{
  "node_id": "mitre-attack-t1601-modify-system-image",
  "title": "MITRE ATT&CK T1601: Modify System Image (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1601 (Modify System Image) is an Enterprise Defense Evasion technique. Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file. To change the operating system, the adversary typically only needs to affect this one file, replacing or modifying it. ATT&CK documents 2 sub-techniques: T1601.001 Patch System Image; T1601.002 Downgrade System Image. Affected platforms: Network. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1027 Password Policies, M1043 Credential Access Protection, M1045 Code Signing, M1046 Boot Integrity, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CM-02, CM-03, CM-05.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}