What MITRE ATT&CK ICS T1693: Modify Firmware (ICS Tactic TA0110 - Persistence) requires
MITRE ATT&CK ICS T1693 (Modify Firmware) is an ICS Persistence, Inhibit Response Function, Impair Process Control technique. Firmware is low-level software embedded in hardware that enables systems and devices to function properly and is commonly found in ICS environments. Adversaries may modify firmware on a system or device by installing malicious or vulnerable versions that enable them to achieve objectives such as Persistence, Impair Process Control, and Inhibit Response Function. Adversaries may modify system and device firmware by using the built-in firmware update functionality which may support local or remote installation. The malicious or vulnerable firmware may be delivered via Replication Through Removable Media, Supply Chain Compromise, or Remote Services. Once installed, the malicious or vulnerable firmware could be used to provide Rootkit and Hooking functionality, Exploitation for Privilege Escal... Affected platforms: see ATT&CK ICS. ATT&CK-mapped mitigations: M0802 Communication Authenticity, M0930 Network Segmentation, M0945 Code Signing, M0807 Network Allowlists, M0808 Encrypt Network Traffic, M0947 Audit, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0946 Boot Integrity, M0941 Encrypt Sensitive Information, M0801 Access Management, M0937 Filter Network Traffic.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1693/
SHA-256 integrity: 06f75a4b9c78e33b85cee933cee66ff55dbe7d09615552678251e5faeada76a7
Primary Citations — 18 traced to source
- MITRE ATT&CK ICS Technique T1693: Modify Firmware (https://attack.mitre.org/techniques/T1693/)
- MITRE ATT&CK ICS Tactic TA0110: Persistence (https://attack.mitre.org/tactics/TA0110/)
+ 16 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-ics-t1693-modify-firmware.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-ics-t1693-modify-firmware.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-ics-t1693-modify-firmware
- Back to registry: Browse all 10,085 compliance nodes