What MITRE ATT&CK ICS T0820: Exploitation for Evasion (ICS Tactic TA0103 - Evasion) requires
MITRE ATT&CK T0820 (Exploitation for Evasion) is an ATT&CK for ICS Evasion technique. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection. Vulnerabilities may exist in software that can be used to disable or circumvent security features. Adversaries may have prior knowledge through Remote System Information Discovery about security features implemented on control devices. These device security features will likely be targeted directly for exploitation. Affected asset classes: None. MITRE-documented mitigations include M0919 Threat Intelligence Program, M0950 Exploit Protection, M0948 Application Isolation and Sandboxing, M0951 Update Software. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0820/
SHA-256 integrity: 202a58fc2bc7d8213928dc43033f9353bedac850371dd7ad48d7919081c2ff70
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0820: Exploitation for Evasion (https://attack.mitre.org/techniques/T0820/)
- MITRE ATT&CK ICS Tactic TA0103: Evasion (https://attack.mitre.org/tactics/TA0103/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-ics-t0820-exploitation-for-evasion.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-ics-t0820-exploitation-for-evasion.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-ics-t0820-exploitation-for-evasion
- Back to registry: Browse all 10,085 compliance nodes