Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse. A common goal for post-compromise exploitation of remote services is for initial access into and lateral movement throughout the ICS environment to enable access to targeted systems. (Citation: Enterprise ATT&CK) ICS asset owners and operators have been affected by ransomware (or disruptive malware masquerading as ransomware) migrating from enterprise IT to ICS environments: WannaCry, NotPetya, and BadRabbit. In each of these cases, self-propagating (wormable) malware initially infected IT networks, but through exploit (particularly the SMBv1-targeting MS17-010 vulnerability) spread to industrial networks, producing significant impacts. (Citation: Joe Slowik April 2019)
Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them.
M0942Disable or Remove Feature or ProgramRemove or deny access to unnecessary and potentially vulnerable software to prevent abuse by adversaries.
M0950Exploit ProtectionUse capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring.
M0919Threat Intelligence ProgramA threat intelligence program helps an organization generate their own threat intelligence information and track trends to inform defensive priorities to mitigate risk.
M0930Network SegmentationArchitect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. Restrict network access to only required systems and services. In addition, prevent systems from other networks or business functions (e.g., enterprise) from accessing critical process control systems. For example, in IEC 62443, systems within the same secure level should be grouped into a zone, and access to that zone is restricted by a conduit, or mechanism to restrict data flows between zones by segmenting the network. (Citation: IEC February 2019) (Citation: IEC August 2013)
M0948Application Isolation and SandboxingRestrict the execution of code to a virtual environment on or in-transit to an endpoint system.
M0926Privileged Account ManagementManage the creation, modification, use, and permissions associated to privileged accounts, including SYSTEM and root.
M0951Update SoftwarePerform regular software updates to mitigate exploitation risk. Software updates may need to be scheduled around operational down times.
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.