Cross-source coverage
T1542.005 / ATT&CK
Pre-OS Boot: TFTP Boot
1 rule across 1 source.
From MITRE ATT&CK 19.2
Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images.
Adversaries may manipulate the configuration on the network device specifying use of a malicious TFTP server, which may be used in conjunction with Modify System Image to load a modified image on device startup or reset. The unauthorized image allows adversaries to modify device configuration, add malicious capabilities to the device, and introduce backdoors to maintain control of the network device while minimizing detection through use of a standard functionality. This technique is similar to ROMMONkit and may result in the network device running a modified image.
- Tactics
- Stealth · Persistence
- Platforms
- Network Devices
- Telemetry
-
networkdevice:confignetworkdevice:syslogNSM:Flow
How MITRE says to detect it DET0582
Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
Network Devices Analytic 1603
Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images.
networkdevice:configConfiguration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP serversnetworkdevice:syslogBoot information log showing image loaded from TFTP server instead of local storageNSM:FlowUnexpected inbound/outbound TFTP traffic for device image files
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Detect Software Download To Network Device | Undefined | SPL |