Compliance Node Overview
MITRE ATT&CK T1601 (Modify System Image) is an Enterprise Defense Evasion technique. Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file. To change the operating system, the adversary typically only needs to affect this one file, replacing or modifying it. ATT&CK documents 2 sub-techniques: T1601.001 Patch System Image; T1601.002 Downgrade System Image. Affected platforms: Network. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1027 Password Policies, M1043 Credential Access Protection, M1045 Code Signing, M1046 Boot Integrity, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CM-02, CM-03, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1601/
SHA-256 integrity: 8c7a184e20019df4fc180cd5ac134c71397c360a81a448c0334ee84d640ac6fc
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1601: Modify System Image (https://attack.mitre.org/techniques/T1601/) with 2 sub-techniques
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access