Compliance Node Overview
MITRE ATT&CK T0894 (System Binary Proxy Execution) is an ATT&CK for ICS Evasion technique. Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Affected asset classes: None. MITRE-documented mitigations include M0938 Execution Prevention. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0894/
SHA-256 integrity: ab53f369397600a1159f7db06c90a2ad4b3f7627c69c1d6d6d6dd94890328aa8
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0894: System Binary Proxy Execution (https://attack.mitre.org/techniques/T0894/)
- MITRE ATT&CK ICS Tactic TA0103: Evasion (https://attack.mitre.org/tactics/TA0103/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.