+ICS ATT&CK
---+Application Isolation and Sandboxing
---+Filter Network Traffic
---+Restrict Web-Based Content
---+Validate Program Inputs
---+Network Segmentation
---+Restrict Library Loading
---+Active Directory Configuration
---+Network Intrusion Prevention
---+Restrict Registry Permissions
---+Data Loss Prevention
---+Access Management
---+Mitigation Limited or Not Effective
---+Exploit Protection
---+Limit Access to Resource Over Network
---+Execution Prevention
---+Static Network Configuration
---+Password Policies
---+Privileged Account Management
---+Human User Authentication
---+SSL/TLS Inspection
---+Code Signing
---+Software Process and Device Authentication
---+Encrypt Network Traffic
---+Account Use Policies
---+Application Developer Guidance
---+Boot Integrity
---+Mechanical Protection Layers
---+Update Software
---+Watchdog Timers
---+Operational Information Confidentiality
---+Operating System Configuration
---+Limit Hardware Installation
---+Encrypt Sensitive Information
---+Network Allowlists
---+Supply Chain Management
---+Data Backup
---+Out-of-Band Communications Channel
---+Audit
---+Communication Authenticity
---+Disable or Remove Feature or Program
---+Threat Intelligence Program
---+Safety Instrumented Systems
---+User Training
---+Multi-factor Authentication
---+Vulnerability Scanning
---+Authorization Enforcement
---+User Account Management
---+Redundancy of Service
---+Restrict File and Directory Permissions
---+Software Configuration
---+Antivirus/Antimalware
---+Minimize Wireless Signal Propagation
---+Analytic 1881
---+Analytic 1936
---+Analytic 1855
---+Analytic 2055
---+Analytic 2048
---+Analytic 1916
---+Analytic 1886
---+Analytic 1860
---+Analytic 1895
---+Analytic 1874
---+Analytic 2058
---+Analytic 1859
---+Analytic 1925
---+Analytic 1926
---+Analytic 1932
---+Analytic 1907
---+Analytic 2066
---+Analytic 1868
---+Analytic 1872
---+Analytic 1879
---+Analytic 1914
---+Analytic 1909
---+Analytic 1929
---+Analytic 1924
---+Analytic 1880
---+Analytic 1921
---+Analytic 1893
---+Analytic 2057
---+Analytic 1899
---+Analytic 2053
---+Analytic 1864
---+Analytic 1920
---+Analytic 1908
---+Analytic 2050
---+Analytic 1882
---+Analytic 1913
---+Analytic 2045
---+Analytic 1894
---+Analytic 1883
---+Analytic 2052
---+Analytic 1901
---+Analytic 2049
---+Analytic 1897
---+Analytic 1898
---+Analytic 1892
---+Analytic 1870
---+Analytic 1905
---+Analytic 1887
---+Analytic 1858
---+Analytic 1902
---+Analytic 1918
---+Analytic 1862
---+Analytic 1928
---+Analytic 1922
---+Analytic 1915
---+Analytic 1863
---+Analytic 1900
---+Analytic 1889
---+Analytic 1911
---+Analytic 1935
---+Analytic 1877
---+Analytic 1878
---+Analytic 1934
---+Analytic 1869
---+Analytic 1866
---+Analytic 1885
---+Analytic 1896
---+Analytic 1930
---+Analytic 1871
---+Analytic 1884
---+Analytic 1876
---+Analytic 1906
---+Analytic 2046
---+Analytic 1910
---+Analytic 1865
---+Analytic 1856
---+Analytic 1931
---+Analytic 1903
---+Analytic 1917
---+Analytic 1923
---+Analytic 1904
---+Analytic 1873
---+Analytic 1857
---+Analytic 2054
---+Analytic 1867
---+Analytic 2056
---+Analytic 1875
---+Analytic 1912
---+Analytic 1891
---+Analytic 1861
---+Analytic 1919
---+Analytic 1888
---+Analytic 2051
---+Analytic 1890
---+Analytic 1927
---+Analytic 2047
---+Analytic 1933
---+Virtual Private Network (VPN) Server
---+Jump Host
---+Remote Terminal Unit (RTU)
---+Field I/O
---+Human-Machine Interface (HMI)
---+Programmable Automation Controller (PAC)
---+Data Gateway
---+Safety Controller
---+Intelligent Electronic Device (IED)
---+Distributed Control System (DCS) Controller
---+Application Server
---+Programmable Logic Controller (PLC)
---+Firewall
---+Switch
---+Routers
---+Data Historian
---+Control Server
---+Workstation
---+Windows Registry Key Deletion
---+Network Connection Creation
---+File Access
---+File Creation
---+Network Traffic Content
---+Logon Session Metadata
---+Process Creation
---+Drive Creation
---+Process/Event Alarm
---+Drive Modification
---+Service Creation
---+Process Termination
---+File Metadata
---+Service Modification
---+Command Execution
---+Service Metadata
---+Scheduled Job Metadata
---+File Modification
---+Software
---+Process History/Live Data
---+OS API Execution
---+Application Log Content
---+Logon Session Creation
---+Device Alarm
---+Script Execution
---+Network Traffic Flow
---+User Account Authentication
---+Asset Inventory
---+Firmware Modification
---+Module Load
---+Windows Registry Key Modification
---+File Deletion
---+Process Metadata
---+Scheduled Job Creation
---+Network Share Access
---+Scheduled Job Modification
---+Detection of Rootkit
---+Detection of Block Reporting Message
---+Detection of Masquerading
---+Detection of Denial of Service
---+Detection of Project File Infection
---+Detection of System Firmware
---+Detection of Exploitation for Privilege Escalation
---+Detection of Alarm Suppression
---+Detection of Denial of View
---+Detection of Device Restart/Shutdown
---+Detection of Denial of Control
---+Detection of Theft of Operational Information
---+Detection of Block Command Message
---+Detection of Program Download All
---+Detection of Siemens Project File Format Infection
---+Detection of Change Credential
---+Detection of Commonly Used Port
---+Detection of Loss of Control
---+Detection of Data from Local System
---+Detection of Screen Capture
---+Detection of Brute Force I/O
---+Detection of Network Connection Enumeration
---+Detection of Automated Collection
---+Detection of Modify Parameter
---+Detection of Manipulation of View
---+Detection of Block Serial COM
---+Detection of System Binary Proxy Execution
---+Detection of Block Wi-Fi
---+Detection of Point & Tag Identification
---+Detection of Multicast Discovery
---+Detection of Supply Chain Compromise
---+Detection of Native API
---+Detection of Monitor Process State
---+Detection of Lateral Tool Transfer
---+Detection of Remote System Information Discovery
---+Detection of Exploitation of Remote Services
---+Detection of Port Scan
---+Detection of Activate Firmware Update Mode
---+Detection of Block Operational Technology Message
---+Detection of Program Upload
---+Detection of Program Download
---+Detection of Standard Application Layer Protocol
---+Detection of Firmware Modification
---+Detection of Remote Services
---+Detection of Wireless Compromise
---+Detection of Modify Program
---+Detection of Modify Alarm Settings
---+Detection of Graphical User Interface
---+Detection of Connection Proxy
---+Detection of Drive-by Compromise
---+Detection of Transient Cyber Asset
---+Detection of Autorun Image
---+Detection of Exploitation for Evasion
---+Detection of Rogue Master
---+Detection of Hooking
---+Detection of Data from Information Repositories
---+Detection of Loss of View
---+Detection of Exploit Public-Facing Application
---+Detection of Manipulate I/O Image
---+Detection of Manipulation of Control
---+Detection of Default Credentials
---+Detection of Service Stop
---+Detection of Adversary-in-the-Middle
---+Detection of Spearphishing Attachment
---+Detection of Wireless Sniffing
---+Detection of Command-Line Interface
---+Detection of Spoof Reporting Message
---+Detection of Online Edit
---+Detection of Loss of Protection
---+Detection of Broadcast Discovery
---+Detection of Loss of Productivity and Revenue
---+Detection of Block Communications
---+Detection of Internet Accessible Device
---+Detection of I/O Image
---+Detection of Replication Through Removable Media
---+Detection of Unauthorized Command Message
---+Detection of Loss of Availability
---+Detection of Hardcoded Credentials
---+Detection of Module Firmware
---+Detection of Detect Operating Mode
---+Detection of Indicator Removal on Host
---+Detection of Program Append
---+Detection of External Remote Services
---+Detection of User Execution
---+Detection of Remote System Discovery
---+Detection of Data Destruction
---+Detection of Execution through API
---+Detection of Unauthorized Message
---+Detection of Network Sniffing
---+Detection of Damage to Property
---+Detection of Scripting
---+Detection of Loss of Safety
---+Detection of Change Operating Mode
---+Detection of Modify Controller Tasking
---+Detection of Block Ethernet
---+Detection of Insecure Credentials
---+Detection of Valid Accounts
---+ATT&CK for ICS
------+Initial Access
---------+Wireless Compromise
---------+Exploit Public-Facing Application
---------+Transient Cyber Asset
---------+Data Historian Compromise
---------+Supply Chain Compromise
---------+Spearphishing Attachment
---------+Drive-by Compromise
---------+Exploitation of Remote Services
---------+External Remote Services
---------+Rogue Master
---------+Replication Through Removable Media
---------+Engineering Workstation Compromise
---------+Remote Services
---------+Internet Accessible Device
------+Execution
---------+Modify Controller Tasking
---------+Command-Line Interface
---------+User Execution
---------+Change Operating Mode
---------+Scripting
---------+Execution through API
---------+Autorun Image
---------+Change Program State
---------+Hooking
---------+Program Organization Units
---------+Graphical User Interface
---------+Native API
------+Persistence
---------+Insecure Credentials
------------+Default Credentials
------------+Hardcoded Credentials
---------+Modify Firmware
------------+System Firmware
------------+Module Firmware
---------+Valid Accounts
---------+Project File Infection
------------+Siemens Project File Format
---------+Modify Program
------+Privilege Escalation
---------+Exploitation for Privilege Escalation
------+Evasion
---------+System Binary Proxy Execution
---------+Rootkit
---------+Indicator Removal on Host
---------+Exploitation for Evasion
---------+Masquerading
---------+Unauthorized Message
------------+Command Message
------------+Reporting Message
------+Discovery
---------+Wireless Sniffing
---------+Remote System Information Discovery
---------+Network Sniffing
---------+Network Service Scanning
---------+Serial Connection Enumeration
---------+Control Device Identification
---------+Remote System Discovery
------------+Port Scan
------------+Multicast Discovery
------------+Broadcast Discovery
---------+I/O Module Discovery
---------+Network Connection Enumeration
------+Lateral Movement
---------+Program Download
------------+Program Append
------------+Download All
------------+Online Edit
---------+Lateral Tool Transfer
------+Collection
---------+Role Identification
---------+Point & Tag Identification
---------+Detect Operating Mode
---------+Monitor Process State
---------+Program Upload
---------+Data from Information Repositories
---------+Automated Collection
---------+I/O Image
---------+Location Identification
---------+Detect Program State
---------+Adversary-in-the-Middle
---------+Screen Capture
---------+Data from Local System
------+Command and Control
---------+Connection Proxy
---------+Standard Application Layer Protocol
---------+Commonly Used Port
------+Inhibit Response Function
---------+Service Stop
---------+Activate Firmware Update Mode
---------+Denial of Service
---------+Device Restart/Shutdown
---------+Alarm Suppression
---------+Block Operational Technology Message
------------+Command Message
------------+Reporting Message
---------+Manipulate I/O Image
---------+Data Destruction
---------+Modify Control Logic
---------+Modify Alarm Settings
---------+Change Credential
---------+Block Communications
------------+Serial COM
------------+Ethernet
------------+Wi-Fi
------+Impair Process Control
---------+Modify Parameter
---------+Brute Force I/O
------+Impact
---------+Loss of View
---------+Manipulation of Control
---------+Loss of Protection
---------+Manipulation of View
---------+Denial of View
---------+Loss of Safety
---------+Loss of Productivity and Revenue
---------+Damage to Property
---------+Loss of Control
---------+Loss of Availability
---------+Theft of Operational Information
---------+Denial of Control
|
ICS ATT&CK
The ATT&CK for Industrial Control Systems (ICS) knowledge base categorizes the unique set of tactics, techniques, and procedures (TTPs) used by threat actors in the ICS technology domain. ATT&CK for ICS outlines the portions of an ICS attack that are out of scope of Enterprise and reflects the various phases of an adversary’s attack life cycle and the assets and systems they are known to target.
