Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0167 — Firmware Modification via Flash Tool or Corrupted Firmware Upload
DET0167

Firmware Modification via Flash Tool or Corrupted Firmware Upload

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0474 Analytic 0474
Windows

Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=6 WinEventLog:Microsoft-Windows-Kernel-Boot Firmware integrity validation failed or boot configuration tampered
[ParentImage] Common legitimate flash tool chains can be allowlisted
[CommandLine] Flags indicating silent or forced flash may vary
AN0475 Analytic 0475
Linux

Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).

auditd:SYSCALL write access to /dev/mem or /sys/firmware/efi/efivars auditd:SYSCALL execution of known flash tools (e.g., flashrom, fwupd)
[ToolName] Custom or renamed firmware tools may require pattern matching
AN0476 Analytic 0476
macOS

EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.

macos:unifiedlog com.apple.firmwareupdater activity or update-firmware binary invoked macos:unifiedlog boot failure events or SMC validation errors
[UpdateTimeWindow] Firmware updates usually occur after OS update; out-of-band patterns may indicate compromise
AN0477 Analytic 0477
Network Devices

Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.

NSM:Flow large upload to firmware interface port or path networkdevice:firmware Firmware update initiated or bootloader tampering detected
[UploadSizeThreshold] Size of firmware images varies by vendor
[RebootWindow] Reboots outside of patch maintenance may be suspicious

Detected Techniques

1

Details

MITRE ID
DET0167
STIX ID
x-mitre-detection-strategy--ab9027fb-3499-474b-845c-50ee113c3be5
Analytics
4
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.