OT

Teaching Operational Technologies

Core Frameworks โ€” Student Guide

โ† Course Navigation
Threat Intelligence ยท Knowledge Base

MITRE ATT&CK for ICS

A student's walk-through of the knowledge base that catalogs how real adversaries have actually attacked control systems โ€” its tactics, its case studies, and how it's used defensively without ever touching attack tooling.

โ† Back to Course Navigation

Quick Facts

Type
Threat-intelligence knowledge base
Maintained By
MITRE Corporation
Structure
12 tactics, dozens of techniques
Companion To
Enterprise ATT&CK (the IT-side matrix)
Built From
Documented real-world ICS incidents
Primary Use
Threat intel, detection engineering, red/blue exercises
01

Foundations

02

How to Use This Guide

  1. 1

    Skim the Quick Facts panel first. The single most important fact there is the first one โ€” this is a knowledge base, not a standard. Everything else follows from that.

  2. 2

    Read Section 03 before the matrix itself. Knowing how ATT&CK for ICS differs from IEC 62443, SP 800-82, and CIP-008 makes the tactic list in Section 04 much easier to place.

  3. 3

    Work through Section 04's three phase cards in order โ€” Access & Foothold โ†’ Situational Awareness โ†’ Physical Impact. They group the 12 tactics into the same "IT compromise leads to OT impact" story your students already know from Lessons 6โ€“7.

  4. 4

    Section 05 is where the matrix becomes concrete. Five real incidents, each mapped to the tactics they demonstrate โ€” this is the material built for case-study teaching under the course's defensive-scope safeguard.

  5. 5

    If you're prepping to teach, start at Section 08. The four exercises there are built to reuse the case studies in Section 05 without requiring any attack tooling.

03

Positioning: ATT&CK for ICS vs. the Other Core Frameworks

IEC 62443 and NIST SP 800-82 tell you how to design and manage a secure system. NERC CIP-008 tells you what you must legally report once something goes wrong. ATT&CK for ICS answers a third, different question: what has actually been done to systems like this, and how would you know?

AttributeMITRE ATT&CK for ICSIEC 62443 / SP 800-82 / CIP-008
TypeThreat-intelligence knowledge base, descriptiveDesign standard, risk-management guide, or compliance mandate โ€” all prescriptive
Origin / AuthorityMITRE Corporation, a federally funded R&D centerISA/IEC standards body, NIST (U.S. federal), NERC (the ERO, under FERC)
Primary Question"What has been done to systems like this, and how would you detect it?""How should this be designed/managed?" or "What must you legally report?"
EnforcementNone โ€” there is nothing to certify or audit againstCertification (62443), federal adoption (800-82), or legal penalty (CIP-008)
Typical PairingSupplies the "how would an attacker do this" lens applied on top of the other threeSupply the design, the risk process, or the reporting obligation that ATT&CK for ICS findings feed into
04

The Matrix โ€” Tactics & Techniques

Twelve tactics span the ICS attack lifecycle. Grouping them into three phases tells the same story Lessons 6โ€“7 already teach: an intrusion typically starts on the IT side, moves through the network to build situational awareness, and only becomes an OT incident once it reaches physical impact. MITRE periodically revises the technique list โ€” treat the examples below as representative, and check the live matrix (linked in Section 09) for the current, complete set before quoting exact counts to students.

Phase 1Get In
Access & Foothold
The adversary gets into the environment and establishes a durable presence.
Initial AccessExecutionPersistencePrivilege EscalationEvasion
Phase 2Get Around
Situational Awareness & Movement
The adversary learns the environment, moves through it, and stages a way to control it remotely.
DiscoveryLateral MovementCollectionCommand and Control
Phase 3Cause Impact
Physical Impact
The adversary blocks the operator's ability to respond and manipulates or damages the physical process.
Inhibit Response FunctionImpair Process ControlImpact

Phase 1 โ€” Access & Foothold

Phase 2 โ€” Situational Awareness & Movement

Phase 3 โ€” Physical Impact

05

Case Studies โ€” Groups & Software

ATT&CK for ICS names the threat "Groups" and "Software" behind documented campaigns and links each to the tactics/techniques they used. These five are the incidents most commonly taught and referenced across the field โ€” every one is analyzed here strictly as a case study, consistent with this course's defensive-scope safeguard.

06

Related Resources

ATT&CK for ICS is one piece of a small ecosystem of MITRE knowledge bases and tools that are usually referenced alongside it.

ResourceFocusHow It Complements ATT&CK for ICS
Enterprise ATT&CKIT-side adversary tactics/techniquesModels the initial compromise before an intrusion ever reaches the OT network โ€” analysts chain Enterprise โ†’ ICS across one incident
ATT&CK NavigatorVisualization toolOverlays detection coverage, or a specific incident's techniques, onto the matrix as a heat map
MITRE D3FENDDefensive technique knowledge baseMaps countermeasures to ATT&CK techniques โ€” the "what do I do about this" companion to ATT&CK's "what did they do"
MITRE EngageAdversary engagement & deceptionFrames deception and denial operations against the same technique vocabulary
CISA ICS AdvisoriesVulnerability & incident advisoriesPrimary source material that feeds new ATT&CK for ICS groups, software, and techniques over time
07

Defensive Applications

There is nothing to audit or certify against here โ€” the value of ATT&CK for ICS is entirely in how defenders use it as a shared reference lens.

Threat Intelligence Structuring

Gives incident reports and vendor advisories a shared vocabulary, so "what happened" in one report means the same thing in the next.

Detection Engineering & Coverage Mapping

Mapping existing SOC/SIEM alert rules to specific techniques reveals exactly which tactics have zero detection coverage.

Red/Blue/Purple Team Exercises

Scopes adversary emulation and tabletop exercises around documented technique sets โ€” without requiring anyone to write or run exploit code.

Gap Analysis & Leadership Reporting

Translates "which techniques could hurt us, and are we covered" into a business-risk conversation leadership can act on.

๐Ÿ“– Teaching Note

Anchor lesson: Lesson 6 (Threat Landscape) and Lesson 7 (Vulnerabilities & Countermeasures). Have students map a Lesson 7 countermeasure to each tactic in Section 04 that it would have interrupted, using one of the Section 05 case studies as the scenario.

โš  Case study analysis and detection mapping only โ€” no attack tooling or live targeting
08

Classroom Uses

Incident Mapping Exercise

Pick one case study from Section 05 and map its known stages onto the 12 tactics in Section 04, phase by phase.

Detection Gap Analysis

Give students a fictional list of eight SOC alert rules. They map each to a technique, then identify which of the 12 tactics have zero coverage.

Purple Team Tabletop

Instructor narrates a documented technique sequence from Section 05 as "red." Students playing "blue" decide what alert or control would have caught each step โ€” narration only, no tooling executed.

Cross-Framework Reporting Bridge

Take the same mapped incident to the NERC CIP-008 page: at which technique does it become a "Reportable Cyber Security Incident," and what would the Attachment 1 notification say?

โš  Case study analysis only โ€” no attack tooling, exploit code, or live targeting
09

Sources & Further Reading

This page is a teaching summary of a publicly maintained knowledge base, not a reproduction of MITRE's technique text or an exhaustive listing. MITRE periodically adds, retires, and renumbers techniques โ€” verify current tactic and technique details against the live matrix before presenting exact counts or IDs to students, per this course's own Safeguards policy on faculty review of generated content.