What MITRE ATT&CK ICS T1693.001: System Firmware (ICS Tactic TA0110 - Persistence) requires
MITRE ATT&CK ICS T1693.001 (System Firmware) is an ICS Persistence, Inhibit Response Function, Impair Process Control technique. System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment. When available, the firmware update feature enables vendors to remotely patch bugs and perform upgrades. Device firmware updates are often delegated to the user and may be done using a software update package. It may also be possible to perform this task over the network. An adversary may exploit the firmware update feature on accessible devices to upload malicious or out-of-date firmware. Malicious modification of device firmware may provide an adversary with root access to a device, given firmware is one of the lowest programming abstraction layers. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1693. ATT&CK-mapped mitigations: M0804 Human User Authentication, M0808 Encrypt Network Traffic, M0947 Audit, M0813 Software Process and Device Authentication, M0937 Filter Network Traffic, M0941 Encrypt Sensitive Information, M0801 Access Management, M0802 Communication Authenticity, M0930 Network Segmentation, M0807 Network Allowlists, M0946 Boot Integrity, M0951 Update Software, M0945 Code Signing.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1693/001/
SHA-256 integrity: 9cfecd9c58c356876766656c08361f4eeb23064e433383d3b44420845fd80f21
Primary Citations — 19 traced to source
- MITRE ATT&CK ICS Technique T1693.001: System Firmware (https://attack.mitre.org/techniques/T1693/001/)
- MITRE ATT&CK ICS Tactic TA0110: Persistence (https://attack.mitre.org/tactics/TA0110/)
+ 17 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-ics-t1693-001-system-firmware.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-ics-t1693-001-system-firmware.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-ics-t1693-001-system-firmware
- Back to registry: Browse all 10,085 compliance nodes