MITRE ATT&CK ICS
T0806

Brute Force I/O

Description

Adversaries may repetitively or successively change I/O point values to perform an action. Brute Force I/O may be achieved by changing either a range of I/O point values or a single point value repeatedly to manipulate a process function. The adversary's goal and the information they have about the target environment will influence which of the options they choose. In the case of brute forcing a range of point values, the adversary may be able to achieve an impact without targeting a specific point. In the case where a single point is targeted, the adversary may be able to generate instability on the process function associated with that particular point. Adversaries may use Brute Force I/O to cause failures within various industrial processes. These failures could be the result of wear on equipment or damage to downstream equipment.

Mapped SPARTA techniques

1 techniques

  • EX-0013.01Valid CommandsST0004
    addresses
    moderate

    T0806 'Brute Force I/O' is the ATT&CK ICS technique for adversary brute-forcing commands of an I/O point to manipulate the process by overloading or saturating I/O — exact concept-match for SPARTA EX-0013.01 'Valid Commands' flooding (overwhelm the receiver with valid-format commands). Cross-tactic moderate (T0806 in impair-process-control vs SPARTA EX-0013.01 execution).

Cite as SafeMode Space, mitre-attack-ics T0806.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.