MITRE ATT&CK ICS
T0822

External Remote Services

Description

Adversaries may leverage external remote services as a point of initial access into your network. These services allow users to connect to internal network resources from external locations. Examples are VPNs, Citrix, and other access mechanisms. Remote service gateways often manage connections and credential authentication for these services. (Citation: Daniel Oakley, Travis Smith, Tripwire) External remote services allow administration of a control system from outside the system. Often, vendors and internal engineering groups have access to external remote services to control system networks via the corporate network. In some cases, this access is enabled directly from the internet. While remote access enables ease of maintenance when a control system is in a remote area, compromise of remote access solutions is a liability. The adversary may use these services to gain access to and execute attacks against a control system network. Access to valid accounts is often a requirement. As they look for an entry point into the control system network, adversaries may begin searching for existing point-to-point VPN implementations at trusted third party networks or through remote support employee connections where split tunneling is enabled. (Citation: Electricity Information Sharing and Analysis Center; SANS Industrial Control Systems March 2016)

Mapped SPARTA techniques

7 techniques

  • T0822 'External Remote Services' is the ATT&CK ICS initial-access technique for using externally-facing remote services as initial-access vectors; SPARTA IA-0004 'Secondary/Backup Communication Channel' covers using backup TT&C channels (TDRSS, contingency uplinks, alternate ground sites) as the same kind of external remote-service entry. Tactic and activity align.

  • IA-0004.01Ground StationST0003
    addresses
    high

    An alternate/backup ground station is an external remote service granting access to the spacecraft; abusing it as initial-access path matches T0822 'External Remote Services' directly.

  • IA-0004.02ReceiverST0003
    addresses
    moderate

    A backup receiver (alternate antenna, redundant transponder path) is an external remote interface to the spacecraft; abusing it as initial-access matches T0822 'External Remote Services'.

  • IA-0009Trusted RelationshipST0003
    addresses
    moderate

    Trusted-relationship access often manifests via partner-network external remote services (B2B VPNs, partner-API endpoints, vendor remote-management portals); T0822 'External Remote Services' covers this pattern at moderate confidence — ICS doesn't have a dedicated 'Trusted Relationship' technique so the closest concept is external-remote-service abuse.

  • Mission collaborators (academia, partner agencies, international consortia) typically connect via external remote services; T0822 covers this as the closest ICS concept-equivalent for trusted-collaborator access.

  • IA-0009.02VendorST0003
    addresses
    moderate

    Vendor compromise often manifests via vendor-provided remote-management/monitoring services (B2B VPN, vendor-portal access into operator MOC); T0822 'External Remote Services' covers this access path.

  • IA-0009.03User SegmentST0003
    addresses
    moderate

    User-segment compromise (compromise an end-user terminal/mission-data customer to pivot upstream) typically uses external remote-service connectivity into the operator's data flows; T0822 'External Remote Services' covers this pivot path.

Cite as SafeMode Space, mitre-attack-ics T0822.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.