MITRE ATT&CK ICS
T1692.002
enhancement

Reporting Message

Parent: T1692

Description

Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the current state of equipment and the industrial process. Reporting messages are important for monitoring the normal operation of a system or identifying important events such as deviations from expected values. If an adversary has the ability to Spoof Reporting Messages, they can impact the control system in many ways. The adversary can Spoof Reporting Messages that state that the process is operating normally, as a form of evasion. The adversary could also Spoof Reporting Messages to make the defenders and operators think that other errors are occurring in order to distract them from the actual source of a problem.(Citation: Bonnie Zhu, Anthony Joseph, Shankar Sastry 2011)

Mapped SPARTA techniques

2 techniques

  • T1692.002 'Reporting Message' addresses adversary unauthorised reporting messages — sensor deception is achieved by injecting falsified sensor reports/measurements into the SSA/SDA processing pipeline, creating exactly this kind of unauthorised reporting message. Cross-tactic moderate (T1692.002 in evasion AND impair-process-control while SPARTA DE-0009.04 is defense-evasion — partial tactic alignment with evasion).

  • EX-0014.03Sensor DataST0004
    addresses
    moderate

    T1692.002 'Reporting Message' specifically addresses unauthorised reporting/telemetry messages; SPARTA EX-0014.03 'Sensor Data' spoofing creates exactly this kind of unauthorised reporting message (falsified sensor readings injected on sensor lines). Cross-tactic moderate (evasion/impair vs execution); direct sub-technique concept match.

Cite as SafeMode Space, mitre-attack-ics T1692.002.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.