Compliance Node Overview
MITRE ATT&CK T0869 (Standard Application Layer Protocol) is an ATT&CK for ICS Command and Control technique. Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus. These protocols may be used to disguise adversary actions as benign network traffic. Standard protocols may be seen on their associated port or in some cases over a non-standard port. Adversaries may use these protocols to reach out of the network for command and control, or in some cases to other infected devices within the network. Affected asset classes: None. MITRE-documented mitigations include M0930 Network Segmentation, M0931 Network Intrusion Prevention, M0807 Network Allowlists. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0869/
SHA-256 integrity: 2a73744ef5b9c48c086e449e98b9d22211d1ac492c2a7069c8e3f83319f45e56
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0869: Standard Application Layer Protocol (https://attack.mitre.org/techniques/T0869/)
- MITRE ATT&CK ICS Tactic TA0101: Command and Control (https://attack.mitre.org/tactics/TA0101/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.