Compliance Node Overview
MITRE CAPEC-638 (Altered Component Firmware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits systems features and/or improperly protected firmware of hardware components, such as Hard Disk Drives (HDD), with the goal of executing malicious code from within the component's Master Boot Record (MBR). Conducting this type of attack entails the adversary infecting the target with firmware altering malware, using known tools, and a payload. Likelihood of attack: Low. Typical severity: Very High. Relates to MITRE ATT&CK T1542.002.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/638.html
SHA-256 integrity: b8c1bdb1e15ac734decf3593643d31ad39f0f38b8434091eb849efc2a8d4e371
Primary Citations — 8 traced to source
- MITRE CAPEC-638: Altered Component Firmware (https://capec.mitre.org/data/definitions/638.html)
- MITRE ATT&CK T1542.002: Pre-OS Boot:Component Firmware (https://attack.mitre.org/techniques/T1542/)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.