1. Overview
| Summary |
Standard |
|
Application Isolation and Sandboxing
|
Restrict the execution of code to a virtual environment on or in-transit to an endpoint system.
|
|
Filter Network Traffic
|
Use network appliances to filter ingress or egress traffic and perform protocol-based filtering. Configure software on endpoints to filter network traffic. Perform inline allow/denylisting of network messages based on the application layer (OSI Layer 7) protocol, especially for automation protocols. Application allowlists are beneficial when there are well-defined communication sequences, types, rates, or patterns needed during expected system operations. Application denylists may be needed if all acceptable communication sequences cannot be defined, but instead a set of known malicious uses can be denied (e.g., excessive communication attempts, shutdown messages, invalid commands). Devices performing these functions are often referred to as deep-packet inspection (DPI) firewalls, context-aware firewalls, or firewalls blocking specific automation/SCADA protocol aware firewalls. (Citation: Centre for the Protection of National Infrastructure February 2005)
|
|
Restrict Web-Based Content
|
Restrict use of certain websites, block downloads/attachments, block Javascript, restrict browser extensions, etc.
|
|
Validate Program Inputs
|
Devices and programs designed to interact with control system parameters should validate the format and content of all user inputs and actions to ensure the values are within intended operational ranges. These values should be evaluated and further enforced through the program logic running on the field controller. If a problematic or invalid input is identified, the programs should either utilize a predetermined safe value or enter a known safe state, while also logging or alerting on the event.(Citation: PLCTop20 Mar 2023)
|
|
Network Segmentation
|
Architect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. Restrict network access to only required systems and services. In addition, prevent systems from other networks or business functions (e.g., enterprise) from accessing critical process control systems. For example, in IEC 62443, systems within the same secure level should be grouped into a zone, and access to that zone is restricted by a conduit, or mechanism to restrict data flows between zones by segmenting the network. (Citation: IEC February 2019) (Citation: IEC August 2013)
|
|
Restrict Library Loading
|
Prevent abuse of library loading mechanisms in the operating system and software to load untrusted code by configuring appropriate library loading mechanisms and investigating potential vulnerable software.
|
|
Active Directory Configuration
|
Configure Active Directory to prevent use of certain techniques; use security identifier (SID) Filtering, etc.
|
|
Network Intrusion Prevention
|
Use intrusion detection signatures to block traffic at network boundaries. In industrial control environments, network intrusion prevention should be configured so it will not disrupt protocols and communications responsible for real-time functions related to control or safety.
|
|
Restrict Registry Permissions
|
Restrict the ability to modify certain hives or keys in the Windows Registry.
|
|
Data Loss Prevention
|
Data Loss Prevention (DLP) technologies can be used to help identify adversarial attempts to exfiltrate operational information, such as engineering plans, trade secrets, recipes, intellectual property, or process telemetry. DLP functionality may be built into other security products such as firewalls or standalone suites running on the network and host-based agents. DLP may be configured to prevent the transfer of information through corporate resources such as email, web, and physical media such as USB for host-based solutions.
|
|
Access Management
|
Access Management technologies can be used to enforce authorization polices and decisions, especially when existing field devices do not provide sufficient capabilities to support user identification and authentication. (Citation: McCarthy, J et al. July 2018) These technologies typically utilize an in-line network device or gateway system to prevent access to unauthenticated users, while also integrating with an authentication service to first verify user credentials. (Citation: Centre for the Protection of National Infrastructure November 2010)
|
|
Mitigation Limited or Not Effective
|
This type of attack technique cannot be easily mitigated with preventative controls since it is based on the abuse of system features.
|
|
Exploit Protection
|
Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring.
|
|
Limit Access to Resource Over Network
|
Prevent access to file shares, remote access to systems, unnecessary services. Mechanisms to limit access may include use of network concentrators, RDP gateways, etc.
|
|
Execution Prevention
|
Block execution of code on a system through application control, and/or script blocking.
|
|
Static Network Configuration
|
Configure hosts and devices to use static network configurations when possible, protocols that require dynamic discovery/addressing (e.g., ARP, DHCP, DNS) can be used to manipulate network message forwarding and enable various AiTM attacks. This mitigation may not always be usable due to limited device features or challenges introduced with different network configurations.
|
|
Password Policies
|
Set and enforce secure password policies for accounts.
|
|
Privileged Account Management
|
Manage the creation, modification, use, and permissions associated to privileged accounts, including SYSTEM and root.
|
|
Human User Authentication
|
Require user authentication before allowing access to data or accepting commands to a device. While strong multi-factor authentication is preferable, it is not always feasible within ICS environments. Performing strong user authentication also requires additional security controls and processes which are often the target of related adversarial techniques (e.g., Valid Accounts, Default Credentials). Therefore, associated ATT&CK mitigations should be considered in addition to this, including [Multi-factor Authentication](https://attack.mitre.org/mitigations/M0932), [Account Use Policies](https://attack.mitre.org/mitigations/M0936), [Password Policies](https://attack.mitre.org/mitigations/M0927), [User Account Management](https://attack.mitre.org/mitigations/M0918), [Privileged Account Management](https://attack.mitre.org/mitigations/M0926), and [User Account Control](https://attack.mitre.org/mitigations/M1052).
|
|
SSL/TLS Inspection
|
Break and inspect SSL/TLS sessions to look at encrypted web traffic for adversary activity.
|
|
Code Signing
|
Enforce binary and application integrity with digital signature verification to prevent untrusted code from executing.
|
|
Software Process and Device Authentication
|
Require the authentication of devices and software processes where appropriate. Devices that connect remotely to other systems should require strong authentication to prevent spoofing of communications. Furthermore, software processes should also require authentication when accessing APIs.
|
|
Encrypt Network Traffic
|
Utilize strong cryptographic techniques and protocols to prevent eavesdropping on network communications.
|
|
Account Use Policies
|
Configure features related to account use like login attempt lockouts, specific login times, etc.
|
|
Application Developer Guidance
|
This mitigation describes any guidance or training given to developers of applications to avoid introducing security weaknesses that an adversary may be able to take advantage of.
|
|
Boot Integrity
|
Use secure methods to boot a system and verify the integrity of the operating system and loading mechanisms.
|
|
Mechanical Protection Layers
|
Utilize a layered protection design based on physical or mechanical protection systems to prevent damage to property, equipment, human safety, or the environment. Examples include interlocks, rupture disk, release values, etc. (Citation: A G Foord, W G Gulland, C R Howard, T Kellacher, W H Smith 2004)
|
|
Update Software
|
Perform regular software updates to mitigate exploitation risk. Software updates may need to be scheduled around operational down times.
|
|
Watchdog Timers
|
Utilize watchdog timers to ensure devices can quickly detect whether a system is unresponsive.
|
|
Operational Information Confidentiality
|
Deploy mechanisms to protect the confidentiality of information related to operational processes, facility locations, device configurations, programs, or databases that may have information that can be used to infer organizational trade-secrets, recipes, and other intellectual property (IP).
|
|
Operating System Configuration
|
Make configuration changes related to the operating system or a common feature of the operating system that result in system hardening against techniques.
|
|
Limit Hardware Installation
|
Block users or groups from installing or using unapproved hardware on systems, including USB devices.
|
|
Encrypt Sensitive Information
|
Protect sensitive data-at-rest with strong encryption.
|
|
Network Allowlists
|
Network allowlists can be implemented through either host-based files or system hosts files to specify what connections (e.g., IP address, MAC address, port, protocol) can be made from a device. Allowlist techniques that operate at the application layer (e.g., DNP3, Modbus, HTTP) are addressed in [Filter Network Traffic](https://attack.mitre.org/mitigations/M0937) mitigation.
|
|
Supply Chain Management
|
Implement a supply chain management program, including policies and procedures to ensure all devices and components originate from a trusted supplier and are tested to verify their integrity.
|
|
Data Backup
|
Take and store data backups from end user systems and critical servers. Ensure backup and storage systems are hardened and kept separate from the corporate network to prevent compromise. Maintain and exercise incident response plans (Citation: Department of Homeland Security October 2009), including the management of 'gold-copy' back-up images and configurations for key systems to enable quick recovery and response from adversarial activities that impact control, view, or availability.
|
|
Out-of-Band Communications Channel
|
Have alternative methods to support communication requirements during communication failures and data integrity attacks. (Citation: National Institute of Standards and Technology April 2013) (Citation: Defense Advanced Research Projects Agency)
|
|
Audit
|
Perform audits or scans of systems, permissions, insecure software, insecure configurations, etc. to identify potential weaknesses. Perform periodic integrity checks of the device to validate the correctness of the firmware, software, programs, and configurations. Integrity checks, which typically include cryptographic hashes or digital signatures, should be compared to those obtained at known valid states, especially after events like device reboots, program downloads, or program restarts.
|
|
Communication Authenticity
|
When communicating over an untrusted network, utilize secure network protocols that both authenticate the message sender and can verify its integrity. This can be done either through message authentication codes (MACs) or digital signatures, to detect spoofed network messages and unauthorized connections.
|
|
Disable or Remove Feature or Program
|
Remove or deny access to unnecessary and potentially vulnerable software to prevent abuse by adversaries.
|
|
Threat Intelligence Program
|
A threat intelligence program helps an organization generate their own threat intelligence information and track trends to inform defensive priorities to mitigate risk.
|
|
Safety Instrumented Systems
|
Utilize Safety Instrumented Systems (SIS) to provide an additional layer of protection to hazard scenarios that may cause property damage. A SIS will typically include sensors, logic solvers, and a final control element that can be used to automatically respond to an hazardous condition (Citation: A G Foord, W G Gulland, C R Howard, T Kellacher, W H Smith 2004) . Ensure that all SISs are segmented from operational networks to prevent them from being targeted by additional adversarial behavior.
|
|
User Training
|
Train users to be aware of access or manipulation attempts by an adversary to reduce the risk of successful spearphishing, social engineering, and other techniques that involve user interaction.
|
|
Multi-factor Authentication
|
Use two or more pieces of evidence to authenticate to a system; such as username and password in addition to a token from a physical smart card or token generator. Within industrial control environments assets such as low-level controllers, workstations, and HMIs have real-time operational control and safety requirements which may restrict the use of multi-factor.
|
|
Vulnerability Scanning
|
Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them.
|
|
Authorization Enforcement
|
The device or system should restrict read, manipulate, or execute privileges to only authenticated users who require access based on approved security policies. Role-based Access Control (RBAC) schemes can help reduce the overhead of assigning permissions to the large number of devices within an ICS. For example, IEC 62351 provides examples of roles used to support common system operations within the electric power sector (Citation: International Electrotechnical Commission July 2020), while IEEE 1686 defines standard permissions for users of IEDs. (Citation: Institute of Electrical and Electronics Engineers January 2014)
|
|
User Account Management
|
Manage the creation, modification, use, and permissions associated to user accounts.
|
|
Redundancy of Service
|
Redundancy could be provided for both critical ICS devices and services, such as back-up devices or hot-standbys.
|
|
Restrict File and Directory Permissions
|
Restrict access by setting directory and file permissions that are not specific to users or privileged accounts.
|
|
Software Configuration
|
Implement configuration changes to software (other than the operating system) to mitigate security risks associated with how the software operates.
|
|
Antivirus/Antimalware
|
Use signatures or heuristics to detect malicious software. Within industrial control environments, antivirus/antimalware installations should be limited to assets that are not involved in critical or real-time operations. To minimize the impact to system availability, all products should first be validated within a representative test environment before deployment to production systems. (Citation: NCCIC August 2018)
|
|
Minimize Wireless Signal Propagation
|
Wireless signals frequently propagate outside of organizational boundaries, which provide opportunities for adversaries to monitor or gain unauthorized access to the wireless network. (Citation: CISA March 2010) To minimize this threat, organizations should implement measures to detect, understand, and reduce unnecessary RF propagation. (Citation: DHS National Urban Security Technology Laboratory April 2019)
|
|
Analytic 1881
|
Monitor for unexpected/abnormal access to files that may be malicious collection of local data, such as user files (e.g., .pdf, .docx, .jpg, .dwg ) or local databases.
Monitor for newly executed processes that may search local system sources, such as file systems or local databases, to find files of interest and sensitive data.
Monitor for any suspicious attempts to enable scripts running on a system. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent. Data may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).
Monitor for API calls that may search local system sources, such as file systems or local databases, to find files of interest and sensitive data.
Monitor executed commands and arguments that may search and collect local system sources, such as file systems or local databases, to find files of interest and sensitive data. Remote access tools with built-in features may interact directly with the Windows API to gather data. Data may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).
|
|
Analytic 1936
|
Monitor network data for uncommon data flows (e.g., time of day, unusual source/destination address) that may be related to abuse of [Valid Accounts](https://attack.mitre.org/techniques/T0859) to log into a service specifically designed to accept remote connections, such as RDP, Telnet, SSH, and VNC.
Monitor DLL file events, specifically creation of these files as well as the loading of DLLs into processes specifically designed to accept remote connections, such as RDP, Telnet, SSH, and VNC.
Monitor for user accounts logged into systems they would not normally access or abnormal access patterns, such as multiple systems over a relatively short period of time. Correlate use of login activity related to remote services with unusual behavior or other malicious or suspicious activity. Adversaries will likely need to learn about an environment and the relationships between systems through Discovery techniques prior to attempting Lateral Movement. For added context on adversary procedures and background see [Remote Services](https://attack.mitre.org/techniques/T1021) and applicable sub-techniques.
Monitor for newly executed processes related to services specifically designed to accept remote connections, such as RDP, Telnet, SSH, and VNC. The adversary may use [Valid Accounts](https://attack.mitre.org/techniques/T0859) to login and may perform follow-on actions that spawn additional processes as the user.
