MITRE ATT&CK ICS
T0819

Exploit Public-Facing Application

Description

Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network. Internet-facing software may be user applications, underlying networking implementations, an assets operating system, weak defenses, etc. Targets of this technique may be intentionally exposed for the purpose of remote management and visibility. An adversary may seek to target public-facing applications as they may provide direct access into an ICS environment or the ability to move into the ICS network. Publicly exposed applications may be found through online tools that scan the internet for open ports and services. Version numbers for the exposed application may provide adversaries an ability to target specific known vulnerabilities. Exposed control protocol or remote access ports found in Commonly Used Port may be of interest by adversaries.

Mapped SPARTA techniques

1 techniques

  • T0819 'Exploit Public-Facing Application' is the ATT&CK ICS initial-access technique for exploiting weaknesses in internet-facing services; SPARTA IA-0007 'Compromise Ground System' covers compromise of GS public-facing applications (operator portals, scheduling interfaces, telemetry forwarders). Tactic and activity align.

Cite as SafeMode Space, mitre-attack-ics T0819.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.