Techniques › T1495
T1495 Firmware Corruption
impact — Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
1
Sigma rules tagged attack.t1495
2
KEV CVEs mapped here
<p>Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards.</p><p>In general, adversaries may manipulate, overwrite, or corrupt firmware in order to deny the use of the system or devices. For example, corruption of firmware responsible for loading the operating system for network devices may render the network devices inoperable. Depending on the device, this attack may also result in Data Destruction.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2024-54085 | AMI MegaRAC SPx | primary impact | Mapped | 2025-06-25 |
| CVE-2025-21480 | Qualcomm Multiple Chipsets | primary impact | Mapped | 2025-06-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0167 Firmware Modification via Flash Tool or Corrupted Firmware Upload v1.0
AN0474 WindowsFirmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.WinEventLog:Microsoft-Windows-Kernel-Boot
Firmware integrity validation failed or boot configuration tampered→ DC0004 Firmware ModificationTunable:ParentImageCommandLineAN0475 LinuxDirect write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).Tunable:ToolNameAN0476 macOSEFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.macos:unifiedlogcom.apple.firmwareupdater activity or update-firmware binary invoked→ DC0032 Process CreationTunable:UpdateTimeWindowAN0477 Network DevicesFirmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.networkdevice:firmwareFirmware update initiated or bootloader tampering detected→ DC0004 Firmware ModificationTunable:UploadSizeThresholdRebootWindow
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1495
Author: Austin Clark
· 2019-08-15 (modified 2023-01-04) · logsource: product=cisco service=aaa · d94a35f0-7a29-45f6-90a0-80df6159967c
Detect a system being shutdown or put into different boot mode