Compliance Node Overview
MITRE ATT&CK T0848 (Rogue Master) is an ATT&CK for ICS Initial Access technique. Adversaries may setup a rogue master to leverage control server functions to communicate with outstations. A rogue master can be used to send legitimate control messages to other control system devices, affecting processes in unintended ways. It may also be used to disrupt network communications by capturing and receiving the network traffic meant for the actual master. Impersonating a master may also allow an adversary to avoid detection. Affected asset classes: None. MITRE-documented mitigations include M0813 Software Process and Device Authentication, M0937 Filter Network Traffic, M0930 Network Segmentation, M0807 Network Allowlists, M0802 Communication Authenticity. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0848/
SHA-256 integrity: d80c5c614c4f8856bef99ea270409fa4f7ce5156fa4cca5f797a6639fea8a4d0
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0848: Rogue Master (https://attack.mitre.org/techniques/T0848/)
- MITRE ATT&CK ICS Tactic TA0108: Initial Access (https://attack.mitre.org/tactics/TA0108/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.