LiveActive security incident?Get immediate response
MITRE ATT&CK® ICS Asset

A0004: Remote Terminal Unit (RTU)

A Remote Terminal Unit (RTU) is a device that typically resides between field devices (e.g., PLCs, IEDs) and control/SCADA servers and supports various communication interfacing and data aggregation functions. RTUs are typically responsible for forwarding commands from the control server and the collection of telemetry, events, and alerts from the field devices. An RTU can be implemented as a dedicated embedded device, as software platform that runs on a hardened/ruggedized computer, or using a custom application program on a PLC.

ICSA0004ICS AssetObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

A Remote Terminal Unit (RTU) is a critical ICS intermediary between field devices such as PLCs/IEDs and control or SCADA servers. Its business importance is that it can carry commands toward the process and return telemetry, events, and alarms back to operators. If an RTU is unavailable, misconfigured, impersonated, or manipulated, organizations may lose trustworthy visibility or control over physical operations.

Executive priority

Treat RTUs as high-value operational resilience assets, not just network endpoints. Leadership should ask whether RTUs are inventoried, segmented, backed up where applicable, monitored for command/telemetry integrity, and included in incident response and recovery plans. The relationship context shows RTUs are relevant to discovery, credential misuse, remote service exploitation, protocol abuse, denial of service, parameter or alarm modification, firmware update mode abuse, and rogue master scenarios, so control priorities should align to safety, uptime, and evidence needs for audits and incident decisions.

Technical view

SOC, OT, and IR teams should validate visibility across RTU communications with SCADA/control servers and field devices. Because MITRE provides no official detection text for this asset, detections should be built from relationship-driven behaviors: unexpected discovery scans or broadcast/multicast enumeration, abnormal use of standard ICS/application protocols, unauthorized remote service access, valid-account activity inconsistent with normal operations, unexpected restart/shutdown or denial-of-service symptoms, changes to parameters or alarm settings, firmware update mode activation, and traffic patterns suggesting adversary-in-the-middle or rogue master behavior. Platforms listed for this asset are Embedded, Linux, and Windows, so host-level visibility may vary significantly by implementation.

Likely telemetry

  • Authoritative RTU asset inventory, firmware/software version, role, network location, and approved communication peers
  • Network flow and packet/protocol telemetry between RTUs, SCADA/control servers, PLCs/IEDs, and engineering workstations
  • ICS protocol command, read/write, alarm, event, point/tag, and telemetry records where available
  • Authentication and account-use logs for RTU management interfaces, remote services, and supporting operating systems
  • Configuration, parameter, alarm setting, firmware/update-mode, restart, and shutdown change records

Detection direction

  • Baseline normal RTU peers and protocol behavior; alert on new masters, unexpected control servers, unusual source systems, or communication paths inconsistent with the RTU role.
  • Correlate network discovery indicators such as port scans, broadcast discovery, multicast discovery, and connection enumeration with authorized maintenance windows to reduce false positives.
  • Monitor for write actions, repeated I/O changes, parameter changes, alarm setting changes, firmware update mode activation, and restart/shutdown events that are not tied to approved engineering activity.
  • Validate credential controls and logging for RTU administration because Valid Accounts is a related technique and default or compromised credentials can undermine network-only defenses.
  • Look for integrity gaps: adversary-in-the-middle or rogue master activity may appear as legitimate protocol traffic unless peer identity, timing, command type, and process context are inspected.

Mitigation priorities

  • Start with a verified RTU inventory and communication map covering SCADA/control servers, field devices, engineering access paths, and remote services.
  • Restrict RTU management and control paths to approved systems and accounts; remove default credentials and enforce least-privilege access where supported.
  • Segment RTU networks and limit unnecessary services or application-layer protocols to reduce discovery, exploitation, and command-and-control opportunities.
  • Establish change control for firmware/update mode, parameter changes, alarm settings, restarts, shutdowns, and maintenance media use.
  • Build recovery evidence: known-good configurations, approved firmware/software records, maintenance procedures, and incident playbooks for loss of visibility, loss of control, or suspected manipulation.
Additional notes and limits

This is an ATT&CK for ICS asset object, not a technique. The strongest decision value comes from the RTU’s position between field devices and control/SCADA servers and from the listed techniques that target it. Use this object to drive asset criticality, telemetry validation, segmentation reviews, credential governance, and OT incident response planning.

