Compliance Node Overview
MITRE ATT&CK T0885 (Commonly Used Port) is an ATT&CK for ICS Command and Control technique. Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection. They may use the protocol associated with the port, or a completely different protocol. They may use commonly open ports, such as the examples provided below. Affected asset classes: None. MITRE-documented mitigations include M0804 Human User Authentication, M0931 Network Intrusion Prevention, M0930 Network Segmentation, M0942 Disable or Remove Feature or Program. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0885/
SHA-256 integrity: 900ee42445e1c787ea2bc24b7b46c70840dcd206af6e2e382a666cf6ba88ce10
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0885: Commonly Used Port (https://attack.mitre.org/techniques/T0885/)
- MITRE ATT&CK ICS Tactic TA0101: Command and Control (https://attack.mitre.org/tactics/TA0101/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.