ATK — Attacker mission
Compromise an exposed device, extract and tamper with firmware, then pivot from the edge into the network behind it — or plant a foothold in the build pipeline that ships to thousands.
Embedded devices and the fabs that build them are the soft underbelly of modern infrastructure: long-lived, rarely patched, and trusted by everything downstream.
Compromise an exposed device, extract and tamper with firmware, then pivot from the edge into the network behind it — or plant a foothold in the build pipeline that ships to thousands.
Detect anomalous device behaviour, contain the compromised node, verify firmware integrity, and keep the production line running without trusting the breached segment.
Your enumeration of the device fleet, the moment you noticed the firmware mismatch, and whether you isolated the edge before it became a pivot — mapped to ATT&CK.
Technique IDs are indicative of the kill chains modelled in this domain; each match draws a unique path through them.
Attack. Defend. Repeat.