kevmap

Log sources › networkdevice:firmware

networkdevice:firmware

Inverted view: what can be detected if this is the log you have. Network Devices

2
channels
2
analytics
2
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Firmware update initiated or bootloader tampering detected DC0004 Firmware Modification AN0477 1
Unexpected firmware image upload events via TFTP/FTP/SCP DC0046 Drive Modification AN0777 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1495 Firmware Corruptionimpact12
T1542 Pre-OS Bootstealth, persistence00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2024-54085AMI MegaRAC SPx T1495 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1495 Mapped