Pre-OS Boot: TFTP Boot T1542.005

Tactics: Stealth, Persistence

Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
All_Traffic.dest_category1ne 1common_software_repo_destination
All_Traffic.src_category1eq 1network, router, switch
All_Traffic.transport1eq 1tcp, udp
DestinationPort1eq 121, 22, 69

Top indicator values (9 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
All_Traffic.dest_categoryne
common_software_repo_destination
1
All_Traffic.src_categoryeq
network
1
All_Traffic.src_categoryeq
router
1
All_Traffic.src_categoryeq
switch
1
All_Traffic.transporteq
tcp
14
All_Traffic.transporteq
udp
1
DestinationPorteq
21
15
DestinationPorteq
22
1
DestinationPorteq
69
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Network

Domain: Network

Splunk 1 rule