Modify System Image

T1601

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file.

To change the operating system, the adversary typically only needs to affect this one file, replacing or modifying it. This can either be done live in memory during system runtime for immediate effect, or in storage to implement the change on the next boot of the network device.

Detection rules1

Rules on DetectionCode tagged with T1601 or one of its sub-techniques.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData sourceTechnique
ESXi Download ErrorsAnomalyNULLVMWare ESXi SyslogT1601.001

Sub-techniques2

IDNameExamples
T1601.001Patch System Image1
T1601.002Downgrade System Image0

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareDRYHOOK

DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.