Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK ICS T0847: Replication Through Removable Media (ICS Tactic TA0108 - Initial Access)

MITRE ATT&CK T0847 (Replication Through Removable Media) is an ATT&CK for ICS Initial Access technique. Adversaries may move onto systems, such as those…

What MITRE ATT&CK ICS T0847: Replication Through Removable Media (ICS Tactic TA0108 - Initial Access) requires

MITRE ATT&CK T0847 (Replication Through Removable Media) is an ATT&CK for ICS Initial Access technique. Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment. The adversary may rely on unknowing trusted third parties, such as suppliers or contractors with access privileges, to introduce the removable media. This technique enables initial access to target devices that never connect to untrusted networks, but are physically accessible. Affected asset classes: None. MITRE-documented mitigations include M0928 Operating System Configuration, M0934 Limit Hardware Installation, M0942 Disable or Remove Feature or Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T0847/

SHA-256 integrity: d62e8a35c9cc2dcd6f9b4a95eecc36edefa756f922f2ed26d72bfd43c1fddf46

Primary Citations — 7 traced to source

  • MITRE ATT&CK for ICS Technique T0847: Replication Through Removable Media (https://attack.mitre.org/techniques/T0847/)
  • MITRE ATT&CK ICS Tactic TA0108: Initial Access (https://attack.mitre.org/tactics/TA0108/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.