Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Discovery, Lateral Movement, Collection, Command and Control, Impact, Inhibit Response Function, Impair Process Control, Evasion, other
[initial-access] Initial Access
- T0817 Drive-by Compromise
An ATT&CK for ICS Initial Access technique. Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session. With this technique, the user's web browser is...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0817-drive-by-compromise
- T0819 Exploit Public-Facing Application
An ATT&CK for ICS Initial Access technique. Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network. Internet-facing software may be user applications, underlying networking...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0819-exploit-public-facing-application
- T0822 External Remote Services
An ATT&CK for ICS Initial Access technique. Adversaries may leverage external remote services as a point of initial access into your network. These services allow users to connect to internal network resources from external locations....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0822-external-remote-services
- T0847 Replication Through Removable Media
An ATT&CK for ICS Initial Access technique. Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0847-replication-through-removable-media
- T0848 Rogue Master
An ATT&CK for ICS Initial Access technique. Adversaries may setup a rogue master to leverage control server functions to communicate with outstations. A rogue master can be used to send legitimate control messages to other control...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0848-rogue-master
- T0860 Wireless Compromise
An ATT&CK for ICS Initial Access technique. Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network. Access to a wireless network may be gained through the...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0860-wireless-compromise
- T0862 Supply Chain Compromise
An ATT&CK for ICS Initial Access technique. Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows. Supply chain compromise is the manipulation...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0862-supply-chain-compromise
- T0864 Transient Cyber Asset
An ATT&CK for ICS Initial Access technique. Adversaries may target devices that are transient across ICS networks and external networks. Normally, transient assets are brought into an environment by authorized personnel and do not...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0864-transient-cyber-asset
- T0865 Spearphishing Attachment
An ATT&CK for ICS Initial Access technique. Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets. Spearphishing attachments are different from...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0865-spearphishing-attachment
- T0866 Exploitation of Remote Services
An ATT&CK for ICS Initial Access and Lateral Movement technique. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0866-exploitation-of-remote-services
- T0883 Internet Accessible Device
Adversary access to industrial control devices directly exposed to the internet without proper authentication, firewall, or VPN protection. Shodan, Censys, and ZoomEye continuously index thousands of exposed PLCs, HMIs, SCADA endpoints,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0883-internet-accessible-device
- T0886 Remote Services
Adversary use of remote services (RDP, VNC, SSH, vendor proprietary remote-support tools) for lateral movement and access to OT environments. Sandworm (Industroyer/Industroyer2), Volt Typhoon, and most major ICS intrusions leveraged...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0886-remote-services
[execution] Execution
- T0807 Command-Line Interface
An ATT&CK for ICS Execution technique. Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands. CLIs provide a means of interacting with computer systems and are a common feature across many...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0807-command-line-interface
- T0821 Modify Controller Tasking
An ATT&CK for ICS Execution technique. Adversaries may modify the tasking of a controller to allow for the execution of their own programs. This can allow an adversary to manipulate the execution flow and behavior of a controller....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0821-modify-controller-tasking
- T0823 Graphical User Interface
An ATT&CK for ICS Execution technique. Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities. Access to a GUI allows a user to interact with a computer in a more...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0823-graphical-user-interface
- T0834 Native API
An ATT&CK for ICS Execution technique. Adversaries may directly interact with the native OS application programming interface (API) to access system functions. Native APIs provide a controlled means of calling low-level OS services...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0834-native-api
- T0853 Scripting
Adversary use of scripting (Python, PowerShell, ladder logic abuse, vendor-specific scripting) on OT systems for execution. Triton/Trisis used Python on Safety Instrumented System engineering workstation. Compliance: NERC CIP-007, NIST...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0853-scripting
- T0858 Change Operating Mode
An ATT&CK for ICS Execution and Evasion technique. Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download. Programmable controllers typically have several...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0858-change-operating-mode
