System Firmware Exploitation
Parent: T1542
Description
Persistence at a pre-OS level can be gained modifying the firmware in a resource. System firmware is quite static, and it doesn't usually provide detections capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. (Citation: MITRE ATT&CK)
Mapped SPARTA techniques
3 techniques
T1542.001 'System Firmware Exploitation' covers the firmware-image manipulation subset of EX-0004 (replacing/patching boot images, flipping configuration bits in non-volatile storage).
T1542.001 'System Firmware Exploitation' is the direct cross-framework counterpart of EX-0005 Exploit Hardware/Firmware Corruption — both describe corrupting firmware images, configuration blobs, and bitstreams below the software stack.
T1542.001 'System Firmware Exploitation' covers the firmware-level subset of EX-0010.04 Bootkit (modifying firmware to redirect image selection or patch kernel/binaries before integrity verification).
Cite as SafeMode Space, space-shield T1542.001.