// MITRE ATT&CK

T1601.002 · Downgrade System Image

🎯 Defense Impairment Network Devices Sub-technique

Sub-technique of T1601 · Modify System Image.

Adversaries may install an older version of the operating system of a network device to weaken security. Older operating system versions on network devices often have weaker encryption ciphers and, in general, fewer/less updated defensive features. (Citation: Cisco Synful Knock Evolution) On embed...

How to detect & mitigate it

Detecting Downgrade System Image starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.