Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network. Internet-facing software may be user applications, underlying networking implementations, an assets operating system, weak defenses, etc. Targets of this technique may be intentionally exposed for the purpose of remote management and visibility. An adversary may seek to target public-facing applications as they may provide direct access into an ICS environment or the ability to move into the ICS network. Publicly exposed applications may be found through online tools that scan the internet for open ports and services. Version numbers for the exposed application may provide adversaries an ability to target specific known vulnerabilities. Exposed control protocol or remote access ports found in Commonly Used Port may be of interest by adversaries.
Perform regular software updates to mitigate exploitation risk. Software updates may need to be scheduled around operational down times.
M0916Vulnerability ScanningVulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them.
M0950Exploit ProtectionUse capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring.
M0926Privileged Account ManagementManage the creation, modification, use, and permissions associated to privileged accounts, including SYSTEM and root.
M0948Application Isolation and SandboxingRestrict the execution of code to a virtual environment on or in-transit to an endpoint system.
M0930Network SegmentationArchitect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. Restrict network access to only required systems and services. In addition, prevent systems from other networks or business functions (e.g., enterprise) from accessing critical process control systems. For example, in IEC 62443, systems within the same secure level should be grouped into a zone, and access to that zone is restricted by a conduit, or mechanism to restrict data flows between zones by segmenting the network. (Citation: IEC February 2019) (Citation: IEC August 2013)
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.