Files
cti/ics-attack/attack-pattern/attack-pattern--354ca909-b54d-4c41-b597-9c296b344a43.json
T
2026-04-27 15:18:54 -04:00

46 lines
2.5 KiB
JSON

{
"type": "bundle",
"id": "bundle--441858cb-28e7-4a75-b2eb-f862127c0dee",
"spec_version": "2.0",
"objects": [
{
"type": "attack-pattern",
"id": "attack-pattern--354ca909-b54d-4c41-b597-9c296b344a43",
"created": "2026-04-20T20:54:20.103Z",
"created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
"revoked": false,
"external_references": [
{
"source_name": "mitre-attack",
"url": "https://attack.mitre.org/techniques/T0873/001",
"external_id": "T0873.001"
},
{
"source_name": "Nicolas Falliere, Liam O Murchu, Eric Chien February 2011",
"description": "Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.",
"url": "https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en"
}
],
"object_marking_refs": [
"marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
],
"modified": "2026-04-23T19:37:43.545Z",
"name": "Siemens Project File Format",
"description": "Adversaries may infect Siemens PLC project files (i.e., Step 7, WinCC, etc.) to achieve [Execution](https://attack.mitre.org/tactics/TA0104), [Persistence](https://attack.mitre.org/tactics/TA0110), and [Lateral Movement](https://attack.mitre.org/tactics/TA0109) objectives. Adversaries may modify an existing project file or bring their own project files into the environment.(Citation: Nicolas Falliere, Liam O Murchu, Eric Chien February 2011)\n\nThe ability for an adversary to deploy an infected project file relies on access to a workstation with Siemens PLC programming software installed on it from which a program download can be performed.\n",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-ics-attack",
"phase_name": "persistence"
}
],
"x_mitre_attack_spec_version": "3.3.0",
"x_mitre_deprecated": false,
"x_mitre_domains": [
"ics-attack"
],
"x_mitre_is_subtechnique": true,
"x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
"x_mitre_version": "1.0"
}
]
}