{
  "node_id": "mitre-attack-ics-t0863-user-execution",
  "title": "MITRE ATT&CK ICS T0863: User Execution (ICS Tactic TA0104 - Execution)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T0863 (User Execution) is an ATT&CK for ICS Execution technique. Adversaries may rely on a targeted organizations user interaction for the execution of malicious code. User interaction may consist of installing applications, opening email attachments, or granting higher permissions to documents. Adversaries may embed malicious code or visual basic code into files such as Microsoft Word and Excel documents or software installers. Execution of this code requires that the user enable scripting or write access within the document. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention, M0921 Restrict Web-Based Content, M0917 User Training, M0931 Network Intrusion Prevention, M0949 Antivirus/Antimalware, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}