ESA SPACE-SHIELD
T1542.001
enhancement

System Firmware Exploitation

Parent: T1542

Description

Persistence at a pre-OS level can be gained modifying the firmware in a resource. System firmware is quite static, and it doesn't usually provide detections capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

3 techniques

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate

    T1542.001 'System Firmware Exploitation' covers the firmware-image manipulation subset of EX-0004 (replacing/patching boot images, flipping configuration bits in non-volatile storage).

  • T1542.001 'System Firmware Exploitation' is the direct cross-framework counterpart of EX-0005 Exploit Hardware/Firmware Corruption — both describe corrupting firmware images, configuration blobs, and bitstreams below the software stack.

  • EX-0010.04BootkitST0004
    addresses
    moderate

    T1542.001 'System Firmware Exploitation' covers the firmware-level subset of EX-0010.04 Bootkit (modifying firmware to redirect image selection or patch kernel/binaries before integrity verification).

Cite as SafeMode Space, space-shield T1542.001.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.