What MITRE ATT&CK ICS T0843.003: Program Append (ICS Tactic TA0109 - Lateral Movement) requires
MITRE ATT&CK ICS T0843.003 (Program Append) is an ICS Lateral Movement technique. Adversaries may execute a program append to a PLC to update parts of an existing program. It may or may not require stopping the PLC which may allow it to continue running during transfer and reconfiguration without interruption to process control. Adversaries may leverage this approach to minimize downtime and evade detection. The ability to perform a program append to the PLC typically relies on access to a workstation with the vendor-specific PLC programming software installed. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0843. ATT&CK-mapped mitigations: M0937 Filter Network Traffic, M0813 Software Process and Device Authentication, M0807 Network Allowlists, M0804 Human User Authentication, M0802 Communication Authenticity, M0800 Authorization Enforcement, M0947 Audit, M0945 Code Signing, M0930 Network Segmentation, M0801 Access Management.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0843/003/
SHA-256 integrity: a242bd0d4bd92f3a01b5405957b259f89492b5b166500357e5e3bb593210957c
Primary Citations — 16 traced to source
- MITRE ATT&CK ICS Technique T0843.003: Program Append (https://attack.mitre.org/techniques/T0843/003/)
- MITRE ATT&CK ICS Tactic TA0109: Lateral Movement (https://attack.mitre.org/tactics/TA0109/)
+ 14 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.