{"id":"T1542.002","name":"Component Firmware","url":"https://attack.mitre.org/techniques/T1542/002","tactics":["stealth","persistence"],"platforms":["Windows","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0323","stix_id":"x-mitre-detection-strategy--a53d62ae-b269-45e8-9937-17def4e28663","name":"Detection Strategy for T1542.002 Pre-OS Boot: Component Firmware","url":"https://attack.mitre.org/detectionstrategies/DET0323","analytics":[{"id":"AN0916","stix_id":"x-mitre-analytic--6f2fdf37-f603-4264-aed1-24fe2d1aa094","name":"Analytic 0916","description":"Detection of anomalous driver and firmware interactions, including unsigned or unexpected firmware updates, driver loads linked to hardware components, and suspicious use of privileged APIs to read/write firmware or controller memory.","url":"https://attack.mitre.org/detectionstrategies/DET0323#AN0916","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"firmware:integrity ","channel":"Firmware integrity verification failures or mismatches against expected UEFI/firmware image baselines","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"firmware-integrity"}],"mutable_elements":[{"field":"KnownGoodFirmwareHashes","description":"Environment-specific list of baseline firmware images for integrity comparison"},{"field":"DriverAllowList","description":"Drivers approved for loading in production environments"},{"field":"TimeWindow","description":"Correlation period between firmware modification attempt and abnormal driver or process behavior"}],"live":true,"detection_strategies":["DET0323"],"techniques":["T1542.002"]},{"id":"AN0917","stix_id":"x-mitre-analytic--062580eb-eb79-4b31-b3fd-e500ebcfc128","name":"Analytic 0917","description":"Detection of suspicious use of ioctl/sysfs calls to access device firmware, unexpected flashing tools execution, and anomalous firmware checksums logged by SMART or kernel audit mechanisms.","url":"https://attack.mitre.org/detectionstrategies/DET0323#AN0917","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"ioctl/write: Direct firmware update or device memory manipulation syscalls","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Driver load events or firmware load failures for hardware devices","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"FirmwareImageBaseline","description":"Baseline firmware checksums for comparison"},{"field":"AlertThresholds","description":"Tolerance levels for SMART errors before triggering alerts"}],"live":true,"detection_strategies":["DET0323"],"techniques":["T1542.002"]},{"id":"AN0918","stix_id":"x-mitre-analytic--c89e4f72-a563-4665-9934-14b9efe88a06","name":"Analytic 0918","description":"Detection of EFI/firmware manipulation attempts via abnormal driver loads, unsigned kexts, or tampered NVRAM variables associated with component firmware configuration.","url":"https://attack.mitre.org/detectionstrategies/DET0323#AN0918","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Firmware update events or kernel extension (kext) loads not signed by Apple","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ApprovedKextList","description":"List of trusted and signed kexts permitted in production systems"},{"field":"EFIHashBaseline","description":"Known-clean EFI image hashes used for verification"}],"live":true,"detection_strategies":["DET0323"],"techniques":["T1542.002"]}],"live":true,"version":"1.0","techniques":["T1542.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}