MITRE ATT&CK ICS
T0834

Native API

Description

Adversaries may directly interact with the native OS application programming interface (API) to access system functions. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. (Citation: The MITRE Corporation May 2017) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Functionality provided by native APIs are often also exposed to user-mode applications via interfaces and libraries. For example, functions such as memcpy and direct operations on memory registers can be used to modify user and system memory space.

Mapped SPARTA techniques

1 techniques

  • EX-0010Malicious CodeST0004
    addresses
    moderate

    T0834 'Native API' is in MITRE ICS execution tactic and addresses adversary use of native OS/system APIs to execute code; SPARTA EX-0010 'Malicious Code' is the parent-level pattern for executing attacker code on the spacecraft, which typically uses native FSW/RTOS APIs. Tactic aligns (both execution); cross-domain moderate (RTOS-vs-enterprise-OS native-API gap).

Cite as SafeMode Space, mitre-attack-ics T0834.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.