{
  "node_id": "mitre-attack-ics-t0869-standard-application-layer-protocol",
  "title": "MITRE ATT&CK ICS T0869: Standard Application Layer Protocol (ICS Tactic TA0101 - Command and Control)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T0869 (Standard Application Layer Protocol) is an ATT&CK for ICS Command and Control technique. Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus. These protocols may be used to disguise adversary actions as benign network traffic. Standard protocols may be seen on their associated port or in some cases over a non-standard port. Adversaries may use these protocols to reach out of the network for command and control, or in some cases to other infected devices within the network. Affected asset classes: None. MITRE-documented mitigations include M0930 Network Segmentation, M0931 Network Intrusion Prevention, M0807 Network Allowlists. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}