MITRE ATT&CK Technique
Defense Evasion T1109
Description

Some adversaries may employ sophisticated means to compromise computer components and install malicious firmware that will execute adversary code outside of the operating system and main system firmware or BIOS. This technique may be similar to [System Firmware](https://attack.mitre.org/techniques/T1019) but conducted upon other system components that may not have the same capability or level of integrity checking. Malicious device firmware could provide both a persistent level of access to systems despite potential typical failures to maintain access and hard disk re-images, as well as a way to evade host software-based defenses and integrity checks.

Supported Platforms
Windows
Created

April 29, 2026

Last Updated

April 29, 2026

STIX Data
{'created': '2017-05-31T21:31:22.374Z',
 'created_by_ref': 'identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5',
 'description': 'Some adversaries may employ sophisticated means to compromise '
                'computer components and install malicious firmware that will '
                'execute adversary code outside of the operating system and '
                'main system firmware or BIOS. This technique may be similar '
                'to [System '
                'Firmware](https://attack.mitre.org/techniques/T1019) but '
                'conducted upon other system components that may not have the '
                'same capability or level of integrity checking. Malicious '
                'device firmware could provide both a persistent level of '
                'access to systems despite potential typical failures to '
                'maintain access and hard disk re-images, as well as a way to '
                'evade host software-based defenses and integrity checks.',
 'external_references': [{'external_id': 'T1109',
                          'source_name': 'mitre-attack',
                          'url': 'https://attack.mitre.org/techniques/T1109'},
                         {'description': 'SanDisk. (n.d.). Self-Monitoring, '
                                         'Analysis and Reporting Technology '
                                         '(S.M.A.R.T.). Retrieved October 2, '
                                         '2018.',
                          'source_name': 'SanDisk SMART'},
                         {'description': 'smartmontools. (n.d.). '
                                         'smartmontools. Retrieved October 2, '
                                         '2018.',
                          'source_name': 'SmartMontools',
                          'url': 'https://www.smartmontools.org/'},
                         {'description': 'Pinola, M. (2014, December 14). 3 '
                                         "tools to check your hard drive's "
                                         "health and make sure it's not "
                                         'already dying on you. Retrieved '
                                         'October 2, 2018.',
                          'source_name': 'ITWorld Hard Disk Health Dec 2014',
                          'url': 'https://www.itworld.com/article/2853992/3-tools-to-check-your-hard-drives-health-and-make-sure-its-not-already-dying-on-you.html'}],
 'id': 'attack-pattern--10d5f3b7-6be6-4da5-9a77-0f1e2bbfcc44',
 'kill_chain_phases': [{'kill_chain_name': 'mitre-attack',
                        'phase_name': 'defense-evasion'},
                       {'kill_chain_name': 'mitre-attack',
                        'phase_name': 'persistence'}],
 'modified': '2025-10-24T17:48:25.071Z',
 'name': 'Component Firmware',
 'object_marking_refs': ['marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168'],
 'revoked': True,
 'spec_version': '2.1',
 'type': 'attack-pattern',
 'x_mitre_attack_spec_version': '3.2.0',
 'x_mitre_deprecated': False,
 'x_mitre_detection': '',
 'x_mitre_domains': ['enterprise-attack'],
 'x_mitre_is_subtechnique': False,
 'x_mitre_modified_by_ref': 'identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5',
 'x_mitre_platforms': ['Windows'],
 'x_mitre_version': '1.1'}
Quick Actions