- T0863 User Execution
An ATT&CK for ICS Execution technique. Adversaries may rely on a targeted organizations user interaction for the execution of malicious code. User interaction may consist of installing applications, opening email attachments, or...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0863-user-execution
- T0871 Execution through API
An ATT&CK for ICS Execution technique. Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware. Specific functionality is often coded into APIs which can...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0871-execution-through-api
- T0874 Hooking
An ATT&CK for ICS Execution and Privilege Escalation technique. Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means. Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0874-hooking
- T0895 Autorun Image
An ATT&CK for ICS Execution technique. Adversaries may leverage AutoRun functionality or scripts to execute malicious code. Devices configured to enable AutoRun functionality or legacy operating systems may be susceptible to abuse of...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0895-autorun-image
[persistence] Persistence
- T0839 Module Firmware
An ATT&CK for ICS Persistence and Impair Process Control technique. Adversaries may install malicious or vulnerable firmware onto modular hardware devices. Control system devices often contain modular hardware devices. These devices may...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0839-module-firmware
- T0857 System Firmware
An ATT&CK for ICS Persistence and Inhibit Response Function technique. System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0857-system-firmware
- T0859 Valid Accounts
An ATT&CK for ICS Persistence and Lateral Movement technique. Adversaries may steal the credentials of a specific user or service account using credential access techniques. In some cases, default credentials for control system devices...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0859-valid-accounts
- T0873 Project File Infection
An ATT&CK for ICS Persistence technique. Adversaries may attempt to infect project files with malicious code. These project files may consist of objects, program organization units, variables such as tags, documentation, and other...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0873-project-file-infection
- T0873.001 Project File Infection
An ICS Persistence technique. Adversaries may infect Siemens PLC project files (i.e., Step 7, WinCC, etc.) to achieve Execution, Persistence, and Lateral Movement objectives. Adversaries may modify an existing project file or bring...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0873-001-siemens-project-file-format
- T0889 Modify Program
An ATT&CK for ICS Persistence technique. Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network. Modification to controller...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0889-modify-program
- T0891 Hardcoded Credentials
An ATT&CK for ICS Lateral Movement and Persistence technique. Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset. Examples credentials that may be...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0891-hardcoded-credentials
[privilege-escalation] Privilege Escalation
- T0874 Hooking
An ATT&CK for ICS Execution and Privilege Escalation technique. Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means. Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0874-hooking
- T0890 Exploitation for Privilege Escalation
An ATT&CK for ICS Privilege Escalation technique. Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0890-exploitation-for-privilege-escalation
[discovery] Discovery
- T0840 Network Connection Enumeration
An ATT&CK for ICS Discovery technique. Adversaries may perform network connection enumeration to discover information about device communication patterns. If an adversary can inspect the state of a network connection with tools, such as...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0840-network-connection-enumeration
- T0842 Network Sniffing
An ATT&CK for ICS Discovery technique. Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information. An...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0842-network-sniffing
- T0846 Remote System Discovery
An ATT&CK for ICS Discovery technique. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0846-remote-system-discovery
- T0846.001 Remote System Discovery
An ICS Discovery technique. Adversaries may perform a port scan on a system, device, or network to identify live hosts, enumerate open ports and running services, identify operating systems, and map out the network. The results of a...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0846-001-port-scan
- T0846.002 Remote System Discovery
An ICS Discovery technique. Adversaries may perform broadcast discovery requests to enumerate systems and devices on a network. Broadcast discovery works by one system or device sending messages to all systems and devices on a network...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0846-002-broadcast-discovery
- T0846.003 Remote System Discovery
An ICS Discovery technique. Adversaries may perform multicast discovery requests which is when one system or device sends messages to all systems and devices in a pre-defined group on a network (or subnet) and then waits for a response....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0846-003-multicast-discovery
- T0887 Wireless Sniffing
