Technique.View on attack.mitre.org
Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards.
In general, adversaries may manipulate, overwrite, or corrupt firmware in order to deny the use of the system or devices. For example, corruption of firmware responsible for loading the operating system for network devices may render the network devices inoperable. Depending on the device, this attack may also result in Data Destruction.
Rules on DetectionCode tagged with T1495.
| Rule | Level | Log source |
|---|---|---|
| Cisco Denial of Service | medium | cisco / NULL |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareBad Rabbit | Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up. |
| MalwareTrickBot | TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.