Watchdog Timer Timeout Modified to Unexpected Value

Monitors changes to WDT timeout values, which could indicate unauthorized modifications designed to disable normal reset mechanisms. For example, WDT timeout value is extended beyond acceptable operational limits, potentially allowing unregulated activity. This could be written in STIX as [x-opencti-watchdog:timeout > 'maximum_operational_limit']

STIX Pattern

[x-opencti-watchdog:timeout != 'baseline_value']

SPARTA TTPs

ID Name Description
DE-0003.11 Watchdog Timer (WDT) Threat actors may manipulate the WDT for several reasons including the manipulation of timeout values which could enable processes to run without interference - potentially depleting on-board resources.