Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0368 — Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks
DET0368

Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1035 Analytic 1035
Windows

Detects tampered hardware or firmware via anomalous host status telemetry. Behavioral chain: (1) Pre-OS or firmware components exhibit unexpected version changes, signature failures, or modified boot paths; (2) System management/firmware tools log hardware inventory drift; (3) Sensor health telemetry or boot attestation events fail baseline checks; (4) Follow-on process execution from altered firmware or unknown drivers after boot.

WinEventLog:Security EventCode=1166, 7045 WinEventLog:Microsoft-Windows-CodeIntegrity/Operational Code integrity violations in boot-start drivers or firmware WinEventLog:Sysmon EventCode=6 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10
[BaselineFirmwareVersion] Expected firmware/BIOS version for each hardware model.
[BaselineDriverList] Approved boot-start drivers.
[IntegrityCheckInterval] Frequency of integrity checks (e.g., daily, weekly).
AN1036 Analytic 1036
Linux

Monitors for hardware or firmware tampering by correlating system boot logs, hardware inventory changes, and secure boot/firmware verification failures. Behavioral chain: (1) UEFI/BIOS version drift; (2) secure boot disabled or signature verification errors; (3) unexpected modules or hardware devices enumerated at boot; (4) new device firmware images loaded from non-approved sources.

auditd:SYSCALL firmware_update, kexec_load fwupd:logs Firmware updates applied or failed
[ApprovedFirmwareHashes] List of SHA256/SHA512 firmware hashes allowed.
[AllowedDeviceIDs] Known hardware component IDs per host baseline.
AN1037 Analytic 1037
macOS

Detects tampered Mac hardware/firmware by analyzing unified logs, EndpointSecurity events, and Apple Mobile File Integrity (AMFI) checks. Behavioral chain: (1) Boot process reports firmware signature mismatch; (2) Secure Boot policy altered; (3) new EFI drivers or hardware devices appear in inventory; (4) system extension loads from unapproved developer IDs post-boot.

macos:unifiedlog EFI firmware integrity check failed macos:endpointsecurity es_event_authentication
[AllowedTeamIDs] Developer Team IDs approved for kext/system extension loads.
[FirmwareVersionBaseline] Expected EFI/firmware version for Mac model.

Detected Techniques

1

Details

MITRE ID
DET0368
STIX ID
x-mitre-detection-strategy--4dfcf95f-0bbb-4ae7-8bd5-91e3e6c51809
Analytics
3
Techniques Detected
1
By Tactic
Initial Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.