Compliance Node Overview
MITRE ATT&CK T0895 (Autorun Image) is an ATT&CK for ICS Execution technique. Adversaries may leverage AutoRun functionality or scripts to execute malicious code. Devices configured to enable AutoRun functionality or legacy operating systems may be susceptible to abuse of these features to run malicious code stored on various forms of removeable media (i.e., USB, Disk Images [.ISO]). Commonly, AutoRun or AutoPlay are disabled in many operating systems configurations to mitigate against this technique. MITRE-documented mitigations include M0928 Operating System Configuration. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0895/
SHA-256 integrity: f172a1c61ca8f91cd03efe23fb9c9096bc69cf8b30e194e6c3463e98bcdf513e
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0895: Autorun Image (https://attack.mitre.org/techniques/T0895/)
- MITRE ATT&CK ICS Tactic TA0104: Execution (https://attack.mitre.org/tactics/TA0104/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.