Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | -68% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -15% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -45% | 0% |
| case-22 | ✗→✓ | ▲ Improved | -60% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 25% | 0% |
> Sub-technique of: T1195
Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise. By modifying hardware or firmware in the supply chain, adversaries can insert a backdoor into consumer networks that may be difficult to detect and give the adversary a high degree of control over the system. Hardware backdoors may be inserted into various devices, such as servers, workstations, network infrastructure, or peripherals.
Platforms: Linux, macOS, Windows
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
Use Trusted Platform Module technology and a secure or trusted boot process to prevent system integrity from being compromised. Check the integrity of the existing BIOS or EFI to determine if it is vulnerable to modification.
| Finding | Severity | Impact | | ----------------------------------------------------- | -------- | -------------- | | Compromise Hardware Supply Chain technique applicable | High | Initial Access |
| CWE ID | Title | | ------ | ------------------------- | | CWE-20 | Improper Input Validation |
Other measured skills in the registry, with their headline benchmark lift.