1200KM / detection
T1495 Firmware Corruption — Detection Rules
Detection workspace for T1495 Firmware Corruption: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Cisco Denial of Service · test · medium · {"product":"cisco","service":"aaa"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0167 Firmware Modification via Flash Tool or Corrupted Firmware Upload
AN0474 Analytic 0474
Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.
AN0475 Analytic 0475
Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).
AN0476 Analytic 0476
EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.
AN0477 Analytic 0477
Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Driver Load · DC0079
- Firmware Modification · DC0004
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.