Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0175 — Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
DET0175

Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0497 Analytic 0497
Network Devices

Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.

networkdevice:config Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor) networkdevice:syslog Unexpected reload, crashinfo, or boot message not tied to scheduled maintenance NSM:Flow Outbound or inbound TFTP file transfers of ROMMON or firmware binaries
[ApprovedROMMONVersions] Baseline ROMMON image versions authorized for the environment
[TimeWindow] Correlation window between ROMMON update command, TFTP file transfer, and device reboot
[AdminUserContext] Expected privileged accounts allowed to execute ROMMON upgrade commands

Detected Techniques

1

Details

MITRE ID
DET0175
STIX ID
x-mitre-detection-strategy--c3924c07-255d-4df9-8357-a47e68c04bbb
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.