{
  "node_id": "mitre-attack-ics-t0843-001-download-all",
  "title": "MITRE ATT&CK ICS T0843.001: Download All (ICS Tactic TA0109 - Lateral Movement)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-06",
  "bluf": "MITRE ATT&CK ICS T0843.001 (Download All) is an ICS Lateral Movement technique. Adversaries may execute a full program download to a PLC to overwrite the entire PLC program and configuration to deploy a new project or make major changes. This typically requires stopping the PLC and adversely impacting control processes. The ability to perform a full program download to the PLC typically relies on access to a workstation with the vendor-specific PLC programming software installed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0843. ATT&CK-mapped mitigations: M0945 Code Signing, M0947 Audit, M0802 Communication Authenticity, M0800 Authorization Enforcement, M0801 Access Management, M0937 Filter Network Traffic, M0930 Network Segmentation, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0807 Network Allowlists.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 16
}