# SYNful Knock
SYNful Knock is a modification of the router's firmware images used to maintain persistence. [[1]](#1)
## Enhanced ATT&CK Techniques
|Name|Use|
|---|---|
|[Persistence::Component Firmware::Router Firmware (F0009.001)](../persistence/component-firmware.md)|SYNful Knock is a stealthy modification of the router's firmware image that can be used to maintain persistence within a victim's network. [[1]](#1)|
|[Defense Evasion::Hijack Execution Flow (F0015)](../defense-evasion/hijack-execution-flow.md)|SYNful Knock hooks iOS functions to call and initialize the malware. [[1]](#1)|
## MBC Behaviors
|Name|Use|
|---|---|
|[Memory::Change Memory Protection (C0008)](../micro-behaviors/memory/change-memory-protection.md)|SYNful Knock modifies the translation lookaside buffer (TLB) Read/Write attributes. [[1]](#1)|
|[Communication::Socket Communication::Send TCP Data (C0001.014)](../micro-behaviors/communication/socket-communication.md)|To initiate communication with the C2 server, a uniquely crafted TCP SYN packet is sent to port 80 of the "implanted" router. [[1]](#1)|
|[Defense Evasion::Alternative Installation Location::Fileless Malware (B0027.001)](../defense-evasion/alternative-installation-location.md)|100 memory-resident modules can be installed. [[1]](#1)|
## References
[1] https://www.mandiant.com/resources/synful-knock-acis