MITRE ATT&CK ICS
T0864

Transient Cyber Asset

Description

Adversaries may target devices that are transient across ICS networks and external networks. Normally, transient assets are brought into an environment by authorized personnel and do not remain in that environment on a permanent basis. (Citation: North American Electric Reliability Corporation June 2021) Transient assets are commonly needed to support management functions and may be more common in systems where a remotely managed asset is not feasible, external connections for remote access do not exist, or 3rd party contractor/vendor access is required. Adversaries may take advantage of transient assets in different ways. For instance, adversaries may target a transient asset when it is connected to an external network and then leverage its trusted access in another environment to launch an attack. They may also take advantage of installed applications and libraries that are used by legitimate end-users to interact with control system devices. Transient assets, in some cases, may not be deployed with a secure configuration leading to weaknesses that could allow an adversary to propagate malicious executable code, e.g., the transient asset may be infected by malware and when connected to an ICS environment the malware propagates onto other systems.

Mapped SPARTA techniques

3 techniques

  • IA-0005.02Docked Vehicle / OSAMST0003
    addresses
    moderate

    T0864 'Transient Cyber Asset' addresses adversary use of transient devices that move between networks/environments; SPARTA IA-0005.02 'Docked Vehicle / OSAM' is the orbital instance — a visiting vehicle is a transient cyber asset that physically attaches to gain access. Cross-domain moderate (orbital docking vs enterprise transient laptop/USB).

  • T0864 'Transient Cyber Asset' addresses adversary use of transient devices that move between environments (engineer laptops, vendor diagnostic tools); SPARTA IA-0011 covers exactly this pattern (auxiliary devices like ATLO benchtop instruments, MOC USB sticks). Tactic and activity align.

  • Mapped by SPARTA, not curated by SafeMode Space.

Cite as SafeMode Space, mitre-attack-ics T0864.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.