Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0582 — Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
DET0582

Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1603 Analytic 1603
Network Devices

Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images.

networkdevice:config Configuration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP servers networkdevice:syslog Boot information log showing image loaded from TFTP server instead of local storage NSM:Flow Unexpected inbound/outbound TFTP traffic for device image files
[ApprovedTFTPServers] Whitelist of TFTP servers authorized for netbooting in the environment
[TimeWindow] Detection correlation window between config change, TFTP activity, and system reboot
[BaselineBootImageHash] Expected system image hashes to validate integrity of boot images loaded via TFTP

Detected Techniques

1

Details

MITRE ID
DET0582
STIX ID
x-mitre-detection-strategy--8f6ddd50-aeb8-48ae-8f4a-83b314829ca3
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.