Compliance Node Overview
MITRE ATT&CK ICS T0843.002 (Online Edit) is an ICS Lateral Movement technique. Adversaries may execute an online edit of a PLC to update parts of an existing program. It does not require stopping the PLC which allows it to continue running during transfer and reconfiguration without interruption to process control. Adversaries may leverage this approach to minimize downtime and evade detection. The ability to perform an online edit to the PLC typically relies on access to a workstation with the vendor-specific PLC programming software installed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0843. ATT&CK-mapped mitigations: M0804 Human User Authentication, M0802 Communication Authenticity, M0930 Network Segmentation, M0807 Network Allowlists, M0800 Authorization Enforcement, M0801 Access Management, M0937 Filter Network Traffic, M0947 Audit, M0813 Software Process and Device Authentication, M0945 Code Signing.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0843/002/
SHA-256 integrity: 58e7275af0896538ddfe6ed7c2132885ea162179a5702e7cb47fee4626920257
Primary Citations — 16 traced to source
- MITRE ATT&CK ICS Technique T0843.002: Online Edit (https://attack.mitre.org/techniques/T0843/002/)
- MITRE ATT&CK ICS Tactic TA0109: Lateral Movement (https://attack.mitre.org/tactics/TA0109/)
+ 14 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.