When defenders talk about how an attacker behaves rather than which specific malware they used, they usually reach for MITRE ATT&CK, a public knowledge base that organizes real-world adversary behavior into a common language. ATT&CK for ICS is the industrial branch of that knowledge base, built specifically around attacks on control systems rather than office computers. It catalogs the goals an attacker pursues and the methods they use to pursue them inside an industrial environment, giving OT security teams a structured way to ask a hard question: against all the ways an adversary could move through our plant, what would we actually detect?
MITRE ATT&CK for ICS in one line: MITRE ATT&CK for ICS is a public, industrial-specific knowledge base that organizes adversary behavior against control systems into tactics, the goals an attacker is trying to achieve, and techniques, the specific ways they achieve them. It spans the full arc of an industrial attack, from initial access through to tactics unique to OT such as impairing process control and inhibiting response functions. OT security teams use it as a shared reference to map their detection coverage, structure threat hunts, and describe adversary behavior in consistent terms.
ATT&CK is built on two ideas that stack together. A tactic is the why, the objective an attacker has at a given stage, such as gaining initial access, moving laterally, or evading detection. A technique is the how, a specific method used to accomplish that objective. Each tactic is a column, and under it sit the many techniques an adversary might use to satisfy that goal. Reading across the matrix from left to right roughly traces the progression of an attack, from the first foothold toward the attacker's ultimate aim, and reading down a column shows the range of ways any single goal can be reached.
What makes ATT&CK for ICS distinct from the enterprise matrix is that its tactics and techniques describe things that happen to control systems, not to file servers. It includes tactics oriented around the physical process, and its techniques cover moves that only make sense in an industrial context, such as issuing unauthorized commands to a controller, modifying a control program, spoofing a reporting message so operators see the wrong thing, or manipulating a process value directly. Where the enterprise matrix ends at data theft or system disruption, the ICS matrix continues into the domain where the consequence is a physical one.
The most consequential of these industrial tactics is impair process control, which is where an adversary actually alters how the physical process runs, and its companion inhibit response function, where an attacker disables the safety and alarming mechanisms meant to catch a problem. These are the moves that turn a network intrusion into a physical incident, and their presence in the matrix is a reminder of what is ultimately at stake. An attacker who reaches these tactics is no longer stealing information; they are reaching for the levers that control equipment in the real world.
The most common practical use of the matrix is as a coverage map. A security team goes technique by technique and asks, if an adversary used this against us, would we see it, and if so, how. Techniques the team can reliably detect get marked as covered, techniques they cannot get marked as gaps, and the finished map shows at a glance where the defenses are strong and where an attacker could operate unseen. This turns a vague worry about being under-protected into a specific, prioritized list of blind spots, and it lets a team argue for investment in the language of concrete adversary behavior rather than generic fear.
The map also guards against a common failure, which is piling detection on the early stages of an attack while leaving the later ones bare. It is tempting to focus on initial access and lateral movement because that is where enterprise security lives, but in ICS the techniques that matter most are often the late ones, where the attacker touches the process itself. A coverage map that honestly marks the impair-process-control and inhibit-response techniques as gaps forces the uncomfortable but important recognition that a team might detect an intruder arriving while remaining blind to the moment they actually manipulate a controller.
Coverage mapping is not a one-time exercise but a living document. As new techniques are added to the knowledge base, as the environment changes, and as new detections are built, the map is updated, and its trend over time tells a story about whether the program is actually getting better. It also feeds directly into planning: the biggest, most dangerous gaps become the next detections to build or the next hunts to run, so the matrix turns from a static reference into an engine that keeps pointing the team at the highest-value work.
The matrix is also a source of hunting hypotheses. Rather than starting from scratch, a hunter can pick a technique the coverage map marks as undetected, especially one known to be used against their sector, and hunt for its footprint directly. Because each technique in the knowledge base comes with a description of how it works and what it looks like, it hands the hunter a ready-made picture of what to search for. Working through the undetected techniques in priority order gives a hunting program structure and ensures that scarce hunting time is spent on the behaviors that actually leave the team exposed.
The framework's shared vocabulary also changes how teams communicate. Publicly analyzed attacks on industrial targets are commonly described in ATT&CK terms, which means a team can read an intrusion report, see which techniques an adversary used against a peer, and immediately check those same techniques against their own coverage map. An incident anywhere becomes a concrete test everywhere: if a documented attack used a particular sequence of techniques, every OT team can ask whether they would have caught that exact sequence, and close the gaps the report exposes before the same adversary reaches them.
This connects the abstract matrix to the operational reality of running plants. The techniques under impair process control describe things an attacker does to setpoints, control logic, and process values, and the only way to detect many of them is to watch what the process is actually doing. A cloud SCADA platform such as Merobix, by continuously recording process behavior across sites, provides the operational evidence a team needs to detect the late-stage, process-affecting techniques the matrix warns about, so the coverage map is backed by real visibility into the process rather than by network monitoring alone. The matrix names the threats; the operational data is often what makes catching the most dangerous of them possible.
The enterprise matrix describes attacks on IT systems like servers, workstations, and cloud services, ending at goals such as data theft or system disruption. ATT&CK for ICS describes attacks on control systems and continues into the physical domain, with tactics and techniques for things like modifying control programs, issuing unauthorized commands to controllers, spoofing reporting messages, and impairing process control. It exists because industrial attacks have goals and methods, tied to the physical process, that the enterprise matrix does not cover.
Impair process control is the ICS tactic covering techniques by which an attacker actually alters how the physical process runs, such as changing setpoints, modifying control logic, or manipulating process values directly. It is one of the most consequential parts of the matrix because it is where a network intrusion becomes a physical incident. Its companion tactic, inhibit response function, covers disabling the safety systems and alarms meant to catch such a problem, which is why detecting these late-stage techniques matters so much.
Most commonly as a detection coverage map: they go technique by technique and mark whether they could detect each one, producing a clear picture of their blind spots that guides where to invest. They also use it to generate threat-hunting hypotheses, choosing undetected techniques to hunt for, and as a shared vocabulary for describing adversary behavior, so a documented attack on a peer becomes a concrete test they can run against their own coverage. It turns a general worry about defenses into a specific, prioritized plan.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.