Monitor executed commands and arguments to services specifically designed to accept remote connections, such as RDP, Telnet, SSH, and VNC. The adversary may then perform these actions using [Valid Accounts](https://attack.mitre.org/techniques/T0859).
Monitor for newly constructed network connections into a service specifically designed to accept remote connections, such as RDP, Telnet, SSH, and VNC. Monitor network connections involving common remote management protocols, such as ports tcp:3283 and tcp:5900, as well as ports tcp:3389 and tcp:22 for remote logins. The adversary may use [Valid Accounts](https://attack.mitre.org/techniques/T0859) to enable remote logins.
Monitor interactions with network shares, such as reads or file transfers, using remote services such as Server Message Block (SMB). For added context on adversary procedures and background see [Remote Services](https://attack.mitre.org/techniques/T1021) and applicable sub-techniques.
|
|
Analytic 1855
|
Monitor for API calls that can be used to install a hook procedure, such as the SetWindowsHookEx and SetWinEventHook functions.(Citation: Microsoft Hook Overview)(Citation: Volatility Detecting Hooks Sept 2012) Also consider analyzing hook chains (which hold pointers to hook procedures for each type of hook) using tools(Citation: Volatility Detecting Hooks Sept 2012)(Citation: PreKageo Winhook Jul 2011)(Citation: Jay GetHooks Sept 2011) or by programmatically examining internal kernel structures.(Citation: Zairon Hooking Dec 2006)(Citation: EyeofRa Detecting Hooking June 2017)
Verify integrity of live processes by comparing code in memory to that of corresponding static binaries, specifically checking for jumps and other instructions that redirect code flow.
|
|
Analytic 2055
|
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist, alarms may still be visible even if Wi-Fi messages are blocked.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
|
|
Analytic 2048
|
Monitor network traffic for insecure credential use in protocols that allow unencrypted authentication.
Monitor logon sessions for insecure credential use, when feasible.
|
|
Analytic 1916
|
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist alarms may still be visible even if command messages are blocked.
|
|
Analytic 1886
|
Monitor for newly constructed logon behavior within Microsoft's SharePoint can be configured to report access to certain pages and documents.(Citation: Microsoft SharePoint Logging) Sharepoint audit logging can also be configured to report when a user shares a resource.(Citation: Sharepoint Sharing Events) The user access logging within Atlassian's Confluence can also be configured to report access to certain pages and documents through AccessLogFilter.(Citation: Atlassian Confluence Logging) Additional log storage and analysis infrastructure will likely be required for more robust detection capabilities.
In the case of detecting collection from shared network drives monitor for unexpected and abnormal accesses to network shares.
Monitor for third-party application logging, messaging, and/or other artifacts that may leverage information repositories to mine valuable information. Information repositories generally have a considerably large user base, detection of malicious use can be non-trivial. At minimum, access to information repositories performed by privileged users (for example, Active Directory Domain, Enterprise, or Schema Administrators) should be closely monitored and alerted upon, as these types of accounts should generally not be used to access information repositories. If the capability exists, it may be of value to monitor and alert on users that are retrieving and viewing a large number of documents and pages; this behavior may be indicative of programmatic means being used to retrieve all data within the repository. In environments with high-maturity, it may be possible to leverage User-Behavioral Analytics (UBA) platforms to detect and alert on user-based anomalies.
|
|
Analytic 1860
|
Monitor ICS automation network protocols for functions related to reading an operational process state (e.g., “Read” function codes in protocols like DNP3 or Modbus). In some cases, there may be multiple ways to monitor an operational process’ state, one of which is typically used in the operational environment. Monitor for the operating mode being checked in unexpected ways.
Monitor applications logs for any access attempts to operational databases (e.g., historians) or other sources of operational data within the ICS environment. These devices should be monitored for adversary collection using techniques relevant to the underlying technologies (e.g., Windows, Linux).
|
|
Analytic 1895
|
No standard detection method currently exists for this technique.
|
|
Analytic 1874
|
Monitor asset application logs for information that indicate task parameters have changed.
Monitor device alarms that indicate controller task parameters have changed, although not all devices produce such alarms.
[Program Download](https://attack.mitre.org/techniques/T0843) may be used to enable this technique. Monitor for program downloads which may be noticeable via operational alarms. Asset management systems should be consulted to understand expected program versions.
Engineering and asset management software will often maintain a copy of the expected program loaded on a controller and may also record any changes made to controller programs and tasks. Data from these platforms can be used to identify modified controller tasking.
|
|
Analytic 2058
|
Monitor device alarms for program downloads, although not all devices produce such alarms.
Monitor for protocol functions related to program download or modification. Program downloads may be observable in ICS automation protocols and remote management protocols.
Consult asset management systems to understand expected program versions.
Monitor devices configuration logs which may contain alerts that indicate whether a program download has occurred. Devices may maintain application logs that indicate whether a full program download, online edit, or program append function has occurred.
|
|
Analytic 1859
|
Monitor login sessions for new or unexpected devices or sessions on wireless networks.
Monitor application logs for new or unexpected devices or sessions on wireless networks.
New or irregular network traffic flows may indicate potentially unwanted devices or sessions on wireless networks. In Wi-Fi networks monitor for changes such as rogue access points or low signal strength, indicating a device is further away from the access point then expected and changes in the physical layer signal.(Citation: Nzyme Alerts Intro) (Citation: Wireless Intrusion Detection) Network traffic content will provide important context, such as hardware (e.g., MAC) addresses, user accounts, and types of messages sent.
|
|
Analytic 1925
|
Monitor for any suspicious attempts to enable script execution on a system. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent.
Monitor executed commands and associated arguments for application programs which support executing custom code, scripts, commands, or executables.
Monitor for unusual processes execution, especially for processes that allow the proxy execution of malicious files.
|
|
Analytic 1926
|
Monitor industrial process history data for events that correspond with command message functions, such as setpoint modification or changes to system status for key devices. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor for anomalous or unexpected commands that may result in changes to the process operation (e.g., discrete write, logic and device configuration, mode changes) observable via asset application logs.
Monitor for new or unexpected connections to controllers, which could indicate an Unauthorized Command Message being sent via [Rogue Master](https://attack.mitre.org/techniques/T0848).
Monitor for anomalous or unexpected commands that may result in changes to the process operation (e.g., discrete write, logic and device configuration, mode changes) observable via asset application logs.
Monitor for unexpected ICS protocol command functions to controllers from existing master devices (including from new processes) or from new devices. The latter is like detection for [Rogue Master](https://attack.mitre.org/techniques/T0848) but requires ICS function level insight to determine if an unauthorized device is issuing commands (e.g., a historian).
Monitoring for unexpected or problematic values below the function level will provide better insights into potentially malicious activity but at the cost of additional false positives depending on the underlying operational process.
|
|
Analytic 1932
|
Monitor for newly executed processes that can aid in sniffing network traffic to capture information about an environment.
Monitor executed commands and arguments for actions that aid in sniffing network traffic to capture information about an environment.
|
|
Analytic 1907
|
No standard detection method currently exists for this technique.
|
|
Analytic 2066
|
Monitor for newly constructed drive letters or mount points to removable media. Monitor for newly executed processes that execute from removable media after it is mounted or when initiated by a user.
|
|
Analytic 1868
|
Monitor command-line arguments for script execution and subsequent behavior. Actions may be related to network and system information Discovery, Collection, or other scriptable post-compromise behaviors and could be used as indicators of detection leading back to the source script. Scripts are likely to perform actions with various effects on a system that may generate events, depending on the types of monitoring used.
Monitor log files for process execution through command-line and scripting activities. This information can be useful in gaining additional insight to adversaries' actions through how they use native processes or custom tools. Also monitor for loading of modules associated with specific languages.
Monitor contextual data about a running process, which may include information such as environment variables, image name, user/owner, or other information that may reveal abuse of system features.
Monitor for events associated with scripting execution, such as the loading of modules associated with scripting languages (e.g., JScript.dll, vbscript.dll).
Monitor for any attempts to enable scripts running on a system would be considered suspicious. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent.
|
|
Analytic 1872
|
Monitor for files (such as /etc/hosts) being accessed that may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
Monitor for newly executed processes that can be used to discover remote systems, such as ping.exe and tracert.exe , especially when executed in quick succession.(Citation: Elastic - Koadiac Detection with EQL) Consider monitoring for new processes engaging in scanning activity or connecting to multiple systems by correlating process creation network data.
Monitor for anomalies related to discovery related ICS functions, including devices that have not previously used these functions or for functions being sent to many outstations. Note that some ICS protocols use broadcast or multicast functionality, which may produce false positives. Also monitor for hosts enumerating network connected resources using non-ICS enterprise protocols.
Monitor for new ICS protocol connections to existing assets or for device scanning (i.e., a host connecting to many devices) over ICS and enterprise protocols (e.g., ICMP, DCOM, WinRM). For added context on adversary enterprise procedures and background see [Remote System Discovery](https://attack.mitre.org/techniques/T1018).
|
|
Analytic 1879
|
Various techniques enable spoofing a reporting message. Consider monitoring for [Rogue Master](https://attack.mitre.org/techniques/T0848) and [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T0830) activity which may precede this technique.
Monitor asset logs for alarms or other information the adversary is unable to directly suppress. Relevant alarms include those from a loss of communications due to [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T0830) activity.
Various techniques enable spoofing a reporting message. Monitor for LLMNR/NBT-NS poisoning via new services/daemons which may be used to enable this technique. For added context on adversary procedures and background see [Name Resolution Poisoning and SMB Relay](https://attack.mitre.org/techniques/T1557/001).
Spoofed reporting messages may be detected by reviewing the content of automation protocols, either through detecting based on expected values or comparing to other out of band process data sources. Spoofed messages may not precisely match legitimate messages which may lead to malformed traffic, although traffic may be malformed for many benign reasons. Monitor reporting messages for changes in how they are constructed.
Various techniques enable spoofing a reporting message. Consider monitoring for [Rogue Master](https://attack.mitre.org/techniques/T0848) and [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T0830) activity.
|
|
Analytic 1914
|
Monitor for unusual network traffic that may indicate additional tools transferred to the system. Use network intrusion detection systems, sometimes with SSL/TLS inspection, to look for known malicious scripts (recon, heap spray, and browser identification scripts have been frequently reused), common script obfuscation, and exploit code.
Firewalls and proxies can inspect URLs for potentially known-bad domains or parameters. They can also do reputation-based analytics on websites and their requested resources such as how old a domain is, who it's registered to, if it's on a known bad list, or how many other users have connected to it before.
Monitor for behaviors on the endpoint system that might indicate successful compromise, such as abnormal behaviors of browser processes. This could include suspicious files written to disk.
Monitor for newly constructed files written to disk through a user visiting a website over the normal course of browsing.
Monitor for newly constructed network connections to untrusted hosts that are used to send or receive data.
|
|
Analytic 1909
|
Monitor ICS asset application logs that indicate alarm settings have changed, although not all assets will produce such logs.
Consult asset management systems to understand expected alarm settings.
Data about the industrial process may indicate it is operating outside of expected bounds and could help indicate that that an alarm setting has changed. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor for alarm setting changes observable in automation or management network protocols.
|
|
Analytic 1929
|
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist alarms may still be visible even if messages over serial COM ports are blocked.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
|
|
Analytic 1924
|
Consult asset management systems which may help with the detection of computer systems or network devices that should not exist on a network.
Monitor for network traffic originating from unknown/unexpected devices or addresses. Local network traffic metadata could be used to identify unexpected connections, including unknown/unexpected source MAC addresses connecting to ports associated with operational protocols. Also, network management protocols such as DHCP and ARP may be helpful in identifying unexpected devices.
Monitor for new master devices communicating with outstations, which may be visible in alarms within the ICS environment.
Monitor for unexpected ICS protocol functions from new and existing devices. Monitoring known devices requires ICS function level insight to determine if an unauthorized device is issuing commands (e.g., a historian).
Monitor for new master devices communicating with outstation assets, which may be visible in asset application logs.
|
|
Analytic 1880
|
No standard detection method currently exists for this technique.
|
|
Analytic 1921
|
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist alarms may still be visible even if reporting messages are blocked.
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
|
|
Analytic 1893
|
Program uploads may be observable in ICS management protocols or file transfer protocols. Note when protocol functions related to program uploads occur. In cases where the ICS protocols is not well understood, one option is to examine network traffic for the program files themselves using signature-based tools.
Monitor device communication patterns to identify irregular bulk transfers of data between the embedded ICS asset and other nodes within the network. Note these indicators are dependent on the profile of normal operations and the capabilities of the industrial automation protocols involved (e.g., partial program uploads).
Monitor for device alarms produced when program uploads occur, although not all devices will produce such alarms.
|
|
Analytic 2057
|
Monitor device alarms for program downloads, although not all devices produce such alarms.
Monitor for protocol functions related to program download or modification. Program downloads may be observable in ICS automation protocols and remote management protocols.
Consult asset management systems to understand expected program versions.
