Command Message
Parent: T1692
Description
Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger their expected function. Command messages are used in ICS networks to give direct instructions to control systems devices. If an adversary can send an unauthorized command message to a control system, then it can instruct the control systems device to perform an action outside the normal bounds of the device's actions. An adversary could potentially instruct a control systems device to perform an action that will cause an [Impact](https://attack.mitre.org/tactics/TA0105).(Citation: Bonnie Zhu, Anthony Joseph, Shankar Sastry 2011) In the Dallas Siren incident, adversaries were able to send command messages to activate tornado alarm systems across the city without an impending tornado or other disaster.(Citation: Zack Whittaker April 2017)(Citation: Benjamin Freed March 2019)
Mapped SPARTA techniques
3 techniques
T1692.001 'Command Message' specifically addresses unauthorised command messages; SPARTA EX-0001.01 'Command Packets' replay is the same activity (replaying captured command packets creates unauthorised command messages). Cross-tactic moderate (evasion/impair vs execution).
T1692.001 'Command Message' addresses adversary sending unauthorised command messages — SPARTA EX-0005.02 'Malicious Use of Hardware Commands' is exactly this pattern (using legitimate hardware commands maliciously means sending technically valid but unauthorised commands). Cross-tactic moderate (evasion/impair vs execution); this is a much better concept-match than MITRE Enterprise where EX-0005.02 was empty.
T1692.001 'Command Message' addresses adversary unauthorised command messages; SPARTA EXF-0001 'Replay' during exfiltration replays captured authenticated commands to trigger downlink — these replayed commands are unauthorised (originally legitimate but adversary-injected). Cross-tactic moderate (T1692.001 in evasion and impair-process-control while SPARTA EXF-0001 is exfiltration); ICS has no exfiltration tactic.
Cite as SafeMode Space, mitre-attack-ics T1692.001.