MITRE ATT&CK ICS
T1692

Unauthorized Message

Description

Adversaries may send unauthorized messages to ICS systems and devices to evade defenses or manipulate processes. Unauthorized messages can be categorized as either reporting messages that contain telemetry data about the current state of systems, devices, and processes or as command messages which instruct systems and devices on how to operate. By injecting unauthorized messages, adversaries can make it appear as if everything is working correctly when it isn’t, trigger alarms to misdirect personnel or impact processes, and manipulate controls to disrupt processes.(Citation: Bonnie Zhu, Anthony Joseph, Shankar Sastry 2011) Adversaries may send unauthorized messages in an ICS environment using software found within the environment (living-off-the-land, vendor-specific interfaces, etc.), custom tooling leveraging OT protocols and libraries, or by positioning themselves between systems and devices and injecting messages into the communications such as the case with an [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T0830) attack.

Mapped SPARTA techniques

4 techniques

  • EX-0001ReplayST0004
    addresses
    moderate

    T1692 'Unauthorized Message' addresses adversary sending unauthorised messages to instruct control-system assets to perform actions outside intended functionality — replay of captured authenticated commands creates exactly this kind of unauthorised message (technically valid format but adversary-injected). Cross-tactic moderate because T1692 sits in evasion and impair-process-control while SPARTA EX-0001 is execution.

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    moderate

    Bus traffic replay (forging arbitrary bus messages, not just commands) maps to T1692 'Unauthorized Message' at parent level — covers the broader category of unauthorised messages on control buses. Cross-tactic moderate.

  • EX-0014SpoofingST0004
    relates to
    moderate

    T1692 'Unauthorized Message' addresses adversary sending unauthorised messages to deceive control systems — SPARTA EX-0014 'Spoofing' parent covers spoofing signals/data sent to the spacecraft, which create unauthorised message-class entities. Cross-tactic moderate (evasion/impair vs execution).

  • EX-0014.02Bus Traffic SpoofingST0004
    addresses
    moderate

    Bus traffic spoofing (forging arbitrary packets on internal buses) creates unauthorised messages on the bus medium; T1692 'Unauthorized Message' covers this at cross-tactic moderate level.

Cite as SafeMode Space, mitre-attack-ics T1692.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.