MITRE ATT&CK ICS
T0820

Exploitation for Evasion

Description

Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection. Vulnerabilities may exist in software that can be used to disable or circumvent security features. Adversaries may have prior knowledge through [Remote System Information Discovery](https://attack.mitre.org/techniques/T0888) about security features implemented on control devices. These device security features will likely be targeted directly for exploitation. There are examples of firmware RAM/ROM consistency checks on control devices being targeted by adversaries to enable the installation of malicious [System Firmware](https://attack.mitre.org/techniques/T0857).

Mapped SPARTA techniques

1 techniques

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    moderate

    T0820 'Exploitation for Evasion' addresses adversary exploitation of vulnerabilities to bypass security features; SPARTA EX-0006 'Disable/Bypass Encryption' is a security-feature-bypass activity (disable or weaken cryptographic protections). Cross-tactic moderate (evasion vs execution); ICS doesn't have a dedicated encryption-weakening technique so T0820 is the closest concept-match.

Cite as SafeMode Space, mitre-attack-ics T0820.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.