Monitor devices configuration logs which may contain alerts that indicate whether a program download has occurred. Devices may maintain application logs that indicate whether a full program download, online edit, or program append function has occurred.
|
|
Analytic 1899
|
Detecting software exploitation may be difficult depending on the tools available. Software exploits may not always succeed or may cause the exploited process to become unstable or crash, which may be recorded in the application log.
Use deep packet inspection to look for artifacts of common exploit traffic, such as known payloads.
|
|
Analytic 2053
|
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist, alarms may still be visible even if messages are blocked.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
|
|
Analytic 1864
|
Monitor for firmware changes which may be observable via operational alarms from devices.
Monitor device application logs for firmware changes, although not all devices will produce such logs.
Monitor firmware for unexpected changes. Asset management systems should be consulted to understand known-good firmware versions. Dump and inspect BIOS images on vulnerable systems and compare against known good images.(Citation: MITRE Copernicus) Analyze differences to determine if malicious changes have occurred. Log attempts to read/write to BIOS and compare against known patching behavior. Likewise, EFI modules can be collected and compared against a known-clean list of EFI executable binaries to detect potentially malicious modules. The CHIPSEC framework can be used for analysis to determine if firmware modifications have been performed.(Citation: McAfee CHIPSEC Blog)(Citation: Github CHIPSEC)(Citation: Intel HackingTeam UEFI Rootkit)
Monitor ICS management protocols / file transfer protocols for protocol functions related to firmware changes.
|
|
Analytic 1920
|
Monitor ICS automation protocols for anomalies related to reading point or tag data, such as new assets using these functions, changes in volume or timing, or unusual information being queried. Many protocols provide multiple ways to achieve the same result (e.g., functions with/without an acknowledgment or functions that operate on a single point vs. multiple points). Monitor for changes in the functions used.
Monitor asset application logs which may provide information about requests for points or tags. Look for anomalies related to reading point or tag data, such as new assets using these functions, changes in volume or timing, or unusual information being queried. Many devices provide multiple ways to achieve the same result (e.g., functions with/without an acknowledgment or functions that operate on a single point vs. multiple points). Monitor for changes in the functions used.
|
|
Analytic 1908
|
Monitor asset management systems for device configuration changes which can be used to understand expected parameter settings.
Monitor device application logs parameter changes, although not all devices will produce such logs.
Monitor for device alarms produced when parameters are changed, although not all devices will produce such alarms.
Monitor ICS management protocols for parameter changes, including for unexpected values, changes far exceeding standard values, or for parameters being changed in an unexpected way (e.g., via a new function, at an unusual time).
|
|
Analytic 2050
|
Monitor for new processes engaging in scanning activity or connecting to multiple systems by correlating process creation network data.
Monitor for hosts enumerating network connected resources using non-ICS enterprise protocols.
|
|
Analytic 1882
|
Monitor executed commands and arguments that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
Monitor for API calls that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
Monitor for changes made to Windows Registry keys or values that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. For added context on adversary procedures and background see [Indicator Removal](https://attack.mitre.org/techniques/T1070) and applicable sub-techniques.
Monitor for contextual file data that may show signs of deletion or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
Monitor Windows registry keys that may be deleted or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. For added context on adversary procedures and background see [Indicator Removal](https://attack.mitre.org/techniques/T1070) and applicable sub-techniques.
Monitor for a file that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
Monitor for changes made to a file may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
Monitor for newly executed processes that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
|
|
Analytic 1913
|
Monitor for suspicious descendant process spawning from Microsoft Office and other productivity software.(Citation: Elastic - Koadiac Detection with EQL) For added context on adversary procedures and background see [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001).
Monitor for newly constructed files from a spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
Monitor network traffic for suspicious email attachments. Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g., monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Use web proxies to review content of emails including sender information, headers, and attachments for potentially malicious content.
Monitor mail server and proxy logs for evidence of messages originating from spoofed addresses, including records indicating failed DKIM+SPF validation or mismatched message headers.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing) Anti-virus can potentially detect malicious documents and attachments as they're scanned to be stored on the email server or on the user's computer.
|
|
Analytic 2045
|
Unauthorized messages may be detected by reviewing the content of automation protocols, either through detecting based on expected values or comparing to other out of band process data sources. Unauthorized messages may not precisely match legitimate messages which may lead to malformed traffic, although traffic may be malformed for benign reasons. Monitor messages for changes in how they are constructed.
Monitor for anomalous or unexpected messages that may result in changes to the process operation observable via asset application logs (e.g., discrete write, logic and device configuration, mode changes, safety triggers).
Consider monitoring for [Rogue Master](https://attack.mitre.org/techniques/T0848) and [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T0830) activity which may precede this technique.
|
|
Analytic 1894
|
No standard detection method currently exists for this technique.
|
|
Analytic 1883
|
Monitor executed commands and arguments that may attempt to take screen captures of the desktop to gather information over the course of an operation.
Monitoring for screen capture behavior will depend on the method used to obtain data from the operating system and write output files. Detection methods could include collecting information from unusual processes using API calls used to obtain image data, and monitoring for image files written to disk, such as CopyFromScreen, xwd, or screencapture.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware) The data may need to be correlated with other events to identify malicious activity, depending on the legitimacy of this behavior within a given network environment.
|
|
Analytic 2052
|
Monitor for anomalies related to discovery related ICS functions, including devices that have not previously used these functions or for functions being sent to many outstations.
Monitor for new ICS protocol connections to existing assets or for device scanning (i.e., a host connecting to many devices) over ICS and enterprise protocols (e.g., ICMP, DCOM, WinRM). For added context on adversary enterprise procedures and background see [Remote System Discovery](https://attack.mitre.org/techniques/T1018).
|
|
Analytic 1901
|
No standard detection method currently exists for this technique.
|
|
Analytic 2049
|
Monitor for unexpected changes to project files, although if the malicious modification occurs in tandem with legitimate changes it will be difficult to isolate the unintended changes by analyzing only file systems modifications.
|
|
Analytic 1897
|
Monitor for changes made to files that may stop or disable services on a system to render those services unavailable to legitimate users.
Monitor executed commands and arguments that may stop or disable services on a system to render those services unavailable to legitimate users.
Remote access tools with built-in features may interact directly with the Windows API to perform these functions outside of typical system utilities. For example, ChangeServiceConfigW may be used by an adversary to prevent services from starting. For added context on adversary procedures and background see [Service Stop](https://attack.mitre.org/techniques/T1489).
Monitor processes and command-line arguments to see if critical processes are terminated or stop running. For added context on adversary procedures and background see [Service Stop](https://attack.mitre.org/techniques/T1489).
Alterations to the service binary path or the service startup type changed to disabled may be suspicious.
Monitor for changes made to Windows registry keys and/or values that may stop or disable services on a system to render those services unavailable to legitimate users.
Monitor for newly executed processes that may stop or disable services on a system to render those services unavailable to legitimate users.
|
|
Analytic 1898
|
Monitor for unexpected changes to project files, although if the malicious modification occurs in tandem with legitimate changes it will be difficult to isolate the unintended changes by analyzing only file systems modifications.
|
|
Analytic 1892
|
On Windows and Unix systems monitor executed commands and arguments that may use shell commands for execution. Shells may be common on administrator, developer, or power user systems depending on job function.
On network device and embedded system CLIs consider reviewing command history if unauthorized or suspicious commands were used to modify device configuration.
Monitor logs from installed applications (e.g., historian logs) for unexpected commands or abuse of system features.
Monitor for processes spawning from known command shell applications (e.g., PowerShell, Bash). Benign activity will need to be allow-listed. This information can be useful in gaining additional insight to adversaries' actions through how they use native processes or custom tools.
|
|
Analytic 1870
|
Monitor operational process data for write commands for an excessive number of I/O points or manipulating a single value an excessive number of times. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Some asset application logs may provide information on I/O points related to write commands. Monitor for write commands for an excessive number of I/O points or manipulating a single value an excessive number of times.
Monitor network traffic for ICS functions related to write commands for an excessive number of I/O points or manipulating a single value an excessive number of times.
|
|
Analytic 1905
|
A manipulated I/O image requires analyzing the application program running on the PLC for specific data block writes. Detecting this requires obtaining and analyzing a PLC’s application program, either directly from the device or from asset management platforms.
|
|
Analytic 1887
|
Monitor ICS management protocols for functions that change an asset’s operating mode.
Monitor device application logs which may contain information related to operating mode changes, although not all devices produce such logs.
Monitor alarms for information about when an operating mode is changed, although not all devices produce such logs.
|
|
Analytic 1858
|
Monitor for newly constructed services/daemons that may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
Monitor for changes made to files outside of an update or patch that may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
Monitor for file names that are mismatched between the file name on disk and that of the binary's metadata. This is a likely indicator that a binary was renamed after it was compiled. For added context on adversary procedures and background see [Masquerading](https://attack.mitre.org/techniques/T1036) and applicable sub-techniques.
Monitor executed commands and arguments that may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.(Citation: Twitter ItsReallyNick Masquerading Update)
Monitor for changes made to scheduled jobs that may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
Monitor for changes made to services that may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
Collect file hashes. Monitor for file names that do not match their expected hash. Perform file monitoring. Files with known names but in unusual locations are suspect. Look for indications of common characters that may indicate an attempt to trick users into misidentifying the file type, such as a space as the last character of a file name or the right-to-left override characters"\u202E", "[U+202E]", and "%E2%80%AE". For added context on adversary procedures and background see [Masquerading](https://attack.mitre.org/techniques/T1036) and applicable sub-techniques.
Monitor for newly constructed scheduled jobs that may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
|
|
Analytic 1902
|
Monitor executed commands and arguments that may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Also monitor executed commands and arguments that may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. Information may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).
Monitor for executed processes (such as ipconfig/ifconfig and arp) with arguments that may look for details about the network configuration and settings, such as IP and/or MAC addresses. Also monitor for executed processes that may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
Monitor for any suspicious attempts to enable script execution on a system. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent.
Monitor for API calls (such as GetAdaptersInfo() and GetIpNetTable()) that may gather details about the network configuration and settings, such as IP and/or MAC addresses. Also monitor for API calls that may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. For added context on adversary procedures and background see [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016) and [System Network Connections Discovery](https://attack.mitre.org/techniques/T1049).
|
|
Analytic 1918
|
No standard detection method currently exists for this technique.
|
|
Analytic 1862
|
No standard detection method currently exists for this technique.
|
|
Analytic 1928
|
Monitor logon activity for unexpected or unusual access to devices from the Internet.
Monitor for unexpected protocols to/from the Internet. While network traffic content and logon session metadata may directly identify a login event, new Internet-based network flows may also be a reliable indicator of this technique.
Monitor for unusual logins to Internet connected devices or unexpected protocols to/from the Internet. Network traffic content will provide valuable context and details about the content of network flows.
|
|
Analytic 1922
|
Monitor for firmware changes which may be observable via operational alarms from devices.
Monitor device application logs for firmware changes, although not all devices will produce such logs.
Monitor ICS management protocols / file transfer protocols for protocol functions related to firmware changes.
Monitor firmware for unexpected changes. Asset management systems should be consulted to understand known-good firmware versions. Dump and inspect BIOS images on vulnerable systems and compare against known good images.(Citation: MITRE Copernicus) Analyze differences to determine if malicious changes have occurred. Log attempts to read/write to BIOS and compare against known patching behavior. Likewise, EFI modules can be collected and compared against a known-clean list of EFI executable binaries to detect potentially malicious modules. The CHIPSEC framework can be used for analysis to determine if firmware modifications have been performed.(Citation: McAfee CHIPSEC Blog)(Citation: Github CHIPSEC)(Citation: Intel HackingTeam UEFI Rootkit)
|
|
Analytic 1915
|
Monitor device management protocols for functions that modify programs such as online edit and program append events.
Monitor device alarms that indicate the program has changed, although not all devices produce such alarms.
Engineering and asset management software will often maintain a copy of the expected program loaded on a controller and may also record any changes made to controller programs. Data from these platforms can be used to identify modified controller programs.
Monitor device application logs that indicate the program has changed, although not all devices produce such logs.
|
|
Analytic 1863
|
Use verification of distributed binaries through hash checking or other integrity checking mechanisms. Scan downloads for malicious signatures.
|
|
Analytic 1900
|
Monitor ICS automation network protocols for functions related to reading an asset’s operating mode. In some cases, there may be multiple ways to detect a device’s operating mode, one of which is typically used in the operational environment. Monitor for the operating mode being checked in unexpected ways.
|
|
Analytic 1889
|
No standard detection method currently exists for this technique.
|
|
Analytic 1911
|
No standard detection method currently exists for this technique.
|
|
Analytic 1935
|
Monitor for network traffic originating from unknown/unexpected systems.
Monitor authentication logs and analyze for unusual access patterns, windows of activity, and access outside of normal business hours, including use of [Valid Accounts](https://attack.mitre.org/techniques/T0859).
