What MITRE ATT&CK ICS T0846.001: Port Scan (ICS Tactic TA0102 - Discovery) requires
MITRE ATT&CK ICS T0846.001 (Port Scan) is an ICS Discovery technique. Adversaries may perform a port scan on a system, device, or network to identify live hosts, enumerate open ports and running services, identify operating systems, and map out the network. The results of a port scan may inform adversary Discovery, Lateral Movement, and vulnerability exploitation decisions (Exploitation for Evasion, Exploitation for Privilege Escalation, Exploitation of Remote Services). Some common tools for executing a port scan include `nmap`, `netcat`, and the Advanced Port Scanner. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T0846. ATT&CK-mapped mitigations: M0814 Static Network Configuration, M0930 Network Segmentation, M0931 Network Intrusion Prevention.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0846/001/
SHA-256 integrity: ec9f6788b8faf076c1fb05763262e18f811d77b66dbc4ad6232ef3f153bc414c
Primary Citations — 9 traced to source
- MITRE ATT&CK ICS Technique T0846.001: Port Scan (https://attack.mitre.org/techniques/T0846/001/)
- MITRE ATT&CK ICS Tactic TA0102: Discovery (https://attack.mitre.org/tactics/TA0102/)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access