Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0469 — Detection Strategy for Patch System Image on Network Devices
DET0469

Detection Strategy for Patch System Image on Network Devices

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1293 Analytic 1293
Network Devices

Defenders may observe adversary attempts to patch system images by monitoring for anomalous file transfers (TFTP, SCP, FTP) of image files, unauthorized CLI commands altering boot system variables, integrity check mismatches between running and baseline OS images, and runtime memory manipulation attempts. Suspicious sequences include uploading a new image, modifying boot parameters, and subsequent reload/reboot of the device. In-memory patching attempts may manifest as debug commands or boot loader manipulation inconsistent with normal administrative activity.

networkdevice:cli Execution of privileged commands such as 'copy tftp flash', 'boot system', or 'debug memory' networkdevice:config Configuration changes to startup image paths, boot loader parameters, or debug flags firmware:runtime Debug or memory access commands indicating attempts to alter OS instructions in memory
[ApprovedFirmwareVersions] Whitelist of validated vendor OS versions; deviations may indicate tampering.
[AuthorizedAdminAccounts] Trusted admin accounts permitted to update images; anomalies suggest compromise.
[ChecksumBaseline] Baseline hash of approved images; used for detecting file tampering.
[TimeWindow] Correlation period for detecting chained behaviors (file upload → boot config change → reboot).

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0469
STIX ID
x-mitre-detection-strategy--ca16d7e8-77f3-4d0c-88a3-31696224ed67
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.