System Firmware Exploitation
Parent: T2041
Description
Persistence at a pre-OS level can be gained modifying the firmware in a resource. System firmware is quite static, and it doesn't usually provide detections capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. (Citation: MITRE ATT&CK)
Mapped SPARTA techniques
2 techniques
T2041.001 'System Firmware Exploitation' covers the firmware-level subset of bootkit evasion (modifying firmware to remain undetected through normal logging/integrity checks).
T2041.001 'System Firmware Exploitation' is the defense-evasion-tactic counterpart of T1542.001 in SPACE-SHIELD; the same firmware-corruption activity is described, with tactic categorization differing.
Cite as SafeMode Space, space-shield T2041.001.