Modify System Image T1601

Tactic: Defense Impairment

Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are typically monolithic and most of the device functionality and capabilities are contained within a single file.

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1in 1ProcessRollup2, exec, exec_event
Message1in 1*could not download*, *download failed*, *failed to download file*
event.type1eq 1start
host.os.type1eq 1
process.args1in 1--exec, --load, --unload
process_name1eq 1kexec
sourcetype1in 1vmw-syslog, vmware:esxlog*

Top indicator values (20 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
ProcessRollup2
1117
EventTypein
exec
1201
EventTypein
exec_event
1149
EventTypein
executed
198
EventTypein
process_started
183
EventTypein
start
1163
Messagein
*could not download*
1
Messagein
*download failed*
1
Messagein
*failed to download file*
1
Messagein
*file download error*
1
event.typeeq
start
11078
process.argsin
--exec
1
process.argsin
--load
1
process.argsin
--unload
1
process.argsin
-e
14
process.argsin
-l
15
process.argsin
-u
19
process_nameeq
kexec
1
sourcetypein
vmw-syslog
123
sourcetypein
vmware:esxlog*
123

Exclusions (5 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_namein
kdumpctl
1
parent_process_namein
unload.sh
1
process.parent.argsin
/usr/bin/kdumpctl
1
process.parent.argsin
/usr/lib/kdump/unload.sh
1
process.parent.argsin
/usr/sbin/kdump-config
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Elastic 1 rule

Splunk 1 rule