Techniques › T1542 › T1542.004
T1542.004 ROMMONkit
stealth · persistence — Network Devices · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1542.004
0
KEV CVEs mapped here
<p>Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.</p><p>ROMMON is a Cisco network device firmware that functions as a boot loader, boot image, or boot helper to initialize hardware and software when the platform is powered on or reset. Similar to TFTP Boot, an adversary may upgrade the ROMMON image locally or remotely (for example, through TFTP) with adversary code and restart the device in order to overwrite the existing ROMMON image. This provides adversaries with the means to update the ROMMON to gain persistence on a system in a way that may be difficult to detect.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0175 Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit v1.0
AN0497 Network DevicesDetection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.networkdevice:config
Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor)→ DC0004 Firmware Modificationnetworkdevice:syslogUnexpected reload, crashinfo, or boot message not tied to scheduled maintenance→ DC0021 OS API ExecutionNSM:FlowOutbound or inbound TFTP file transfers of ROMMON or firmware binaries→ DC0082 Network Connection CreationTunable:ApprovedROMMONVersionsTimeWindowAdminUserContext
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1542.004
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.