What MITRE ATT&CK ICS T0871: Execution through API (ICS Tactic TA0104 - Execution) requires
MITRE ATT&CK T0871 (Execution through API) is an ATT&CK for ICS Execution technique. Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware. Specific functionality is often coded into APIs which can be called by software to engage specific functions on a device or other software. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention, M0800 Authorization Enforcement, M0804 Human User Authentication, M0801 Access Management. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0871/
SHA-256 integrity: a11b67de986793846ca32a253c33c780b5860f6a0efd070758dc9f769d2c44a3
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0871: Execution through API (https://attack.mitre.org/techniques/T0871/)
- MITRE ATT&CK ICS Tactic TA0104: Execution (https://attack.mitre.org/tactics/TA0104/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-ics-t0871-execution-through-api.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-ics-t0871-execution-through-api.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-ics-t0871-execution-through-api
- Back to registry: Browse all 10,085 compliance nodes