Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-532 — Altered Installed BIOS
CAPEC-532

Altered Installed BIOS

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. An attacker with access to download and update system software sends a maliciously altered BIOS to the victim or victim supplier/integrator, which when installed allows for future exploitation.

Mitigation

Deploy strong code integrity policies to allow only authorized apps to run. | Use endpoint detection and response solutions that can automaticalkly detect and remediate suspicious activities. | Maintain a highly secure build and update infrastructure by immediately applying security patches for OS and software, implementing mandatory integrity controls to ensure only trusted tools run, and requiring multi-factor authentication for admins. | Require SSL for update channels and implement certificate transparency based verification. | Sign update packages and BIOS patches.

Details

Platforms
Supply-chain
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.