MITRE ATT&CK ICS
T1693.001
enhancement

System Firmware

Parent: T1693

Description

System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment. When available, the firmware update feature enables vendors to remotely patch bugs and perform upgrades. Device firmware updates are often delegated to the user and may be done using a software update package. It may also be possible to perform this task over the network. An adversary may exploit the firmware update feature on accessible devices to upload malicious or out-of-date firmware. Malicious modification of device firmware may provide an adversary with root access to a device, given firmware is one of the lowest programming abstraction layers.(Citation: Basnight, Zachry, et al.)

Mapped SPARTA techniques

4 techniques

  • DE-0008Evasion via BootkitST0006
    addresses
    moderate

    Bootkits reside in system firmware; T1693.001 'System Firmware' addresses adversary modification of system firmware which is the residence layer for bootkit installation. Cross-tactic moderate (T1693 family in persistence/inhibit-response-function/impair-process-control vs SPARTA DE-0008 defense-evasion); ICS doesn't have a specific Bootkit sub-technique.

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate

    T1693.001 'System Firmware' addresses adversary modification of system firmware; SPARTA EX-0004 'Compromise Boot Memory' covers boot-memory compromise (bootloader, boot ROM, flash boot images) — equivalent firmware-level activity. Cross-tactic moderate (T1693 family sits in persistence/inhibit-response-function/impair-process-control while SPARTA EX-0004 is execution).

  • EX-0010.04BootkitST0004
    addresses
    moderate

    Bootkits reside in system firmware below the OS layer; T1693.001 'System Firmware' addresses adversary modification of system firmware which is the residence layer for bootkit implants. Cross-tactic moderate (T1693 family in persistence/inhibit/impair vs SPARTA EX-0010.04 execution); ICS has no specific Bootkit sub-technique.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate

    SDR reconfiguration (adding subcarriers, changing modulation, scheduling maintenance bursts) is achieved by modifying the SDR's system firmware; T1693.001 'System Firmware' covers this firmware-level reconfiguration. Cross-tactic moderate (persistence/inhibit-response-function/impair-process-control vs exfiltration).

Cite as SafeMode Space, mitre-attack-ics T1693.001.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.