When authentication is not required to access an exposed remote service, monitor for follow-on activities such as anomalous external use of the exposed API or application.
|
|
Analytic 1877
|
Monitor for network traffic originating from unknown/unexpected hardware devices. Local network traffic metadata (such as source MAC addressing) may be helpful in identifying transient assets.
Networking devices such as switches may log when new client devices connect (e.g., SNMP notifications). Monitor for any logs documenting changes to network connection status to determine when a new connection has occurred, including the resulting addresses (e.g., IP, MAC) of devices on that network.
|
|
Analytic 1878
|
Monitor for unexpected network share access, such as files transferred between shares within a network using protocols such as Server Message Block (SMB).
Monitor for alike file hashes or characteristics (ex: filename) that are created on multiple hosts.
Monitor for file creation in conjunction with other techniques (e.g., file transfers using [Remote Services](https://attack.mitre.org/techniques/T0886)).
Monitor for unusual processes with internal network connections creating files on-system which may be suspicious.
Monitor executed commands and arguments for abnormal usage of utilities and command-line arguments that may be used in support of remote transfer of files.
Monitor newly constructed processes that assist in lateral tool transfers, such as file transfer programs.
Monitor for network traffic originating from unknown/unexpected hosts. Local network traffic metadata (such as source MAC addressing) as well as usage of network management protocols such as DHCP may be helpful in identifying hardware.
|
|
Analytic 1934
|
Monitor ICS automation network protocols for information that an asset has been placed into Firmware Update Mode.
Monitor device alarms that indicate the devices has been placed into Firmware Update Mode, although not all devices produce such alarms.
Monitor asset log which may provide information that an asset has been placed into Firmware Update Mode. Some assets may log firmware updates themselves without logging that the device has been placed into update mode.
|
|
Analytic 1869
|
Analyze network data for uncommon data flows (e.g., new protocols in use between hosts, unexpected ports in use). Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor for mismatches between protocols and their expected ports (e.g., non-HTTP traffic on tcp:80). Analyze packet contents to detect communications that do not follow the expected protocol behavior for the port that is being used.(Citation: University of Birmingham C2)
|
|
Analytic 1866
|
Monitor for newly executed processes that execute from removable media after it is mounted or when initiated by a user. If a remote access tool is used in this manner to move laterally, then additional actions are likely to occur after execution, such as opening network connections for Command and Control and system and network information Discovery.
Monitor for newly constructed files copied to or from removable media.
Monitor for newly constructed drive letters or mount points to removable media.
Monitor for files accessed on removable media, particularly those with executable content.
|
|
Analytic 1885
|
Devices that provide user access to the underlying operating system may allow the installation of custom software to monitor OS API execution. Monitoring API calls may generate a significant amount of data and may not be useful for defense unless collected under specific circumstances, since benign use of API functions are common and may be difficult to distinguish from malicious behavior. Correlation of other events with behavior surrounding API function calls using API monitoring will provide additional context to an event that may assist in determining if it is due to malicious behavior.
|
|
Analytic 1896
|
Monitor HKLM\Software\Policies\Microsoft\Windows NT\DNSClient for changes to the "EnableMulticast" DWORD value. A value of "0" indicates LLMNR is disabled.
Host-based implementations of this technique may utilize networking-based system calls or network utility commands (e.g., iptables) to locally intercept traffic. Monitor for relevant process creation events.
Monitor for network traffic originating from unknown/unexpected hosts. Local network traffic metadata (such as source MAC addressing) as well as usage of network management protocols such as DHCP may be helpful in identifying hardware. For added context on adversary procedures and background see [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557) and applicable sub-techniques.
Monitor for newly constructed services/daemons through Windows event logs for event IDs 4697 and 7045.
Monitor network traffic for anomalies associated with known AiTM behavior. For Collection activity where transmitted data is not manipulated, anomalies may be present in network management protocols (e.g., ARP, DHCP).
Monitor application logs for changes to settings and other events associated with network protocols and other services commonly abused for AiTM.
|
|
Analytic 1930
|
Monitor network traffic for hardcoded credential use in protocols that allow unencrypted authentication.
Monitor logon sessions for hardcoded credential use, when feasible.
|
|
Analytic 1871
|
Detecting software exploitation may be difficult depending on the tools available. Software exploits may not always succeed or may cause the exploited process to become unstable or crash.
|
|
Analytic 1884
|
Monitor device alarms for program downloads, although not all devices produce such alarms.
Monitor for protocol functions related to program download or modification. Program downloads may be observable in ICS automation protocols and remote management protocols.
Consult asset management systems to understand expected program versions.
Monitor devices configuration logs which may contain alerts that indicate whether a program download has occurred. Devices may maintain application logs that indicate whether a full program download, online edit, or program append function has occurred.
|
|
Analytic 1876
|
Purely passive network sniffing cannot be detected effectively. In cases where the adversary interacts with the wireless network (e.g., joining a Wi-Fi network) detection may be possible. Monitor for new or irregular network traffic flows which may indicate potentially unwanted devices or sessions on wireless networks. In Wi-Fi networks monitor for changes such as rogue access points or low signal strength, indicating a device is further away from the access point then expected and changes in the physical layer signal.(Citation: Nzyme Alerts Intro) (Citation: Wireless Intrusion Detection) Network traffic content will provide important context, such as hardware (e.g., MAC) addresses, user accounts, and types of messages sent.
|
|
Analytic 1906
|
Collecting information from the I/O image requires analyzing the application program running on the PLC for specific data block reads. Detecting this requires obtaining and analyzing a PLC’s application program, either directly from the device or from asset management platforms.
|
|
Analytic 2046
|
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist alarms may still be visible even if messages are blocked.
|
|
Analytic 1910
|
No standard detection method currently exists for this technique.
|
|
Analytic 1865
|
No standard detection method currently exists for this technique.
|
|
Analytic 1856
|
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g., extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g., monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor for application logging, messaging, and/or other artifacts that may result from Denial of Service (DoS) attacks which degrade or block the availability of services to users. In addition to network level detections, endpoint logging and instrumentation can be useful for detection.
Monitor operational data for indicators of temporary data loss which may indicate a Denial of Service. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
|
|
Analytic 1931
|
Monitor and analyze traffic flows that do not follow the expected protocol standards and traffic flows (e.g., extraneous packets that do not belong to established flows , or gratuitous or anomalous traffic patterns). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g., monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Monitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g., extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g., monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
|
|
Analytic 1903
|
Monitor for device alarms produced when device management passwords are changed, although not all devices will produce such alarms.
Monitor for device credential changes observable in automation or management network protocols.
|
|
Analytic 1917
|
No standard detection method currently exists for this technique.
|
|
Analytic 1923
|
Monitor for newly executed processes that depend on user interaction, especially for applications that can embed programmatic capabilities (e.g., Microsoft Office products with scripts, installers, zip files). This includes compression applications, such as those for zip files, that can be used to [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140) in payloads. For added context on adversary procedures and background see [User Execution](https://attack.mitre.org/techniques/T1204) and applicable sub-techniques.
Monitor for application logging, messaging, and/or other artifacts that may rely upon specific actions by a user in order to gain execution.
Monitor for newly constructed web-based network connections that are sent to malicious or suspicious destinations (e.g., destinations attributed to phishing campaigns). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments (e.g., monitor anomalies in use of files that do not normally initiate network connections or unusual connections initiated by regsvr32.exe, rundll.exe, SCF, HTA, MSI, DLLs, or msiexec.exe).
Anti-virus can potentially detect malicious documents and files that are downloaded and executed on the user's computer. Endpoint sensing or network sensing can potentially detect malicious events once the file is opened (such as a Microsoft Word document or PDF reaching out to the internet or spawning PowerShell).
Monitor for newly executed processes that depend on user interaction, especially for applications that can embed programmatic capabilities (e.g., Microsoft Office products with scripts, installers, zip files). This includes compression applications, such as those for zip files, that can be used to [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140) in payloads.
Monitor and analyze traffic patterns and packet inspection associated with web-based network connections that are sent to malicious or suspicious destinations (e.g., destinations attributed to phishing campaigns). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments (e.g., monitor anomalies in use of files that do not normally initiate network connections or unusual connections initiated by regsvr32.exe, rundll.exe, SCF, HTA, MSI, DLLs, or msiexec.exe).
|
|
Analytic 1904
|
Monitor for newly executed processes related to services specifically designed to accept remote graphical connections, such as RDP and VNC. [Remote Services](https://attack.mitre.org/techniques/T0886) and [Valid Accounts](https://attack.mitre.org/techniques/T0859) may be used to access a host’s GUI.
Monitor executed commands and arguments related to services specifically designed to accept remote graphical connections, such as RDP and VNC. [Remote Services](https://attack.mitre.org/techniques/T0886) and [Valid Accounts](https://attack.mitre.org/techniques/T0859) may be used to access a host’s GUI.
Monitor DLL file events, specifically creation of these binary files as well as the loading of DLLs into processes associated with remote graphical connections, such as RDP and VNC. [Remote Services](https://attack.mitre.org/techniques/T0886) may be used to access a host’s GUI.
Monitor for user accounts logged into systems they would not normally access or abnormal access patterns, such as multiple systems over a relatively short period of time. Correlate use of login activity related to remote services with unusual behavior or other malicious or suspicious activity. [Remote Services](https://attack.mitre.org/techniques/T0886) may be used to access a host’s GUI.
|
|
Analytic 1873
|
Detecting software exploitation may be difficult depending on the tools available. Software exploits may not always succeed or may cause the exploited process to become unstable or crash. Web Application Firewalls may detect improper inputs attempting exploitation.
Use deep packet inspection to look for artifacts of common exploit traffic, such as known payloads.
|
|
Analytic 1857
|
Monitor for an authentication attempt by a user that may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
Monitor for logon behavior that may abuse credentials of existing accounts as a means of gaining Lateral Movement or Persistence. Correlate other security systems with login information (e.g., a user has an active login session but has not entered the building or does not have VPN access).
Monitor for suspicious account behavior across systems that share accounts, either user, admin, or service accounts. Examples: one account logged into multiple systems simultaneously; multiple accounts logged into the same machine simultaneously; accounts logged in at odd times or outside of business hours. Activity may be from interactive login sessions or process ownership from accounts being used to execute binaries on a remote system as a particular account.
|
|
Analytic 2054
|
Monitor asset alarms which may help identify a loss of communications. Consider correlating alarms with other data sources that indicate traffic has been blocked, such as network traffic. In cases where alternative methods of communicating with outstations exist, alarms may still be visible even if Ethernet messages are blocked.
Monitor for a loss of network communications, which may indicate this technique is being used.
Monitor for lack of operational process data which may help identify a loss of communications. This will not directly detect the technique’s execution but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor application logs for changes to settings and other events associated with network protocols that may be used to block communications.
Monitor for the termination of processes or services associated with ICS automation protocols and application software which could help detect blocked communications.
|
|
Analytic 1867
|
Monitor for any suspicious attempts to enable script execution on a system. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible, to determine their actions and intent.
Monitor executed commands and arguments for actions that could be taken to collect internal data.
Monitor for unexpected files (e.g., .pdf, .docx, .jpg) viewed for collecting internal data.
Monitor for information collection on assets that may indicate deviations from standard operational tools. Examples include unexpected industrial automation protocol functions, new high volume communication sessions, or broad collection across many hosts within the network.
|
|
Analytic 2056
|
Monitor device alarms for program downloads, although not all devices produce such alarms.
Monitor for protocol functions related to program download or modification. Program downloads may be observable in ICS automation protocols and remote management protocols.
Consult asset management systems to understand expected program versions.
Monitor devices configuration logs which may contain alerts that indicate whether a program download has occurred. Devices may maintain application logs that indicate whether a full program download, online edit, or program append function has occurred.
|
|
Analytic 1875
|
Devices that provide user access to the underlying operating system may allow the installation of custom software to monitor OS API execution. Monitoring API calls may generate a significant amount of data and may not be useful for defense unless collected under specific circumstances, since benign use of API functions are common and may be difficult to distinguish from malicious behavior. Correlation of other events with behavior surrounding API function calls using API monitoring will provide additional context to an event that may assist in determining if it is due to malicious behavior.
|
|
Analytic 1912
|
Monitor for changes made to firmware for unexpected modifications to settings and/or data that may be used by rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Asset management systems should be consulted to understand known-good firmware versions and configurations.
|
|
Analytic 1891
|
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g., extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g., monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Monitor for known proxy protocols (e.g., SOCKS, Tor, peer-to-peer protocols) and tool usage (e.g., Squid, peer-to-peer software) on the network that are not part of normal operations. Also monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
|
|
Analytic 1861
|
Monitor for loss of network traffic which could indicate alarms are being suppressed. A loss of expected communications associated with network protocols used to communicate alarm events or process data could indicate this technique is being used. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor for loss of operational process data which could indicate alarms are being suppressed. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor for loss of expected device alarms which could indicate alarms are being suppressed. As noted in the technique description, there may be multiple sources of alarms in an ICS environment. Discrepancies between alarms may indicate the adversary is suppressing some but not all the alarms in the environment. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Monitor for loss of expected operational process alarms which could indicate alarms are being suppressed. As noted in the technique description, there may be multiple sources of alarms in an ICS environment. Discrepancies between alarms may indicate the adversary is suppressing some but not all the alarms in the environment. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
|
|
Analytic 1919
|
Monitor for new ICS protocol connections to existing assets or for device scanning (i.e., a host connecting to many devices) over ICS and enterprise protocols (e.g., ICMP, DCOM, WinRM).
