Techniques › T1542 › T1542.005
T1542.005 TFTP Boot
stealth · persistence — Network Devices · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1542.005
1
KEV CVEs mapped here
<p>Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images.</p><p>Adversaries may manipulate the configuration on the network device specifying use of a malicious TFTP server, which may be used in conjunction with Modify System Image to load a modified image on device startup or reset. The unauthorized image allows adversaries to modify device configuration, add malicious capabilities to the device, and introduce backdoors to maintain control of the network device while minimizing detection through use of a standard functionality. This technique is similar to ROMMONkit and may result in the network device running a modified image.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2017-6742 | Cisco IOS and IOS XE Software | secondary impact | Mapped | 2023-04-19 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0582 Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot v1.0
AN1603 Network DevicesDetection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images.networkdevice:config
Configuration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP servers→ DC0064 Command Executionnetworkdevice:syslogBoot information log showing image loaded from TFTP server instead of local storage→ DC0004 Firmware ModificationNSM:FlowUnexpected inbound/outbound TFTP traffic for device image files→ DC0082 Network Connection CreationTunable:ApprovedTFTPServersTimeWindowBaselineBootImageHash
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1542.005
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 1 actively exploited CVE maps here.