What MITRE ATT&CK ICS T0874: Hooking (ICS Tactic TA0104 - Execution / TA0111 - Privilege Escalation) requires
MITRE ATT&CK T0874 (Hooking) is an ATT&CK for ICS Execution and Privilege Escalation technique. Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means. Windows processes often leverage these API functions to perform tasks that require reusable system resources. Windows API functions are typically stored in dynamic-link libraries (DLLs) as exported functions. One type of hooking seen in ICS involves redirecting calls to these functions via import address table (IAT) hooking. Affected asset classes: None. MITRE-documented mitigations include M0944 Restrict Library Loading, M0947 Audit. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0874/
SHA-256 integrity: f130e92fe3e51075ef1b94289156ea5effed6541a52e57038b1ba92ae442e122
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0874: Hooking (https://attack.mitre.org/techniques/T0874/)
- MITRE ATT&CK ICS Tactic TA0104: Execution (https://attack.mitre.org/tactics/TA0104/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.