Modify Firmware
Description
Firmware is low-level software embedded in hardware that enables systems and devices to function properly and is commonly found in ICS environments. Adversaries may modify firmware on a system or device by installing malicious or vulnerable versions that enable them to achieve objectives such as [Persistence](https://attack.mitre.org/tactics/TA0110), [Impair Process Control](https://attack.mitre.org/tactics/TA0106), and [Inhibit Response Function](https://attack.mitre.org/tactics/TA0107). Adversaries may modify system and device firmware by using the built-in firmware update functionality which may support local or remote installation. The malicious or vulnerable firmware may be delivered via [Replication Through Removable Media](https://attack.mitre.org/techniques/T0847), [Supply Chain Compromise](https://attack.mitre.org/techniques/T0862), or [Remote Services](https://attack.mitre.org/techniques/T0886). Once installed, the malicious or vulnerable firmware could be used to provide [Rootkit](https://attack.mitre.org/techniques/T0851) and [Hooking](https://attack.mitre.org/techniques/T0874) functionality, [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T0890), or [Denial of Service](https://attack.mitre.org/techniques/T0814).(Citation: Basnight, Zachry, et al.)
Mapped SPARTA techniques
4 techniques
T1693 'Modify Firmware' addresses adversary firmware modification at parent level; SPARTA EX-0005 'Exploit Hardware/Firmware Corruption' covers the broader firmware-exploitation pattern. Cross-tactic moderate (persistence/inhibit/impair vs execution).
Hardware/firmware design flaws are exploited via firmware modification or replacement; T1693 'Modify Firmware' covers the post-exploitation activity at cross-tactic moderate level (the design-flaw aspect is the entry point, the firmware modification is the action).
Modifying communications configuration to create covert downlink/crosslink paths is typically achieved by firmware modification on radio/transponder modules; T1693 'Modify Firmware' covers this firmware-level reconfiguration at parent level. Cross-tactic moderate (T1693 family in persistence/inhibit-response-function/impair-process-control vs SPARTA EXF-0006 exfiltration); ICS has no exfiltration tactic.
T1693 'Modify Firmware' covers adversary firmware modification; SPARTA PER-0001 'Memory Compromise' includes firmware-level memory compromise as one persistence path (alongside RAM/flash compromise). T1693 family is in persistence (among others); tactic-aligned moderate complementing T0889.
Cite as SafeMode Space, mitre-attack-ics T1693.