An ATT&CK for ICS Discovery and Collection technique. Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments. RF communication frequencies vary between 3 kHz...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0887-wireless-sniffing
- T0888 Remote System Information Discovery
An ATT&CK for ICS Discovery technique. An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration. Adversaries may use information from Remote System...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0888-remote-system-information-discovery
[lateral-movement] Lateral Movement
- T0812 Default Credentials
An ATT&CK for ICS Lateral Movement technique. Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0812-default-credentials
- T0843 Program Download
An ATT&CK for ICS Lateral Movement technique. Adversaries may perform a program download to transfer a user program to a controller. Variations of program download, such as online edit and program append, allow a controller to continue...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0843-program-download
- T0843.001 Program Download
An ICS Lateral Movement technique. Adversaries may execute a full program download to a PLC to overwrite the entire PLC program and configuration to deploy a new project or make major changes. This typically requires stopping the PLC...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0843-001-download-all
- T0843.002 Program Download
An ICS Lateral Movement technique. Adversaries may execute an online edit of a PLC to update parts of an existing program. It does not require stopping the PLC which allows it to continue running during transfer and reconfiguration...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0843-002-online-edit
- T0843.003 Program Download
An ICS Lateral Movement technique. Adversaries may execute a program append to a PLC to update parts of an existing program. It may or may not require stopping the PLC which may allow it to continue running during transfer and...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0843-003-program-append
- T0859 Valid Accounts
An ATT&CK for ICS Persistence and Lateral Movement technique. Adversaries may steal the credentials of a specific user or service account using credential access techniques. In some cases, default credentials for control system devices...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0859-valid-accounts
- T0866 Exploitation of Remote Services
An ATT&CK for ICS Initial Access and Lateral Movement technique. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0866-exploitation-of-remote-services
- T0867 Lateral Tool Transfer
Adversary transfer of tools or payloads between OT systems for lateral movement. Includes USB-based tool transfer (Stuxnet propagation), SMB file copy on OT IT-adjacent networks, vendor protocol-based payload delivery. Compliance: NERC...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0867-lateral-tool-transfer
- T0886 Remote Services
Adversary use of remote services (RDP, VNC, SSH, vendor proprietary remote-support tools) for lateral movement and access to OT environments. Sandworm (Industroyer/Industroyer2), Volt Typhoon, and most major ICS intrusions leveraged...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0886-remote-services
- T0891 Hardcoded Credentials
An ATT&CK for ICS Lateral Movement and Persistence technique. Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset. Examples credentials that may be...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0891-hardcoded-credentials
[collection] Collection
- T0801 Monitor Process State
Adversary collection of OT process telemetry, alarm states, and operating conditions for reconnaissance and to plan disruptive operations. Industroyer included process-monitoring modules. Compliance: NERC CIP-007, NIST SP 800-82 Rev 3,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0801-monitor-process-state
- T0802 Automated Collection
An ATT&CK for ICS Collection technique. Adversaries may automate collection of industrial environment information using tools or scripts. This automated collection may leverage native control protocols and tools available in the control...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0802-automated-collection
- T0811 Data from Information Repositories
An ATT&CK for ICS Collection technique. Adversaries may target and collect data from information repositories. This can include sensitive data such as specifications, schematics, or diagrams of control system layouts, devices, and...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0811-data-from-information-repositories
- T0830 Adversary-in-the-Middle
An ATT&CK for ICS Collection technique. Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks. This type of attack allows the adversary to intercept...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0830-adversary-in-the-middle
- T0845 Program Upload
An ATT&CK for ICS Collection technique. Adversaries may attempt to upload a program from a PLC to gather information about an industrial process. Uploading a program may allow them to acquire and study the underlying logic. Methods of...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0845-program-upload
- T0852 Screen Capture
An ATT&CK for ICS Collection technique. Adversaries may attempt to perform screen capture of devices in the control system environment. Screenshots may be taken of workstations, HMIs, or other devices that display environment-relevant...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0852-screen-capture
