{"id":"T1601.001","name":"Patch System Image","url":"https://attack.mitre.org/techniques/T1601/001","tactics":["defense-impairment"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0469","stix_id":"x-mitre-detection-strategy--ca16d7e8-77f3-4d0c-88a3-31696224ed67","name":"Detection Strategy for Patch System Image on Network Devices","url":"https://attack.mitre.org/detectionstrategies/DET0469","analytics":[{"id":"AN1293","stix_id":"x-mitre-analytic--bf64c48c-5834-426c-be21-6db0efbc7909","name":"Analytic 1293","description":"Defenders may observe adversary attempts to patch system images by monitoring for anomalous file transfers (TFTP, SCP, FTP) of image files, unauthorized CLI commands altering boot system variables, integrity check mismatches between running and baseline OS images, and runtime memory manipulation attempts. Suspicious sequences include uploading a new image, modifying boot parameters, and subsequent reload/reboot of the device. In-memory patching attempts may manifest as debug commands or boot loader manipulation inconsistent with normal administrative activity.","url":"https://attack.mitre.org/detectionstrategies/DET0469#AN1293","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"Execution of privileged commands such as 'copy tftp flash', 'boot system', or 'debug memory'","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"},{"name":"networkdevice:config","channel":"Configuration changes to startup image paths, boot loader parameters, or debug flags","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkdevice-config"},{"name":"firmware:runtime","channel":"Debug or memory access commands indicating attempts to alter OS instructions in memory","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"firmware-runtime"}],"mutable_elements":[{"field":"ApprovedFirmwareVersions","description":"Whitelist of validated vendor OS versions; deviations may indicate tampering."},{"field":"AuthorizedAdminAccounts","description":"Trusted admin accounts permitted to update images; anomalies suggest compromise."},{"field":"ChecksumBaseline","description":"Baseline hash of approved images; used for detecting file tampering."},{"field":"TimeWindow","description":"Correlation period for detecting chained behaviors (file upload → boot config change → reboot)."}],"live":true,"detection_strategies":["DET0469"],"techniques":["T1601.001"]}],"live":true,"version":"1.0","techniques":["T1601.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}