Monitor for anomalies related to discovery related ICS functions, including devices that have not previously used these functions or for functions being sent to many outstations. Note that some ICS protocols use broadcast or multicast functionality, which may produce false positives. Also monitor for hosts enumerating network connected resources using non-ICS enterprise protocols.
Monitor for files (such as /etc/hosts) being accessed that may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
Monitor for newly executed processes that can be used to discover remote systems, such as ping.exe and tracert.exe, especially when executed in quick succession.(Citation: Elastic - Koadiac Detection with EQL) Consider monitoring for new processes engaging in scanning activity or connecting to multiple systems by correlating process creation network data.
|
|
Analytic 1888
|
Monitor network traffic for default credential use in protocols that allow unencrypted authentication.
Monitor logon sessions for default credential use.
|
|
Analytic 2051
|
Monitor for anomalies related to discovery related ICS functions, including devices that have not previously used these functions or for functions being sent to many outstations.
Monitor for new ICS protocol connections to existing assets or for device scanning (i.e., a host connecting to many devices) over ICS and enterprise protocols (e.g., ICMP, DCOM, WinRM). For added context on adversary enterprise procedures and background see [Remote System Discovery](https://attack.mitre.org/techniques/T1018).
|
|
Analytic 1890
|
Monitor for changes made to a large quantity of files for unexpected modifications in both user directories and directories used to store programs and OS components (e.g., C:\Windows\System32).
Monitor for newly executed processes of binaries that could be involved in data destruction activity, such as SDelete.
Monitor for unexpected deletion of files.
Monitor executed commands and arguments for binaries that could be involved in data destruction activity, such as SDelete.
|
|
Analytic 1927
|
Detecting software exploitation may be difficult depending on the tools available. Software exploits may not always succeed or may cause the exploited process to become unstable or crash.
|
|
Analytic 2047
|
Monitor for firmware changes which may be observable via operational alarms from devices.
Monitor device application logs for firmware changes, although not all devices will produce such logs.
Monitor ICS management protocols / file transfer protocols for protocol functions related to firmware changes.
Monitor firmware for unexpected changes. Asset management systems should be consulted to understand known-good firmware versions. Dump and inspect BIOS images on vulnerable systems and compare against known good images.(Citation: MITRE Copernicus) Analyze differences to determine if malicious changes have occurred. Log attempts to read/write to BIOS and compare against known patching behavior. Likewise, EFI modules can be collected and compared against a known-clean list of EFI executable binaries to detect potentially malicious modules. The CHIPSEC framework can be used for analysis to determine if firmware modifications have been performed.(Citation: McAfee CHIPSEC Blog)(Citation: Github CHIPSEC)(Citation: Intel HackingTeam UEFI Rootkit)
|
|
Analytic 1933
|
Monitor for a loss of network communications, which may indicate a device has been shutdown or restarted. This will not directly detect the technique’s execution, but instead may provide additional evidence that the technique has been used and may complement other detections.
Device restarts and shutdowns may be observable in device application logs. Monitor for unexpected device restarts or shutdowns.
Devices may produce alarms about restarts or shutdowns. Monitor for unexpected device restarts or shutdowns.
Monitor ICS automation protocols for functions that restart or shutdown a device. Commands to restart or shutdown devices may also be observable in traditional IT management protocols.
|
|
Virtual Private Network (VPN) Server
|
A VPN server is a device that is used to establish a secure network tunnel between itself and other remote VPN devices, including field VPNs. VPN servers can be used to establish a secure connection with a single remote device, or to securely bridge all traffic between two separate networks together by encapsulating all data between those networks. VPN servers typically support remote network services that are used by field VPNs to initiate the establishment of the secure VPN tunnel between the field device and server.
|
|
Jump Host
|
Jump hosts are devices used to support remote management sessions into ICS networks or devices. The system is used to access the ICS environment securely from external networks, such as the corporate network. The user must first remote into the jump host before they can access ICS devices. The jump host may be a customized Windows server using common remote access protocols (e.g., RDP) or a dedicated access management device. The jump host typically performs various security functions to ensure the authenticity of remote sessions, including authentication, enforcing access controls/permissions, and auditing all access attempts.
|
|
Remote Terminal Unit (RTU)
|
A Remote Terminal Unit (RTU) is a device that typically resides between field devices (e.g., PLCs, IEDs) and control/SCADA servers and supports various communication interfacing and data aggregation functions. RTUs are typically responsible for forwarding commands from the control server and the collection of telemetry, events, and alerts from the field devices. An RTU can be implemented as a dedicated embedded device, as software platform that runs on a hardened/ruggedized computer, or using a custom application program on a PLC.
|
|
Field I/O
|
Field I/O are devices that communicate with a controller or data aggregator to either send input data or receive output data. Input data may include readings about a given environment/device state from sensors, while output data may include data sent back to actuators for them to either undertake actions or change parameter values.(Citation: Guidance - NIST SP800-82) These devices are frequently embedded devices running on lightweight embedded operating systems or RTOSes.
|
|
Human-Machine Interface (HMI)
|
Human-Machine Interfaces (HMIs) are systems used by an operator to monitor the real-time status of an operational process and to perform necessary control functions, including the adjustment of device parameters. An HMI can take various forms, including a dedicated screen or control panel integrated with a specific device/controller, or a customizable software GUI application running on a standard operating system (e.g., MS Windows) that interfaces with a control/SCADA server. The HMI is critical to ensuring operators have sufficient visibility and control over the operational process.
|
|
Programmable Automation Controller (PAC)
|
A Programmable Automation Controller (PAC) is an embedded programmable control device. PACs are designed to enable automation applications across integrated software applications, peer controllers (e.g., PLC), Human Machine Interfaces, and other systems. PACs often include advanced features for process control, motion control, drive control, and vision applications. PACs are programmed using traditional process automation programming languages (IEC-61131) and sometimes languages such as C and C++ to support more advanced controls.
|
|
Data Gateway
|
Data Gateway is a device that supports the communication and exchange of data between different systems, networks, or protocols within the ICS. Different types of data gateways are used to perform various functions, including:
* Protocol Translation: Enable communication to devices that support different or incompatible protocols by translating information from one protocol to another.
* Media Converter: Convert data across different Layer 1 and 2 network protocols / mediums, for example, converting from Serial to Ethernet.
* Data Aggregation: Collect and combine data from different devices into one consistent format and protocol interface.
* Data Mirroring: Create a real-time, exact copy of data streams from devices to a separate destination for redundancy, monitoring, or backup purposes.
Data gateways are often critical to the forwarding/transmission of critical control or monitoring data within the ICS. Further, these devices often have remote various network services that are used to communicate across different zones or networks.
These assets may focus on a single function listed below or combinations of these functions to best fit the industry use-case.
|
|
Safety Controller
|
Safety controllers are typically a type of field device used to perform the safety critical function. Safety controllers often support the deployment of custom programs/logic, similar to a PLC, but can also be tailored for sector specific functions/applications. The safety controllers typically utilize redundant hardware and processors to ensure they operate reliably if a component fails.
|
|
Intelligent Electronic Device (IED)
|
An Intelligent Electronic Device (IED) is a type of specialized field device that is designed to perform specific operational functions, frequently for protection, monitoring, or control within the electric sector. IEDs are typically used to both acquire telemetry and execute tailored control algorithms/actions based on customizable parameters/settings. An IED is usually implemented as a dedicated embedded device and supports various network automation protocols to communicate with RTUs and Control Servers.
|
|
Distributed Control System (DCS) Controller
|
A Distributed Control System (DCS) Controller is a microprocessor unit that is used to manage automation processes. DCS Controllers are often found in plants (chemical, manufacturing, oil and gas, etc.) where large scale continuous automation processes are required. A DCS Controller typically operates as part of a larger networked system with other DCS Controllers where each DCS Controller manages an individual part of a continuous process. In addition to these other controllers, DCS Controllers operate along side multiple other system components including system software, operator stations, and other embedded field controllers. The distributed nature of DCS Controllers provides scalability, redundancy, and improved process reliability. DCS Controllers are programmed using traditional process automation programming languages (IEC-61131).
|
|
Application Server
|
Application servers are used across many different sectors to host various diverse software applications necessary to supporting the ICS. Example functions can include data analytics and reporting, alarm management, and the management/coordination of different control servers. The application server typically runs on a modern server operating system (e.g., MS Windows Server).
|
|
Programmable Logic Controller (PLC)
|
A Programmable Logic Controller (PLC) is an embedded programmable control device. PLCs typically utilize a modular architecture with separate modules used to support its processing capabilities, communication mediums, and I/O interfaces. PLCs allow for the deployment of customized programs/logic to control or monitor an operational process. This logic is defined using industry specific programming languages, such as IEC 61131 (Citation: IEC February 2013), which define the set of tasks and program organizational units (POUs) included in the device’s programs. PLCs also typically have distinct operating modes (e.g., Remote, Run, Program, Stop) which are used to determine when the device can be programmed or whether it should execute the custom logic.
|
|
Firewall
|
A gateway that limits access between networks in accordance with local security policy.
In ICS networks, firewalls can exist in multiple locations in the network architecture and serve a variety of purposes. The first, and often the most important, is the firewall segmenting the ICS network from the business network. This firewall acts as the primary network boundary point that controls the ingress/egress of network traffic between the ICS and business networks. This firewall may also be a single device connected to multiple network segments, where the firewall defines individual zones for the different network segments and can control access to the zones and between the zones. This can limit the ability of an adversary to traverse a network.
|
|
Switch
|
A switch is a network device that connects endpoints (e.g., workstations, servers, HMIs, PLCs, etc.) so that they can communicate and share data and resources. Switches may operate at either Layer 2 or Layer 3 of the OSI Model and intelligently forward packets across the network based on the specified address (Media Access Control (MAC) address for Layer 2 and Internet Protocol (IP) address for Layer 3). Switches are typically used to define network segments and connect the devices within a particular level of the Purdue Model.
|
|
Routers
|
A computer that is a gateway between two networks at OSI layer 3 and that relays and directs data packets through that inter-network. The most common form of router operates on IP packets.(Citation: IETF RFC4949 2007)
|
|
Data Historian
|
Data historians, or historian, are systems used to collect and store data, including telemetry, events, alerts, and alarms about the operational process and supporting devices. The historian typically utilizes a database to store this data, and commonly provide tools and interfaces to support the analysis of the data. Data historians are often used to support various engineering or business analysis functions and therefore commonly needs access from the corporate network. Data historians often work in a hierarchical paradigm where lower/site level historians collect and store data which is then aggregated into a site/plant level historian. Therefore, data historians often have remote services that can be accessed externally from the ICS network. Many data historian vendors have designed their software to securely transfer data between the ICS and business networks instead of requiring business systems to access the data historian in the ICS network directly.
|
|
Control Server
|
Control servers are typically a software platform that runs on a modern server operating system (e.g., MS Windows Server). The server typically uses one or more automation protocols (e.g., Modbus, DNP3) to communicate with the various low-level control devices such as Remote Terminal Units (RTUs) and Programmable Logic Controllers (PLCs). The control server also usually provides an interface/network service to connect with an HMI.
|
|
Workstation
|
Workstations are devices used by human operators or engineers to perform various configuration, programming, maintenance, diagnostic, or operational tasks. Workstations typically utilize standard desktop or laptop hardware and operating systems (e.g., MS Windows), but run dedicated control system applications or diagnostic/management software to support interfacing with the control servers or field devices. Some workstations have a fixed location within the network architecture, while others are transient devices that are directly connected to various field devices to support local management activities.
|
|
Windows Registry Key Deletion
|
The removal of a registry key within the Windows operating system.
*Data Collection Measures:*
- Windows Event Logs
- Event ID 4658 - Registry Key Handle Closed: Captures when a handle to a registry key is closed, which may indicate deletion.
- Event ID 4660 - Object Deleted: Logs when a registry key is deleted.
- Sysmon (System Monitor) for Windows
- Sysmon Event ID 12 - Registry Key Deleted: Logs when a registry key is removed.
- Sysmon Event ID 13 - Registry Value Deleted: Captures removal of specific registry values.
- Endpoint Detection and Response (EDR) Solutions
- Monitor registry deletions for suspicious behavior.
|
|
Network Connection Creation
|
The initial establishment of a network session, where a system or process initiates a connection to a local or remote endpoint. This typically involves capturing socket information (source/destination IP, ports, protocol) and tracking session metadata. Monitoring these events helps detect lateral movement, exfiltration, and command-and-control (C2) activities.
*Data Collection Measures:*
- Windows:
- Event ID 5156 – Filtering Platform Connection - Logs network connections permitted by Windows Filtering Platform (WFP).
- Sysmon Event ID 3 – Network Connection Initiated - Captures process, source/destination IP, ports, and parent process.