- T0861 Point & Tag Identification
An ATT&CK for ICS Collection technique. Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment. Points may be values such as inputs, memory locations, outputs or other process...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0861-point-tag-identification
- T0868 Detect Operating Mode
An ATT&CK for ICS Collection technique. Adversaries may gather information about a PLCs or controllers current operating mode. Operating modes dictate what change or maintenance functions can be manipulated and are often controlled by a...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0868-detect-operating-mode
- T0877 I/O Image
An ATT&CK for ICS Collection technique. Adversaries may seek to capture process values related to the inputs and outputs of a PLC. During the scan cycle, a PLC reads the status of all inputs and stores them in an image table. The image...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0877-i-o-image
- T0887 Wireless Sniffing
An ATT&CK for ICS Discovery and Collection technique. Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments. RF communication frequencies vary between 3 kHz...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0887-wireless-sniffing
- T0893 Data from Local System
An ATT&CK for ICS Collection technique. Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases. This can include sensitive data such as specifications,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0893-data-from-local-system
[command-and-control] Command and Control
- T0869 Standard Application Layer Protocol
An ATT&CK for ICS Command and Control technique. Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus. These protocols may be used...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0869-standard-application-layer-protocol
- T0884 Connection Proxy
Adversary use of legitimate-looking proxy infrastructure within or adjacent to OT zones for C2 communication. Volt Typhoon used compromised SOHO routers as proxies into US critical infrastructure. Compliance: NERC CIP-005, NIST SP...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0884-connection-proxy
- T0885 Commonly Used Port
An ATT&CK for ICS Command and Control technique. Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0885-commonly-used-port
[impact] Impact
- T0813 Denial of Control
An ATT&CK for ICS Impact technique. Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls. An adversary may attempt to deny process control access to cause a...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0813-denial-of-control
- T0815 Denial of View
An ATT&CK for ICS Impact technique. Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment. This may manifest itself as a temporary communication failure between a...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0815-denial-of-view
- T0826 Loss of Availability
Adversary impact resulting in loss of availability of ICS operations. Includes ransomware on OT (Colonial Pipeline 2021), wiper on engineering workstation (Industroyer/CRASHOVERRIDE), DoS on safety-critical systems. Compliance: NERC...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0826-loss-of-availability
- T0827 Loss of Control
An ATT&CK for ICS Impact technique. Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided. The German Federal...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0827-loss-of-control
- T0828 Loss of Productivity and Revenue
An ATT&CK for ICS Impact technique. Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes. This technique...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0828-loss-of-productivity-and-revenue
- T0829 Loss of View
An ATT&CK for ICS Impact technique. Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation. By causing a...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0829-loss-of-view
- T0831 Manipulation of Control
An ATT&CK for ICS Impact technique. Adversaries may manipulate physical process control within the industrial environment. Methods of manipulating control can include changes to set point values, tags, or other parameters. Adversaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0831-manipulation-of-control
- T0832 Manipulation of View
An ATT&CK for ICS Impact technique. Adversaries may attempt to manipulate the information reported back to operators or controllers. This manipulation may be short term or sustained. During this time the process itself could be in a...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0832-manipulation-of-view
- T0837 Loss of Protection
An ATT&CK for ICS Impact technique. Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions. This can result in equipment damage, prolonged process disruptions and hazards...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0837-loss-of-protection
- T0879 Damage to Property
Adversary-induced physical damage to property, equipment, or environment via cyber means. Stuxnet (2010 Iranian centrifuges), German steel mill (2014 BSI report), Ukrainian power grid (2015-2016), Triton/Trisis (2017 Saudi petrochemical...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0879-damage-to-property
- T0880 Loss of Safety
An ATT&CK for ICS Impact technique. Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur. Safety systems are often composed of the same...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0880-loss-of-safety
- T0882 Theft of Operational Information
