Modify System Image: Patch System Image T1601.001

Tactic: Defense Impairment

Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime.

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1in 1ProcessRollup2, exec, exec_event
Message1in 1*could not download*, *download failed*, *failed to download file*
event.type1eq 1start
host.os.type1eq 1
process.args1in 1--exec, --load, --unload
process_name1eq 1kexec
sourcetype1in 1vmw-syslog, vmware:esxlog*

Top indicator values (20 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
ProcessRollup2
1118
EventTypein
exec
1206
EventTypein
exec_event
1150
EventTypein
executed
198
EventTypein
process_started
183
EventTypein
start
1168
Messagein
*could not download*
1
Messagein
*download failed*
1
Messagein
*failed to download file*
1
Messagein
*file download error*
1
event.typeeq
start
11087
process.argsin
--exec
1
process.argsin
--load
1
process.argsin
--unload
1
process.argsin
-e
14
process.argsin
-l
15
process.argsin
-u
19
process_nameeq
kexec
1
sourcetypein
vmw-syslog
123
sourcetypein
vmware:esxlog*
123

Exclusions (5 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_namein
kdumpctl
1
parent_process_namein
unload.sh
1
process.parent.argsin
/usr/bin/kdumpctl
1
process.parent.argsin
/usr/lib/kdump/unload.sh
1
process.parent.argsin
/usr/sbin/kdump-config
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Elastic 1 rule

Splunk 1 rule