{"id":"T1495","name":"Firmware Corruption","url":"https://attack.mitre.org/techniques/T1495","tactics":["impact"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0167","stix_id":"x-mitre-detection-strategy--ab9027fb-3499-474b-845c-50ee113c3be5","name":"Firmware Modification via Flash Tool or Corrupted Firmware Upload","url":"https://attack.mitre.org/detectionstrategies/DET0167","analytics":[{"id":"AN0474","stix_id":"x-mitre-analytic--a0ecdd41-a051-4ada-9ec1-c29dc0c4ac61","name":"Analytic 0474","description":"Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.","url":"https://attack.mitre.org/detectionstrategies/DET0167#AN0474","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-Kernel-Boot","channel":"Firmware integrity validation failed or boot configuration tampered","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"wineventlog-microsoft-windows-kernel-boot"}],"mutable_elements":[{"field":"ParentImage","description":"Common legitimate flash tool chains can be allowlisted"},{"field":"CommandLine","description":"Flags indicating silent or forced flash may vary"}],"live":true,"detection_strategies":["DET0167"],"techniques":["T1495"]},{"id":"AN0475","stix_id":"x-mitre-analytic--5b1514b3-e35b-4ea8-bcc1-b8e492d6d3cd","name":"Analytic 0475","description":"Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).","url":"https://attack.mitre.org/detectionstrategies/DET0167#AN0475","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"write access to /dev/mem or /sys/firmware/efi/efivars","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execution of known flash tools (e.g., flashrom, fwupd)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ToolName","description":"Custom or renamed firmware tools may require pattern matching"}],"live":true,"detection_strategies":["DET0167"],"techniques":["T1495"]},{"id":"AN0476","stix_id":"x-mitre-analytic--df32865a-79b2-4faa-abd4-3ecfa27c8a77","name":"Analytic 0476","description":"EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.","url":"https://attack.mitre.org/detectionstrategies/DET0167#AN0476","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"com.apple.firmwareupdater activity or update-firmware binary invoked","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"boot failure events or SMC validation errors","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UpdateTimeWindow","description":"Firmware updates usually occur after OS update; out-of-band patterns may indicate compromise"}],"live":true,"detection_strategies":["DET0167"],"techniques":["T1495"]},{"id":"AN0477","stix_id":"x-mitre-analytic--39d675d5-548d-4b35-8a8f-a6605ae3835d","name":"Analytic 0477","description":"Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.","url":"https://attack.mitre.org/detectionstrategies/DET0167#AN0477","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"large upload to firmware interface port or path","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"networkdevice:firmware","channel":"Firmware update initiated or bootloader tampering detected","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"networkdevice-firmware"}],"mutable_elements":[{"field":"UploadSizeThreshold","description":"Size of firmware images varies by vendor"},{"field":"RebootWindow","description":"Reboots outside of patch maintenance may be suspicious"}],"live":true,"detection_strategies":["DET0167"],"techniques":["T1495"]}],"live":true,"version":"1.0","techniques":["T1495"]}],"sigma_rules":[{"id":"d94a35f0-7a29-45f6-90a0-80df6159967c","title":"Cisco Denial of Service","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-15","modified":"2023-01-04","description":"Detect a system being shutdown or put into different boot mode","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.impact","attack.t1495","attack.t1529","attack.t1565.001"],"path":"rules/network/cisco/aaa/cisco_cli_dos.yml","techniques":["T1495","T1529","T1565.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-54085","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-21480","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}