An ATT&CK for ICS Impact technique. Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations. This information may include design documents,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0882-theft-of-operational-information
[inhibit-response-function] Inhibit Response Function
- T0800 Activate Firmware Update Mode
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction. For example,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0800-activate-firmware-update-mode
- T0803 Block Command Message
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may block a command message from reaching its intended target to prevent command execution. In OT networks, command messages are sent to provide instructions to control...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0803-block-command-message
- T0804 Block Reporting Message
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may block or prevent a reporting message from reaching its intended target. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0804-block-reporting-message
- T0805 Block Serial COM
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices. Serial Communication ports (COM) allow communication with control...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0805-block-serial-com
- T0809 Data Destruction
Adversary destruction of data and historian records on industrial control systems to inhibit operator response and forensic investigation. CRASHOVERRIDE/Industroyer (Ukraine 2016), Industroyer2 (Ukraine 2022), and FrostyGoop (Ukraine...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0809-data-destruction
- T0814 Denial of Service
Adversary denial-of-service attacks targeting ICS components to disrupt operations. Examples include PLC flooding, fieldbus disruption, HMI lockout, and historian overload. Industroyer protocol-specific DoS modules and CrashOverride...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0814-denial-of-service
- T0816 Device Restart/Shutdown
Adversary forced restart or shutdown of ICS devices to disrupt process control. Industroyer included device restart modules. Modern threats target PLC controllers, RTU, IED relay devices via vendor protocols. Compliance: NERC CIP-007...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0816-device-restart-shutdown
- T0835 Manipulate I/O Image
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected. Methods of I/O image manipulation may include overriding the I/O...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0835-manipulate-i-o-image
- T0838 Modify Alarm Settings
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios. Reporting messages...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0838-modify-alarm-settings
- T0851 Rootkit
An ATT&CK for ICS Evasion and Inhibit Response Function technique. Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0851-rootkit
- T0857 System Firmware
An ATT&CK for ICS Persistence and Inhibit Response Function technique. System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0857-system-firmware
- T0878 Alarm Suppression
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may target protection function alarms to prevent them from notifying operators of critical conditions. Alarm messages may be a part of an overall reporting system and of...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0878-alarm-suppression
- T0881 Service Stop
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services can inhibit or stop response to an incident...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0881-service-stop
- T0892 Change Credential
An ATT&CK for ICS Inhibit Response Function technique. Adversaries may modify software and device credentials to prevent operator and responder access. Depending on the device, the modification or addition of this password could prevent...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0892-change-credential
[impair-process-control] Impair Process Control
- T0806 Brute Force I/O
An ATT&CK for ICS Impair Process Control technique. Adversaries may repetitively or successively change I/O point values to perform an action. Brute Force I/O may be achieved by changing either a range of I/O point values or a single...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0806-brute-force-i-o
- T0836 Modify Parameter
Adversary unauthorised modification of OT process parameters (setpoints, alarm thresholds, control logic parameters) to impair operations or cause physical damage. Stuxnet modified centrifuge spin parameters. Triton/Trisis attempted...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0836-modify-parameter
- T0839 Module Firmware
An ATT&CK for ICS Persistence and Impair Process Control technique. Adversaries may install malicious or vulnerable firmware onto modular hardware devices. Control system devices often contain modular hardware devices. These devices may...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0839-module-firmware
- T0855 Unauthorized Command Message
An ATT&CK for ICS Impair Process Control technique. Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0855-unauthorized-command-message
- T0856 Spoof Reporting Message
An ATT&CK for ICS Evasion and Impair Process Control technique. Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0856-spoof-reporting-message
[evasion] Evasion
- T0820 Exploitation for Evasion
An ATT&CK for ICS Evasion technique. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0820-exploitation-for-evasion
- T0849 Masquerading
An ATT&CK for ICS Evasion technique. Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion. Possible disguises of these masquerading files can...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0849-masquerading
