Sergey Pariev
или она добавкой к основной матрице идет?
Ну да, они так и пишут в блоге
However, IT platforms form a significant foundation for ICS so we can’t completely ignore them. ATT&CK for ICS attempts to only include ATT&CK for Enterprise techniques used against systems that are leveraged in the final stages leading up to an adversary induced impact, targeted or un-targeted, against an industrial process. For instance, the Enterprise technique Hooking (T1179) has been leveraged to modify DLLs associated with engineering applications used to interface directly with PLCs. The use of this technique in the ICS domain brings about new considerations and unique concerns due to unique ICS-specific functions engineering applications enable. Therefore, Hooking (T874) was also added to the ICS knowledge base to help highlight the use of this technique in a different context.
It’s very clear that there’s a fair bit of overlap between the Enterprise and ICS technology domains. Nonetheless, ATT&CK for ICS has a primary focus on the actions that adversaries take against the non-IT based systems and functions of ICS. It seeks to capture and define distinctions in ICS environments, from tactics and techniques to domain specific assets and technology. It is this focus that defines ATT&CK for ICS as a unique and vital knowledge base in the ATT&CK ecosystem.