Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M0930
MITRE ATT&CK Mitigation

M0930: Network Segmentation

ShareXLinkedInRedditHN

Architect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. Restrict network access to only required systems and services. In addition, prevent systems from other networks or business functions (e.g., enterprise) from accessing critical process control systems. For example, in IEC 62443, systems within the same secure level should be grouped into a zone, and access to that zone is restricted by a conduit, or mechanism to restrict data flows between zones by segmenting the network. (Citation: IEC February 2019) (Citation: IEC August 2013)

▪Techniques addressed (39)

T0869Standard Application Layer ProtocolT1693.002Module FirmwareT0838Modify Alarm SettingsT1693Modify FirmwareT0822External Remote ServicesT0883Internet Accessible DeviceT0842Network SniffingT1692.002Reporting MessageT0830Adversary-in-the-MiddleT0846.003Multicast DiscoveryT1695.003Wi-FiT0816Device Restart/ShutdownT0846.001Port ScanT1695.001Serial COMT0886Remote ServicesT0843.002Online EditT0806Brute Force I/OT0848Rogue MasterT0866Exploitation of Remote ServicesT0845Program UploadT0864Transient Cyber AssetT0846.002Broadcast DiscoveryT0843Program DownloadT0843.001Download AllT0881Service StopT0802Automated CollectionT1695.002EthernetT1693.001System FirmwareT1695Block CommunicationsT0878Alarm SuppressionT0885Commonly Used PortT0861Point & Tag IdentificationT0843.003Program AppendT1692Unauthorized MessageT0858Change Operating ModeT0868Detect Operating ModeT0800Activate Firmware Update ModeT0819Exploit Public-Facing ApplicationT1692.001Command Message

▪Reference

M0930on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.