- T0851 Rootkit
An ATT&CK for ICS Evasion and Inhibit Response Function technique. Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0851-rootkit
- T0856 Spoof Reporting Message
An ATT&CK for ICS Evasion and Impair Process Control technique. Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0856-spoof-reporting-message
- T0858 Change Operating Mode
An ATT&CK for ICS Execution and Evasion technique. Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download. Programmable controllers typically have several...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0858-change-operating-mode
- T0872 Indicator Removal on Host
An ATT&CK for ICS Evasion technique. Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks. In cases where an adversary may feel detection is imminent, they may try to overwrite,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0872-indicator-removal-on-host
- T0894 System Binary Proxy Execution
An ATT&CK for ICS Evasion technique. Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t0894-system-binary-proxy-execution
[other] other
- T1691 T1691
An ICS Inhibit Response Function technique. Adversaries may block messages between systems and devices in an OT/ICS environment to disrupt processes. Messages typically fall into two categories: (1) reporting messages that contain...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1691-block-operational-technology-message
- T1691.001 T1691.001
An ICS Inhibit Response Function technique. Adversaries may block a command message from reaching its intended target to prevent command execution. In OT networks, command messages are sent to provide instructions to control system...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1691-001-command-message
- T1691.002 T1691.002
An ICS Inhibit Response Function technique. Adversaries may block or prevent a reporting message from reaching its intended target. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1691-002-reporting-message
- T1692 T1692
An ICS Evasion, Impair Process Control technique. Adversaries may send unauthorized messages to ICS systems and devices to evade defenses or manipulate processes. Unauthorized messages can be categorized as either reporting messages...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1692-unauthorized-message
- T1692.001 T1692.001
An ICS Evasion, Impair Process Control technique. Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1692-001-command-message
- T1692.002 T1692.002
An ICS Evasion, Impair Process Control technique. Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry data (e.g.,...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1692-002-reporting-message
- T1693 T1693
An ICS Persistence, Inhibit Response Function, Impair Process Control technique. Firmware is low-level software embedded in hardware that enables systems and devices to function properly and is commonly found in ICS environments....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1693-modify-firmware
- T1693.001 T1693.001
An ICS Persistence, Inhibit Response Function, Impair Process Control technique. System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1693-001-system-firmware
- T1693.002 T1693.002
An ICS Persistence, Inhibit Response Function, Impair Process Control technique. Adversaries may install malicious or vulnerable firmware onto modular hardware devices. Control system devices often contain modular hardware devices....
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1693-002-module-firmware
- T1694 T1694
An ICS Persistence, Lateral Movement technique. Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1694-insecure-credentials
- T1694.001 T1694.001
An ICS Persistence, Lateral Movement technique. Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1694-001-default-credentials
- T1694.002 T1694.002
An ICS Persistence, Lateral Movement technique. Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset. Examples credentials that may be hardcoded in...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1694-002-hardcoded-credentials
- T1695 T1695
An ICS Inhibit Response Function technique. Operational technology communications occur over serial COM, Ethernet, Wi-Fi, cellular (4G/5G), and satellite mediums. Adversaries may block communications to prevent reporting messages and...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1695-block-communications
- T1695.001 T1695.001
An ICS Inhibit Response Function technique. Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices. Serial Communication ports (COM) allow communication with control system...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1695-001-serial-com
- T1695.002 T1695.002
An ICS Inhibit Response Function technique. Adversaries may block access to Ethernet communications to prevent instructions or configurations messages from reaching target systems and devices. Ethernet connections allow for...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1695-002-ethernet
- T1695.003 T1695.003
An ICS Inhibit Response Function technique. Adversaries may block access to Wi-Fi communications to prevent messages from reaching target systems and devices. Wi-Fi connections allow for communications between IT and OT systems and...
Bidda node: https://bidda.com/intelligence/mitre-attack-ics-t1695-003-wi-fi
Full interactive matrix: https://bidda.com/mitre-ics
MITRE source: https://attack.mitre.org/matrices/ics/