- Linux/macOS:
- Netfilter (iptables), nftables logs - Tracks incoming and outgoing network connections.
- AuditD (`connect` syscall) - Logs TCP, UDP, and ICMP connections.
- Zeek (`conn.log`) - Captures protocol, duration, and bytes transferred.
- Cloud & Network Infrastructure:
- AWS VPC Flow Logs / Azure NSG Flow Logs - Logs IP traffic at the network level in cloud environments.
- Zeek (conn.log) or Suricata (network events) - Captures packet metadata for detection and correlation.
- Endpoint Detection & Response (EDR):
- Detect anomalous network activity such as new C2 connections or data exfiltration attempts.
|
|
File Access
|
To events where a file is opened or accessed, making its contents available to the requester. This includes reading, executing, or interacting with files by authorized or unauthorized entities. Examples include logging file access events (e.g., Windows Event ID 4663), monitoring file reads, and detecting unusual file access patterns. Examples:
- File Read Operations: A user opens a sensitive document (e.g., financial_report.xlsx) on a shared drive.
- File Execution: A script or executable file is accessed and executed (e.g., malware.exe is run from a temporary directory).
- Unauthorized File Access: An unauthorized user attempts to access a protected configuration file (e.g., `/etc/passwd` on Linux or `System32` files on Windows).
- File Access Patterns: Bulk access to multiple files in a short time (e.g., mass access to documents on a file server).
- File Access via Network: Files on a network share are accessed remotely (e.g., logs of SMB file access).
|
|
File Creation
|
A new file is created on a system or network storage. This action often signifies an operation such as saving a document, writing data, or deploying a file. Logging these events helps identify legitimate or potentially malicious file creation activities. Examples include logging file creation events (e.g., Sysmon Event ID 11 or Linux auditd logs).
|
|
Network Traffic Content
|
The full packet capture (PCAP) or session data that logs both protocol headers and payload content. This allows analysts to inspect command and control (C2) traffic, exfiltration, and other suspicious activity within network communications. Unlike metadata-based logs, full content analysis enables deeper protocol inspection, payload decoding, and forensic investigations.
*Data Collection Measures:*
- Network Packet Capture (Full Content Logging)
- Wireshark / tcpdump / tshark
- Full packet captures (PCAP files) for manual analysis or IDS correlation. `tcpdump -i eth0 -w capture.pcap`
- Zeek (formerly Bro)
- Extracts protocol headers and payload details into structured logs. `echo "redef Log::default_store = Log::ASCII;" > local.zeek | zeek -Cr capture.pcap local.zeek`
- Suricata / Snort (IDS/IPS with PCAP Logging)
- Deep packet inspection (DPI) with signature-based and behavioral analysis. `suricata -c /etc/suricata/suricata.yaml -i eth0 -l /var/log/suricata`
- Host-Based Collection
- Sysmon Event ID 22 – DNS Query Logging, Captures DNS requests made by processes, useful for detecting C2 domains.
- Sysmon Event ID 3 – Network Connection Initiated, Logs process-to-network connection relationships.
- AuditD (Linux) – syscall=connect, Monitors outbound network requests from processes. `auditctl -a always,exit -F arch=b64 -S connect -k network_activity`
- Cloud & SaaS Traffic Collection
- AWS VPC Flow Logs / Azure NSG Flow Logs / Google VPC Flow Logs, Captures metadata about inbound/outbound network traffic.
- Cloud IDS (AWS GuardDuty, Azure Sentinel, Google Chronicle), Detects malicious activity in cloud environments by analyzing network traffic patterns.
|
|
Logon Session Metadata
|
Contextual data about a logon session, such as username, logon type, access tokens (security context, user SIDs, logon identifiers, and logon SID), and any activity associated within it
|
|
Process Creation
|
Refers to the event in which a new process (executable) is initialized by an operating system. This can involve parent-child process relationships, process arguments, and environmental variables. Monitoring process creation is crucial for detecting malicious behaviors, such as execution of unauthorized binaries, scripting abuse, or privilege escalation attempts..
|
|
Drive Creation
|
The activity of assigning a new drive letter or creating a mount point for a data storage device, such as a USB, network share, or external hard drive, enabling access to its content on a host system. Examples:
- USB Drive Insertion: A USB drive is plugged in and automatically assigned the letter `E:\` on a Windows machine.
- Network Drive Mapping: A network share `\\server\share` is mapped to the drive `Z:\`.
- Virtual Drive Creation: A virtual disk is mounted on `/mnt/virtualdrive` using an ISO image or a virtual hard disk (VHD).
- Cloud Storage Mounting: Google Drive is mounted as `G:\` on a Windows machine using a cloud sync tool.
- External Storage Integration: An external HDD or SSD is connected and assigned `/mnt/external` on a Linux system..
|
|
Process/Event Alarm
|
This includes a list of any process alarms or alerts produced to indicate unusual or concerning activity within the operational process (e.g., increased temperature/pressure)
|
|
Drive Modification
|
The alteration of a drive letter, mount point, or other attributes of a data storage device, which could involve reassignment, renaming, permissions changes, or other modifications. Examples:
- Drive Letter Reassignment: A USB drive previously assigned `E:\` is reassigned to `D:\` on a Windows machine.
- Mount Point Change: On a Linux system, a mounted storage device at `/mnt/external` is moved to `/mnt/storage`.
- Drive Permission Changes: A shared drive's permissions are modified to allow write access for unauthorized users or processes.
- Renaming of a Drive: A network drive labeled "HR_Share" is renamed to "Shared_Resources."
- Modification of Cloud-Integrated Drives: A cloud storage mount such as Google Drive is modified to sync only specific folders.
This data component can be collected through the following measures:
Windows Event Logs
- Relevant Events:
- Event ID 98: Indicates changes to a volume (e.g., drive letter reassignment).
- Event ID 1006: Logs permission modifications or changes to removable storage.
- Configuration: Enable "Storage Operational Logs" in the Event Viewer:
`Applications and Services Logs > Microsoft > Windows > Storage-Tiering > Operational`
Linux System Logs
- Auditd Configuration: Add audit rules to track changes to mounted drives: `auditctl -w /mnt/ -p w -k drive_modification`
- Command-Line Monitoring: Use `dmesg` or `journalctl` to observe drive modifications.
macOS System Logs
- Unified Logs: Collect mount or drive modification events: `log show --info | grep "Volume modified"`
- Command-Line Monitoring: Use `diskutil` to track changes:
Endpoint Detection and Response (EDR) Tools
- Configure policies in EDR solutions to monitor and log changes to drive configurations or attributes.
SIEM Tools
- Aggregate logs from multiple systems into a centralized platform like Splunk to correlate events and alert on suspicious drive modification activities.
|
|
Service Creation
|
The registration of a new service or daemon on an operating system.
*Data Collection Measures:*
- Windows Event Logs
- Event ID 4697 - Captures the creation of a new Windows service.
- Event ID 7045 - Captures services installed by administrators or adversaries.
- Event ID 7034 - Could indicate malicious service modification or exploitation.
- Sysmon Logs
- Sysmon Event ID 1 - Process Creation (captures service executables).
- Sysmon Event ID 4 - Service state changes (detects service installation).
- Sysmon Event ID 13 - Registry modifications (captures service persistence changes).
- PowerShell Logging
- Monitor `New-Service` and `Set-Service` PowerShell cmdlets in Event ID 4104 (Script Block Logging).
- Linux/macOS Collection Methods
- AuditD & Syslog Daemon Logs (`/var/log/syslog`, `/var/log/messages`, `/var/log/daemon.log`)
- AuditD Rules:
- `auditctl -w /etc/systemd/system -p wa -k service_creation`
- Detects changes to `systemd` service configurations.
- Systemd Journals (`journalctl -u `)
- Captures newly created systemd services.
- LaunchDaemons & LaunchAgents (macOS)
- Monitor `/Library/LaunchDaemons/` and `/Library/LaunchAgents/` for new plist files.
|
|
Process Termination
|
The exit or termination of a running process on a system. This can occur due to normal operations, user-initiated commands, or malicious actions such as process termination by malware to disable security controls.
|
|
File Metadata
|
contextual information about a file, including attributes such as the file's name, size, type, content (e.g., signatures, headers, media), user/owner, permissions, timestamps, and other related properties. File metadata provides insights into a file's characteristics and can be used to detect malicious activity, unauthorized modifications, or other anomalies. Examples:
- File Ownership and Permissions: Checking the owner and permissions of a critical configuration file like /etc/passwd on Linux or C:\Windows\System32\config\SAM on Windows.
- Timestamps: Analyzing the creation, modification, and access timestamps of a file.
- File Content and Signatures: Extracting the headers of an executable file to verify its signature or detect packing/obfuscation.
- File Attributes: Analyzing attributes like hidden, system, or read-only flags in Windows.
- File Hashes: Generating MD5, SHA-1, or SHA-256 hashes of files to compare against threat intelligence feeds.
- File Location: Monitoring files located in unusual directories or paths, such as temporary or user folders.
|
|
Service Modification
|
Changes made to an existing service or daemon, such as modifying the service name, start type, execution parameters, or security configurations.
|
|
Command Execution
|
Command Execution involves monitoring and capturing the execution of textual commands (including shell commands, cmdlets, and scripts) within an operating system or application. These commands may include arguments or parameters and are typically executed through interpreters such as `cmd.exe`, `bash`, `zsh`, `PowerShell`, or programmatic execution. Examples:
- Windows Command Prompt
- dir – Lists directory contents.
- net user – Queries or manipulates user accounts.
- tasklist – Lists running processes.
- PowerShell
- Get-Process – Retrieves processes running on a system.
- Set-ExecutionPolicy – Changes PowerShell script execution policies.
- Invoke-WebRequest – Downloads remote resources.
- Linux Shell
- ls – Lists files in a directory.
- cat /etc/passwd – Reads the user accounts file.
- curl http://malicious-site.com – Retrieves content from a malicious URL.
- Container Environments
- docker exec – Executes a command inside a running container.
- kubectl exec – Runs commands in Kubernetes pods.
- macOS Terminal
- open – Opens files or URLs.
- dscl . -list /Users – Lists all users on the system.
- osascript -e – Executes AppleScript commands.
|
|
Service Metadata
|
Contextual data about a service/daemon, which may include information such as name, service executable, start type, etc.
|
|
Scheduled Job Metadata
|
Contextual data about a scheduled job, which may include information such as name, timing, command(s), etc.
|
|
File Modification
|
Changes made to a file, including updates to its contents, metadata, access permissions, or attributes. These modifications may indicate legitimate activity (e.g., software updates) or unauthorized changes (e.g., tampering, ransomware, or adversarial modifications). Examples:
- Content Modifications: Changes to the content of a configuration file, such as modifying `/etc/ssh/sshd_config` on Linux or `C:\Windows\System32\drivers\etc\hosts` on Windows.
- Permission Changes: Altering file permissions to allow broader access, such as changing a file from `644` to `777` on Linux or modifying NTFS permissions on Windows.
- Attribute Modifications: Changing a file's attributes to hidden, read-only, or system on Windows.
- Timestamp Manipulation: Adjusting a file's creation or modification timestamp using tools like `touch` in Linux or timestomping tools on Windows.
- Software or System File Changes: Modifying system files such as `boot.ini`, kernel modules, or application binaries.
|
|
Software
|
This includes sources of current and expected software or application programs deployed to a device, along with information on the version and patch level for vendor products, full source code for any application programs, and unique identifiers (e.g., hashes, signatures).
|
|
Process History/Live Data
|
This includes any data stores that maintain historical or real-time events and telemetry recorded from various sensors or devices
|
|
OS API Execution
|
Calls made by a process to operating system-provided Application Programming Interfaces (APIs). These calls are essential for interacting with system resources such as memory, files, and hardware, or for performing system-level tasks. Monitoring these calls can provide insight into a process's intent, especially if the process is malicious.
|
|
Application Log Content
|
Application Log Content refers to logs generated by applications or services, providing a record of their activity. These logs may include metrics, errors, performance data, and operational alerts from web, mail, or other applications. These logs are vital for monitoring application behavior and detecting malicious activities or anomalies. Examples:
- Web Application Logs: These logs include information about requests, responses, errors, and security events (e.g., unauthorized access attempts).
- Email Application Logs: Logs contain metadata about emails sent, received, or blocked (e.g., sender/receiver addresses, message IDs).
- SaaS Application Logs: Activity logs include user logins, configuration changes, and access to sensitive resources.
- Cloud Application Logs: Logs detail control plane activities, including API calls, instance modifications, and network changes.
- System/Application Monitoring Logs: Logs provide insights into application performance, errors, and anomalies.
|
|
Logon Session Creation
|
The successful establishment of a new user session following a successful authentication attempt. This typically signifies that a user has provided valid credentials or authentication tokens, and the system has initiated a session associated with that user account. This data is crucial for tracking authentication events and identifying potential unauthorized access. Examples:
- Windows Systems
- Event ID: 4624
- Logon Type: 2 (Interactive) or 10 (Remote Interactive via RDP).
