kevmap

TechniquesT1542.004 › AN0497

AN0497 Analytic 0497

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.</p>
Detects
T1542.004 ROMMONkit
Part of
DET0175 Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:configLog entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor)DC0004 Firmware Modification
networkdevice:syslogUnexpected reload, crashinfo, or boot message not tied to scheduled maintenanceDC0021 OS API Execution
NSM:FlowOutbound or inbound TFTP file transfers of ROMMON or firmware binariesDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ApprovedROMMONVersionsBaseline ROMMON image versions authorized for the environment
TimeWindowCorrelation window between ROMMON update command, TFTP file transfer, and device reboot
AdminUserContextExpected privileged accounts allowed to execute ROMMON upgrade commands