mitre / cti

Cyber Threat Intelligence Repository expressed in STIX 2.0
Other
1.71k stars 410 forks source link

ICS platform information #214

Open rubinatorz opened 1 year ago

rubinatorz commented 1 year ago

Hi there!

For ICS techniques have platforms like: Control Server, Field Controller/RTU/PLC/IED, Safety Instrumented System/Protection Relay, etc. These are mentioned at the technique pages as well as in the Navigator platform filter.

However, when looking at data source platforms, you don't see those ICS-platforms like the ones mentioned above. For example:

Module Load

The Module data source has platforms: Linux, Windows, macOS. While one of the techniques referenced by Module Load, T0886 has platforms: Control Server, Engineering Workstation, Human-Machine Interface.

So those doesn't seem to correspond, while for Mobile and Enterprise the DS platforms and technique platforms correspond.

I think this is because of the former "Assets" attribute on the old ICS Wiki pages. Is that true? And can you elaborate on the future of these ICS platforms? Will this stay like this, or will this be harmonized in the future?

Edit: "ICS only" data sources like Asset and Operational databases doesn't have the platform property. So it's also possible that there are no platforms included for ICS at data source level...?

It would be great if you can shine your light on this topic. Thanks in advance!