T1601 - Modify System Image

Tattiche:
Defense Evasion
Piattaforme:
Network Devices
Rilevamento:
Not specified
Description:
Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file.

To change the operating system, the adversary typically only needs to affect this one file, replacing or modifying it. This can either be done live in memory during system runtime for immediate effect, or in storage to implement the change on the next boot of the network device.
Sub-tecniche (2)
ID ATT&CK Azioni
T1601.001 Patch System Image
T1601.002 Downgrade System Image
Metadata
MITRE ID: T1601
STIX ID: attack-pattern--ae7f3575-0a5e-...
Piattaforme: Network Devices
Created: 13/01/2026 17:48
Updated: 14/03/2026 16:00