Techniques › T1542.004 › AN0497
AN0497 Analytic 0497
Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.</p>
- Detects
- T1542.004 ROMMONkit
- Part of
- DET0175 Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| networkdevice:config | Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor) | DC0004 Firmware Modification |
| networkdevice:syslog | Unexpected reload, crashinfo, or boot message not tied to scheduled maintenance | DC0021 OS API Execution |
| NSM:Flow | Outbound or inbound TFTP file transfers of ROMMON or firmware binaries | DC0082 Network Connection Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ApprovedROMMONVersions | Baseline ROMMON image versions authorized for the environment |
TimeWindow | Correlation window between ROMMON update command, TFTP file transfer, and device reboot |
AdminUserContext | Expected privileged accounts allowed to execute ROMMON upgrade commands |