live":true,"detection_strategies":["DET0170"],"techniques":["T1601"]}],"live":true,"version":"1.0","techniques":["T1601"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2021-44168","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}