MITRE provides no official detection text, no tactics for the asset, and no vendor-specific implementation details. The relationship descriptions are truncated in places, and actual monitoring options depend on the RTU model, whether it is embedded or runs on Linux/Windows, available protocol decoding, and local operational constraints.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Remote Terminal Unit (RTU)

A Remote Terminal Unit (RTU) is a device that typically resides between field devices (e.g., PLCs, IEDs) and control/SCADA servers and supports various communication interfacing and data aggregation functions. RTUs are typically responsible for forwarding commands from the control server and the collection of telemetry, events, and alerts from the field devices. An RTU can be implemented as a dedicated embedded device, as software platform that runs on a hardened/ruggedized computer, or using a custom application program on a PLC.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

45 rows
DomainIDNameRelationship / procedure
ICST0846.003Multicast DiscoverySub-techniqueMulticast Discovery targets this object.
ICST0884Connection ProxyConnection Proxy targets this object.
ICST0848Rogue MasterRogue Master targets this object.
ICST0809Data DestructionData Destruction targets this object.
ICST0862Supply Chain CompromiseSupply Chain Compromise targets this object.
ICST0842Network SniffingNetwork Sniffing targets this object.
ICST0888Remote System Information DiscoveryRemote System Information Discovery targets this object.
ICST1691Block Operational Technology MessageBlock Operational Technology Message targets this object.
ICST0847Replication Through Removable MediaReplication Through Removable Media targets this object.
ICST1695.003Wi-FiSub-techniqueWi-Fi targets this object.
ICST1695.002EthernetSub-techniqueEthernet targets this object.
ICST0846Remote System DiscoveryRemote System Discovery targets this object.
ICST1691.002Reporting MessageSub-techniqueReporting Message targets this object.
ICST0881Service StopService Stop targets this object.
ICST0866Exploitation of Remote ServicesExploitation of Remote Services targets this object.
ICST1695.001Serial COMSub-techniqueSerial COM targets this object.
ICST0892Change CredentialChange Credential targets this object.
ICST0801Monitor Process StateMonitor Process State targets this object.
ICST0861Point & Tag IdentificationPoint & Tag Identification targets this object.
ICST0834Native APINative API targets this object.
ICST0872Indicator Removal on HostIndicator Removal on Host targets this object.
ICST1693.001System FirmwareSub-techniqueSystem Firmware targets this object.
ICST0871Execution through APIExecution through API targets this object.
ICST0816Device Restart/ShutdownDevice Restart/Shutdown targets this object.
ICST0874HookingHooking targets this object.
ICST1694.001Default CredentialsSub-techniqueDefault Credentials targets this object.
ICST1694Insecure CredentialsInsecure Credentials targets this object.
ICST1692.002Reporting MessageSub-techniqueReporting Message targets this object.
ICST0878Alarm SuppressionAlarm Suppression targets this object.
ICST1692.001Command MessageSub-techniqueCommand Message targets this object.
ICST0800Activate Firmware Update ModeActivate Firmware Update Mode targets this object.
ICST1695Block CommunicationsBlock Communications targets this object.
ICST0846.001Port ScanSub-techniquePort Scan targets this object.
ICST0814Denial of ServiceDenial of Service targets this object.
ICST0846.002Broadcast DiscoverySub-techniqueBroadcast Discovery targets this object.
ICST0869Standard Application Layer ProtocolStandard Application Layer Protocol targets this object.
ICST0840Network Connection EnumerationNetwork Connection Enumeration targets this object.
ICST0836Modify ParameterModify Parameter targets this object.
ICST0838Modify Alarm SettingsModify Alarm Settings targets this object.
ICST1691.001Command MessageSub-techniqueCommand Message targets this object.
ICST0806Brute Force I/OBrute Force I/O targets this object.
ICST0885Commonly Used PortCommonly Used Port targets this object.
ICST0830Adversary-in-the-MiddleAdversary-in-the-Middle targets this object.
ICST1692Unauthorized MessageUnauthorized Message targets this object.
ICST0859Valid AccountsValid Accounts targets this object.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
0bb67234186a5b6d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle0bb67234186a…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    mitre-attackA0004
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.