{
  "node_id": "mitre-attack-ics-t0856-spoof-reporting-message",
  "title": "MITRE ATT&CK ICS T0856: Spoof Reporting Message (ICS Tactic TA0103 - Evasion / TA0106 - Impair Process Control)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T0856 (Spoof Reporting Message) is an ATT&CK for ICS Evasion and Impair Process Control technique. Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the current state of equipment and the industrial process. Reporting messages are important for monitoring the normal operation of a system or identifying important events such as deviations from expected values. Affected asset classes: None. MITRE-documented mitigations include M0813 Software Process and Device Authentication, M0802 Communication Authenticity, M0930 Network Segmentation, M0807 Network Allowlists, M0937 Filter Network Traffic. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}