Cross-source coverage

T1542.005 / ATT&CK

Pre-OS Boot: TFTP Boot

1 rule across 1 source.

From MITRE ATT&CK 19.2

Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images.

Adversaries may manipulate the configuration on the network device specifying use of a malicious TFTP server, which may be used in conjunction with Modify System Image to load a modified image on device startup or reset. The unauthorized image allows adversaries to modify device configuration, add malicious capabilities to the device, and introduce backdoors to maintain control of the network device while minimizing detection through use of a standard functionality. This technique is similar to ROMMONkit and may result in the network device running a modified image.

Tactics
Stealth · Persistence
Platforms
Network Devices
Telemetry
networkdevice:confignetworkdevice:syslogNSM:Flow

How MITRE says to detect it DET0582

Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot

Network Devices Analytic 1603

Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images.

  • networkdevice:config Configuration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP servers
  • networkdevice:syslog Boot information log showing image loaded from TFTP server instead of local storage
  • NSM:Flow Unexpected inbound/outbound TFTP traffic for device image files

splunk/security_content

1 rule
Detection Severity Format
Detect Software Download To Network Device Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.