- Account Name: JohnDoe
- Source Network Address: 192.168.1.100
- Authentication Package: NTLM
- Linux Systems
- /var/log/utmp or /var/log/wtmp:
- Log format: login user [tty] from [source_ip]
- User: jane
- IP: 10.0.0.5
- Timestamp: 2024-12-28 08:30:00
- macOS Systems
- /var/log/asl.log or unified logging framework:
- Log: com.apple.securityd: Authentication succeeded for user 'admin'
- Cloud Environments
- Azure Sign-In Logs:
- Activity: Sign-in successful
- Client App: Browser
- Location: Unknown (Country: X)
- Google Workspace
- Activity: Login
- Event Type: successful_login
- Source IP: 203.0.113.55
|
|
Device Alarm
|
This includes alarms associated with unexpected device functions, such as shutdowns, restarts, failures, or configuration changes
|
|
Script Execution
|
The execution of a text file that contains code via the interpreter.
|
|
Network Traffic Flow
|
Summarized network packet data that captures session-level details such as source/destination IPs, ports, protocol types, timestamps, and data volume, without storing full packet payloads. This is commonly used for traffic analysis, anomaly detection, and network performance monitoring.
|
|
User Account Authentication
|
An attempt (successful and failed login attempts) by a user, service, or application to gain access to a network, system, or cloud-based resource. This typically involves credentials such as passwords, tokens, multi-factor authentication (MFA), or biometric validation.
|
|
Asset Inventory
|
This includes sources of current and expected devices on the network, including the manufacturer, model, and necessary identifiers (e.g., IP and hardware addresses)
|
|
Firmware Modification
|
Changes made to firmware, which may include its settings, configurations, or underlying data. This can encompass alterations to the Master Boot Record (MBR), Volume Boot Record (VBR), or other firmware components critical to system boot and functionality. Such modifications are often indicators of adversary activity, including malware persistence and system compromise. Examples:
- Changes to Master Boot Record (MBR): Modifying the MBR to load malicious code during the boot process.
- Changes to Volume Boot Record (VBR): Altering the VBR to redirect boot processes to malicious locations.
- Firmware Configuration Changes: Modifying BIOS/UEFI settings such as disabling Secure Boot.
- Firmware Image Tampering: Updating firmware with a malicious or unauthorized image.
- Logs or Errors Indicating Firmware Changes: Logs showing unauthorized firmware updates or checksum mismatches.
This data component can be collected through the following measures:
- BIOS/UEFI Logs: Enable and monitor BIOS/UEFI logs to capture settings changes or firmware updates.
- Firmware Integrity Monitoring: Use tools or firmware security features to detect changes to firmware components.
- Endpoint Detection and Response (EDR) Solutions: Many EDR platforms can detect abnormal firmware activity, such as changes to MBR/VBR or unauthorized firmware updates.
- File System Monitoring: Monitor changes to MBR/VBR-related files using tools like Sysmon or auditd.
- Windows Example (Sysmon): Monitor Event ID 7 (Raw disk access).
- Linux Example (auditd): `auditctl -w /dev/sda -p wa -k firmware_modification`
- Network Traffic Analysis: Capture firmware updates downloaded over the network, particularly from untrusted sources. Use network monitoring tools like Zeek or Wireshark to analyze firmware-related traffic.
- Secure Boot Logs: Collect and analyze Secure Boot logs for signs of tampering or unauthorized configurations. Example: Use PowerShell to retrieve Secure Boot settings on Windows: `Confirm-SecureBootUEFI`
- Vendor-Specific Firmware Tools: Many hardware vendors provide tools for firmware integrity checks.Examples:
- Intel Platform Firmware Resilience (PFR).
- Lenovo UEFI diagnostics.
|
|
Module Load
|
When a process or program dynamically attaches a shared library, module, or plugin into its memory space. This action is typically performed to extend the functionality of an application, access shared system resources, or interact with kernel-mode components.
|
|
Windows Registry Key Modification
|
Changes made to an existing registry key or its values. These modifications can include altering permissions, modifying stored data, or updating configuration settings.
*Data Collection Measures:*
- Windows Event Logs
- Event ID 4657 - Registry Value Modified: Logs changes to registry values, including modifications to startup entries, security settings, or system configurations.
- Sysmon (System Monitor) for Windows
- Sysmon Event ID 13 - Registry Value Set: Captures changes to specific registry values.
- Sysmon Event ID 14 - Registry Key & Value Renamed: Logs renaming of registry keys, which may indicate evasion attempts.
- Endpoint Detection and Response (EDR) Solutions
- Monitor registry modifications for suspicious behavior.
|
|
File Deletion
|
Refers to events where files are removed from a system or storage device. These events can indicate legitimate housekeeping activities or malicious actions such as attackers attempting to cover their tracks. Monitoring file deletions helps organizations identify unauthorized or suspicious activities.
|
|
Process Metadata
|
Contextual data about a running process, which may include information such as environment variables, image name, user/owner, etc.
|
|
Scheduled Job Creation
|
The establishment of a task or job that will execute at a predefined time or based on specific triggers.
|
|
Network Share Access
|
Opening a network share, which makes the contents available to the requestor (ex: Windows EID 5140 or 5145)
|
|
Scheduled Job Modification
|
Changes made to an existing scheduled job, including modifications to its execution parameters, command payload, or execution timing.
|
|
Detection of Rootkit
|
Detection of Rootkit
|
|
Detection of Block Reporting Message
|
Detection of Block Reporting Message
|
|
Detection of Masquerading
|
Detection of Masquerading
|
|
Detection of Denial of Service
|
Detection of Denial of Service
|
|
Detection of Project File Infection
|
Detection of Project File Infection
|
|
Detection of System Firmware
|
Detection of System Firmware
|
|
Detection of Exploitation for Privilege Escalation
|
Detection of Exploitation for Privilege Escalation
|
|
Detection of Alarm Suppression
|
Detection of Alarm Suppression
|
|
Detection of Denial of View
|
Detection of Denial of View
|
|
Detection of Device Restart/Shutdown
|
Detection of Device Restart/Shutdown
|
|
Detection of Denial of Control
|
Detection of Denial of Control
|
|
Detection of Theft of Operational Information
|
Detection of Theft of Operational Information
|
|
Detection of Block Command Message
|
Detection of Block Command Message
|
|
Detection of Program Download All
|
Detection of Program Download All
|
|
Detection of Siemens Project File Format Infection
|
Detection of Siemens Project File Format Infection
|
|
Detection of Change Credential
|
Detection of Change Credential
|
|
Detection of Commonly Used Port
|
Detection of Commonly Used Port
|
|
Detection of Loss of Control
|
Detection of Loss of Control
|
|
Detection of Data from Local System
|
Detection of Data from Local System
|
|
Detection of Screen Capture
|
Detection of Screen Capture
|
|
Detection of Brute Force I/O
|
Detection of Brute Force I/O
|
|
Detection of Network Connection Enumeration
|
Detection of Network Connection Enumeration
|
|
Detection of Automated Collection
|
Detection of Automated Collection
|
|
Detection of Modify Parameter
|
Detection of Modify Parameter
|
|
Detection of Manipulation of View
|
Detection of Manipulation of View
|
|
Detection of Block Serial COM
|
Detection of Block Serial COM
|
|
Detection of System Binary Proxy Execution
|
Detection of System Binary Proxy Execution
|
|
Detection of Block Wi-Fi
|
Detection of Block Wi-Fi
|
|
Detection of Point & Tag Identification
|
Detection of Point & Tag Identification
|
|
Detection of Multicast Discovery
|
Detection of Multicast Discovery
|
|
Detection of Supply Chain Compromise
|
Detection of Supply Chain Compromise
|
|
Detection of Native API
|
Detection of Native API
|
|
Detection of Monitor Process State
|
Detection of Monitor Process State
|
|
Detection of Lateral Tool Transfer
|
Detection of Lateral Tool Transfer
|
|
Detection of Remote System Information Discovery
|
Detection of Remote System Information Discovery
|
|
Detection of Exploitation of Remote Services
|
Detection of Exploitation of Remote Services
|
|
Detection of Port Scan
|
Detection of Port Scan
|
|
Detection of Activate Firmware Update Mode
|
Detection of Activate Firmware Update Mode
|
|
Detection of Block Operational Technology Message
|
Detection of Block Operational Technology Message
|
|
Detection of Program Upload
|
Detection of Program Upload
|
|
Detection of Program Download
|
Detection of Program Download
|
|
Detection of Standard Application Layer Protocol
|
Detection of Standard Application Layer Protocol
|
|
Detection of Firmware Modification
|
Detection of Firmware Modification
|
|
Detection of Remote Services
|
Detection of Remote Services
|
|
Detection of Wireless Compromise
|
Detection of Wireless Compromise
|
|
Detection of Modify Program
|
Detection of Modify Program
|
|
Detection of Modify Alarm Settings
|
Detection of Modify Alarm Settings
|
|
Detection of Graphical User Interface
|
Detection of Graphical User Interface
|
|
Detection of Connection Proxy
|
Detection of Connection Proxy
|
|
Detection of Drive-by Compromise
|
Detection of Drive-by Compromise
|
|
Detection of Transient Cyber Asset
|
Detection of Transient Cyber Asset
|
|
Detection of Autorun Image
|
Detection of Autorun Image
|
|
Detection of Exploitation for Evasion
|
Detection of Exploitation for Evasion
|
|
Detection of Rogue Master
|
Detection of Rogue Master
|
|
Detection of Hooking
|
Detection of Hooking
|
|
Detection of Data from Information Repositories
|
Detection of Data from Information Repositories
|
|
Detection of Loss of View
|
Detection of Loss of View
|
|
Detection of Exploit Public-Facing Application
|
Detection of Exploit Public-Facing Application
|
|
Detection of Manipulate I/O Image
|
Detection of Manipulate I/O Image
|
|
Detection of Manipulation of Control
|
Detection of Manipulation of Control
|
|
Detection of Default Credentials
|
Detection of Default Credentials
|
|
Detection of Service Stop
|
Detection of Service Stop
|
|
Detection of Adversary-in-the-Middle
|
Detection of Adversary-in-the-Middle
|
|
Detection of Spearphishing Attachment
|
Detection of Spearphishing Attachment
|
|
Detection of Wireless Sniffing
|
Detection of Wireless Sniffing
|
|
Detection of Command-Line Interface
|
Detection of Command-Line Interface
|
|
Detection of Spoof Reporting Message
|
Detection of Spoof Reporting Message
|
|
Detection of Online Edit
|
Detection of Online Edit
|
|
Detection of Loss of Protection
|
Detection of Loss of Protection
|
|
Detection of Broadcast Discovery
|
Detection of Broadcast Discovery
|
|
Detection of Loss of Productivity and Revenue
|
Detection of Loss of Productivity and Revenue
|
|
Detection of Block Communications
|
Detection of Block Communications
|
|
Detection of Internet Accessible Device
|
Detection of Internet Accessible Device
|
|
Detection of I/O Image
|
Detection of I/O Image
|
|
Detection of Replication Through Removable Media
|
Detection of Replication Through Removable Media
|
|
Detection of Unauthorized Command Message
|
Detection of Unauthorized Command Message
|
|
Detection of Loss of Availability
|
Detection of Loss of Availability
|
|
Detection of Hardcoded Credentials
|
Detection of Hardcoded Credentials
|
|
Detection of Module Firmware
|
Detection of Module Firmware
|
|
Detection of Detect Operating Mode
|
Detection of Detect Operating Mode
|
|
Detection of Indicator Removal on Host
|
Detection of Indicator Removal on Host
|
|
Detection of Program Append
|
Detection of Program Append
|
|
Detection of External Remote Services
|
Detection of External Remote Services
|
|
Detection of User Execution
|
Detection of User Execution
|
|
Detection of Remote System Discovery
|
Detection of Remote System Discovery
|
|
Detection of Data Destruction
|
Detection of Data Destruction
|
|
Detection of Execution through API
|
Detection of Execution through API
|
|
Detection of Unauthorized Message
|
Detection of Unauthorized Message
|
|
Detection of Network Sniffing
|
Detection of Network Sniffing
|
|
Detection of Damage to Property
|
Detection of Damage to Property
|
|
Detection of Scripting
|
Detection of Scripting
|
|
Detection of Loss of Safety
|
Detection of Loss of Safety
|
|
Detection of Change Operating Mode
|
Detection of Change Operating Mode
|
|
Detection of Modify Controller Tasking
|
Detection of Modify Controller Tasking
|
|
Detection of Block Ethernet
|
Detection of Block Ethernet
|
|
Detection of Insecure Credentials
|
Detection of Insecure Credentials
|
|
Detection of Valid Accounts
|
Detection of Valid Accounts
|
1.1 References
1.2 Identified Requirements
1.3 Related Regulations
2. Identified Requirements
Requirements
| Source |
Requirement |
3. Related Regulations
Regulations
| Source |
Regulation |
Linked Issues
- MITREATTACK -
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/
Terms of Use
The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
"© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."
MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.
ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
See our FAQ for more information on how to use and represent the ATT&CK name.
|