What MITRE ATT&CK ICS T0852: Screen Capture (ICS Tactic TA0100 - Collection) requires
MITRE ATT&CK T0852 (Screen Capture) is an ATT&CK for ICS Collection technique. Adversaries may attempt to perform screen capture of devices in the control system environment. Screenshots may be taken of workstations, HMIs, or other devices that display environment-relevant process, device, reporting, alarm, or related data. These device displays may reveal information regarding the ICS process, layout, control, and related schematics. In particular, an HMI can provide a lot of important industrial process information. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0852/
SHA-256 integrity: e4cb2b52182539f89f7fab1e4a8752442fb4300c9cab9d6f0ddcee4e6b1aca7a
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0852: Screen Capture (https://attack.mitre.org/techniques/T0852/)
- MITRE ATT&CK ICS Tactic TA0100: Collection (https://attack.mitre.org/tactics/TA0100/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-ics-t0852-screen-capture.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-ics-t0852-screen-capture.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-ics-t0852-screen-capture
- Back to registry: Browse all 10,085 compliance nodes