SYNful Knock

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[SYNful Knock](https://attack.mitre.org/software/S0519) is a stealthy modification of the operating system of network devices that can be used to maintain persistence within a victim's network and provide new capabilities to the adversary.(Citation: Mandiant - Synful Knock)(Citation: Cisco Synful Knock Evolution)

Associated Techniques (3)
ID ATT&CK Tactics
T1205 Traffic Signaling -
T1556.004 Network Device Authentication -
T1601.001 Patch System Image -
Metadata
ID: 373
Created: 13/01/2026 17:48
Updated: 21/04/2026 04:00