MITRE ATT&CK ICS
T1693

Modify Firmware

Description

Firmware is low-level software embedded in hardware that enables systems and devices to function properly and is commonly found in ICS environments. Adversaries may modify firmware on a system or device by installing malicious or vulnerable versions that enable them to achieve objectives such as [Persistence](https://attack.mitre.org/tactics/TA0110), [Impair Process Control](https://attack.mitre.org/tactics/TA0106), and [Inhibit Response Function](https://attack.mitre.org/tactics/TA0107). Adversaries may modify system and device firmware by using the built-in firmware update functionality which may support local or remote installation. The malicious or vulnerable firmware may be delivered via [Replication Through Removable Media](https://attack.mitre.org/techniques/T0847), [Supply Chain Compromise](https://attack.mitre.org/techniques/T0862), or [Remote Services](https://attack.mitre.org/techniques/T0886). Once installed, the malicious or vulnerable firmware could be used to provide [Rootkit](https://attack.mitre.org/techniques/T0851) and [Hooking](https://attack.mitre.org/techniques/T0874) functionality, [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T0890), or [Denial of Service](https://attack.mitre.org/techniques/T0814).(Citation: Basnight, Zachry, et al.)

Mapped SPARTA techniques

4 techniques

  • T1693 'Modify Firmware' addresses adversary firmware modification at parent level; SPARTA EX-0005 'Exploit Hardware/Firmware Corruption' covers the broader firmware-exploitation pattern. Cross-tactic moderate (persistence/inhibit/impair vs execution).

  • EX-0005.01Design FlawsST0004
    addresses
    moderate

    Hardware/firmware design flaws are exploited via firmware modification or replacement; T1693 'Modify Firmware' covers the post-exploitation activity at cross-tactic moderate level (the design-flaw aspect is the entry point, the firmware modification is the action).

  • Modifying communications configuration to create covert downlink/crosslink paths is typically achieved by firmware modification on radio/transponder modules; T1693 'Modify Firmware' covers this firmware-level reconfiguration at parent level. Cross-tactic moderate (T1693 family in persistence/inhibit-response-function/impair-process-control vs SPARTA EXF-0006 exfiltration); ICS has no exfiltration tactic.

  • PER-0001Memory CompromiseST0005
    addresses
    moderate

    T1693 'Modify Firmware' covers adversary firmware modification; SPARTA PER-0001 'Memory Compromise' includes firmware-level memory compromise as one persistence path (alongside RAM/flash compromise). T1693 family is in persistence (among others); tactic-aligned moderate complementing T0889.

Cite as SafeMode Space, mitre-attack-ics T1693.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.