ESA SPACE-SHIELD
T2041.001
enhancement

System Firmware Exploitation

Parent: T2041

Description

Persistence at a pre-OS level can be gained modifying the firmware in a resource. System firmware is quite static, and it doesn't usually provide detections capabilities. A firmware level manipulation can remain unnoticed until next phases of the attack. (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

2 techniques

  • DE-0008Evasion via BootkitST0006
    addresses
    moderate

    T2041.001 'System Firmware Exploitation' covers the firmware-level subset of bootkit evasion (modifying firmware to remain undetected through normal logging/integrity checks).

  • T2041.001 'System Firmware Exploitation' is the defense-evasion-tactic counterpart of T1542.001 in SPACE-SHIELD; the same firmware-corruption activity is described, with tactic categorization differing.

Cite as SafeMode Space, space-shield T2041.001.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.