Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0004 — Firmware Modification
DC0004

Firmware Modification

15 analytic(s) · 10 detection strategy(ies)

Description

Changes made to firmware, which may include its settings, configurations, or underlying data. This can encompass alterations to the Master Boot Record (MBR), Volume Boot Record (VBR), or other firmware components critical to system boot and functionality. Such modifications are often indicators of adversary activity, including malware persistence and system compromise. Examples: - Changes to Master Boot Record (MBR): Modifying the MBR to load malicious code during the boot process. - Changes to Volume Boot Record (VBR): Altering the VBR to redirect boot processes to malicious locations. - Firmware Configuration Changes: Modifying BIOS/UEFI settings such as disabling Secure Boot. - Firmware Image Tampering: Updating firmware with a malicious or unauthorized image. - Logs or Errors Indicating Firmware Changes: Logs showing unauthorized firmware updates or checksum mismatches. This data component can be collected through the following measures: - BIOS/UEFI Logs: Enable and monitor BIOS/UEFI logs to capture settings changes or firmware updates. - Firmware Integrity Monitoring: Use tools or firmware security features to detect changes to firmware components. - Endpoint Detection and Response (EDR) Solutions: Many EDR platforms can detect abnormal firmware activity, such as changes to MBR/VBR or unauthorized firmware updates. - File System Monitoring: Monitor changes to MBR/VBR-related files using tools like Sysmon or auditd. - Windows Example (Sysmon): Monitor Event ID 7 (Raw disk access). - Linux Example (auditd): `auditctl -w /dev/sda -p wa -k firmware_modification` - Network Traffic Analysis: Capture firmware updates downloaded over the network, particularly from untrusted sources. Use network monitoring tools like Zeek or Wireshark to analyze firmware-related traffic. - Secure Boot Logs: Collect and analyze Secure Boot logs for signs of tampering or unauthorized configurations. Example: Use PowerShell to retrieve Secure Boot settings on Windows: `Confirm-SecureBootUEFI` - Vendor-Specific Firmware Tools: Many hardware vendors provide tools for firmware integrity checks.Examples: - Intel Platform Firmware Resilience (PFR). - Lenovo UEFI diagnostics.

Referenced in Analytics

15
AN0246 Analytic 0246 DET0089

Keylogging on legacy network devices via unauthorized system image modification or remote capture of console keystrokes (telnet, SSH) through altered firmware or man-in-the-middle key sniffing.

networkdevice:syslog NSM:Flow
AN0276 Analytic 0276 DET0099

Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.

networkdevice:config networkdevice:runtime
AN0474 Analytic 0474 DET0167

Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Kernel-Boot
AN0475 Analytic 0475 DET0167

Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).

auditd:SYSCALL auditd:SYSCALL
AN0476 Analytic 0476 DET0167

EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.

macos:unifiedlog macos:unifiedlog
AN0477 Analytic 0477 DET0167

Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.

NSM:Flow networkdevice:firmware
AN0497 Analytic 0497 DET0175

Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.

networkdevice:config networkdevice:syslog NSM:Flow
AN0777 Analytic 0777 DET0278

Unexpected firmware image uploads via TFTP/FTP/SCP. Configuration changes modifying boot image pointers. Logs showing boot variable redirection to non-standard images. Anomalous reboots immediately following firmware changes not tied to patch schedules.

networkdevice:config networkdevice:firmware
AN0916 Analytic 0916 DET0323

Detection of anomalous driver and firmware interactions, including unsigned or unexpected firmware updates, driver loads linked to hardware components, and suspicious use of privileged APIs to read/write firmware or controller memory.

WinEventLog:Sysmon firmware:integrity
AN0917 Analytic 0917 DET0323

Detection of suspicious use of ioctl/sysfs calls to access device firmware, unexpected flashing tools execution, and anomalous firmware checksums logged by SMART or kernel audit mechanisms.

auditd:SYSCALL linux:syslog
AN0918 Analytic 0918 DET0323

Detection of EFI/firmware manipulation attempts via abnormal driver loads, unsigned kexts, or tampered NVRAM variables associated with component firmware configuration.

macos:unifiedlog
AN1024 Analytic 1024 DET0359

Encrypted traffic or ICMP tunneling from border routers to internal routers or unknown external IPs. Forwarded traffic shows consistent hop-to-hop relaying without matching configured VPN or expected network topology.

NSM:Flow NSM:Firewall networkdevice:syslog
AN1271 Analytic 1271 DET0461

Anomalous creation or mounting of hidden partitions or virtual file systems. Defender view: detection of registry modifications linked to non-standard file systems, suspicious disk I/O patterns, or bootkit-like behavior where hidden volumes are accessed outside normal file system APIs.

WinEventLog:Security WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Storage
AN1293 Analytic 1293 DET0469

Defenders may observe adversary attempts to patch system images by monitoring for anomalous file transfers (TFTP, SCP, FTP) of image files, unauthorized CLI commands altering boot system variables, integrity check mismatches between running and baseline OS images, and runtime memory manipulation attempts. Suspicious sequences include uploading a new image, modifying boot parameters, and subsequent reload/reboot of the device. In-memory patching attempts may manifest as debug commands or boot loader manipulation inconsistent with normal administrative activity.

networkdevice:cli networkdevice:config firmware:runtime
AN1603 Analytic 1603 DET0582

Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images.

networkdevice:config networkdevice:syslog NSM:Flow

Details

MITRE ID
DC0004
STIX ID
x-mitre-data-component--b9d031bb-d150-4fc6-8025-688201bf3ffd
Analytics
15
Detection Strategies
10
Leaving Threaticon

This link opens an external site that isn't part of the platform.