What MITRE ATT&CK ICS T0877: I/O Image (ICS Tactic TA0100 - Collection) requires
MITRE ATT&CK T0877 (I/O Image) is an ATT&CK for ICS Collection technique. Adversaries may seek to capture process values related to the inputs and outputs of a PLC. During the scan cycle, a PLC reads the status of all inputs and stores them in an image table. The image table is the PLCs internal storage location where values of inputs/outputs for one scan are stored while it executes the user program. After the PLC has solved the entire logic program, it updates the output image table. The contents of this output image table are written to the corresponding output points in I/O Modules. Affected asset classes: None. MITRE-documented mitigations include M0816 Mitigation Limited or Not Effective. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0877/
SHA-256 integrity: b9db89ffe41a9dd9e0f89f0021447e0771d4836c6b2c24137d05d9705652d3e4
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0877: I/O Image (https://attack.mitre.org/techniques/T0877/)
- MITRE ATT&CK ICS Tactic TA0100: Collection (https://attack.mitre.org/tactics/TA0100/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.