Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0170 — Detection Strategy for Modify System Image on Network Devices
DET0170

Detection Strategy for Modify System Image on Network Devices

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0482 Analytic 0482
Network Devices

Defenders may observe adversary attempts to alter or replace a network device’s operating system image through anomalous CLI commands, unexpected firmware updates, integrity check failures, or mismatches in version and checksum validation. Suspicious behavior includes modification of image files on storage, OS version output inconsistent with baselines, unexpected reloads or reboots after image replacement, and changes to boot configuration that load non-standard system images.

networkdevice:cli Execution of commands to load, copy, or replace system images (e.g., 'copy tftp flash', 'boot system') networkdevice:config Configuration changes to boot variables, startup image paths, or checksum verification failures
[AuthorizedAdminAccounts] Defines trusted administrator accounts allowed to modify system images; deviations indicate possible malicious modification.
[ApprovedFirmwareVersions] Whitelist of validated vendor OS images; unexpected versions may suggest adversarial tampering.
[TimeWindow] Correlation window for detecting config changes followed by firmware updates or reboots.
[ChecksumBaseline] Baseline cryptographic hashes of approved system images; deviations may indicate compromise.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0170
STIX ID
x-mitre-detection-strategy--536eed5d-a4b6-4377-a936-90283bb1b25c
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.