What MITRE ATT&CK ICS T0863: User Execution (ICS Tactic TA0104 - Execution) requires
MITRE ATT&CK T0863 (User Execution) is an ATT&CK for ICS Execution technique. Adversaries may rely on a targeted organizations user interaction for the execution of malicious code. User interaction may consist of installing applications, opening email attachments, or granting higher permissions to documents. Adversaries may embed malicious code or visual basic code into files such as Microsoft Word and Excel documents or software installers. Execution of this code requires that the user enable scripting or write access within the document. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention, M0921 Restrict Web-Based Content, M0917 User Training, M0931 Network Intrusion Prevention, M0949 Antivirus/Antimalware, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0863/
SHA-256 integrity: a3cf612c3ade50ab469f506602250e540c01b8df284f56f778778f56e5af2bd6
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0863: User Execution (https://attack.mitre.org/techniques/T0863/)
- MITRE ATT&CK ICS Tactic TA0104: Execution (https://attack.mitre.org/tactics/TA0104/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.