LiveActive security incident?Get immediate response
MITRE ATT&CK® ICS Asset

A0014: Routers

A computer that is a gateway between two networks at OSI layer 3 and that relays and directs data packets through that inter-network. The most common form of router operates on IP packets.[1]

ICSA0014ICS AssetObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Routers are decision points between networks, so in an ICS environment they can become both a dependency for operations and a choke point for adversary activity. The ATT&CK relationships show routers being relevant to discovery, remote access abuse, credential misuse, traffic interception/proxying, communications blocking, restart/shutdown, and data destruction. For leaders, the practical issue is not just whether routers exist, but whether the organization can prove they are inventoried, securely administered, monitored, and recoverable if network paths supporting control operations are disrupted.

Executive priority

Treat ICS routers as resilience-critical infrastructure. They sit at boundaries where remote services, Ethernet/Wi-Fi communications, and inter-network routing can affect operational continuity and incident response access. Priority questions for executives and risk owners: Which routers connect IT, OT, vendor access, wireless, or other trusted networks? Are default or insecure credentials eliminated where possible? Are management paths controlled and logged? Is there a tested recovery path if a router is restarted, shut down, reconfigured, or used to block communications? These answers support control prioritization, audit evidence, and cyber-physical risk discussions.

Technical view

For SOC, detection engineering, and IR teams, validate visibility around Embedded and Network platforms that perform routing in the ICS environment. MITRE provides no official detection text for this asset, so coverage should be built from relationship context: scans and discovery against routers; use of external remote services; exploitation of remote services or vulnerabilities; credential changes or default credential use; unexpected restart/shutdown; proxy-like behavior; communications over commonly used ports; adversary-in-the-middle indicators; and loss or blocking of Ethernet/Wi-Fi communications. Baseline normal routing, management, and remote access behavior before alerting on deviations.

Likely telemetry

  • Asset inventory and network topology showing routers between IT, OT, vendor, wireless, and other network segments
  • Router configuration backups and change records
  • Authentication and administrative access logs for router management interfaces
  • Remote access gateway, VPN, or other external remote service logs where they interact with router-controlled paths
  • Network flow records across routed boundaries

Detection direction

  • Confirm routers are represented as monitored assets, not just passive network infrastructure.
  • Baseline expected management sources, administrator accounts, ports, protocols, and maintenance windows; alert on deviations, especially credential changes, configuration changes, restart/shutdown, or unexpected remote access.
  • Tune discovery detections for ICS context: port scans, broadcast discovery, and multicast discovery may overlap with legitimate engineering, inventory, or monitoring tools, so source identity and timing matter.
  • Look for routed-boundary anomalies such as unusual proxy behavior, traffic interception symptoms, blocked communications, or unexpected use of commonly used ports that differs from the expected protocol or destination pattern.
  • Correlate loss of communications with router interface events, routing changes, authentication events, and device restarts before treating it as only a process or endpoint issue.

Mitigation priorities

  • Maintain an accurate inventory of ICS routers and the networks, remote services, Ethernet, and Wi-Fi paths they support.
  • Restrict and monitor administrative access to router management functions, especially from external remote service paths.
  • Review credentials for default, hardcoded, shared, or otherwise insecure use where local device capabilities allow remediation.
  • Control and document configuration changes, including routing, access control, interface state, and management service exposure.
  • Keep recoverable configuration backups and test restoration procedures for restart, shutdown, destructive change, or lockout scenarios.
Additional notes and limits

This object is an ICS asset definition, not a technique. Its value comes from the set of techniques that target it: Data Destruction, Device Restart/Shutdown, Exploitation for Evasion, External Remote Services, Adversary-in-the-Middle, Port/Broadcast/Multicast Discovery, Exploitation of Remote Services, Hooking, Connection Proxy, Commonly Used Port, Exploitation for Privilege Escalation, Change Credential, Insecure/Default Credentials, and Block Communications over Ethernet or Wi-Fi. The strongest defensive use is to map these behaviors to the organization’s actual router roles and management paths.

MITRE does not provide tactics or official detection guidance for this asset, and the supplied platform scope is limited to Embedded and Network. This take does not imply active exploitation, attribution, or existing detection coverage. Local topology, device models, management methods, remote access design, and operational procedures are required to determine material risk and feasible monitoring.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Routers

A computer that is a gateway between two networks at OSI layer 3 and that relays and directs data packets through that inter-network. The most common form of router operates on IP packets.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

19 rows
DomainIDNameRelationship / procedure
ICST0830Adversary-in-the-MiddleAdversary-in-the-Middle targets this object.
ICST0885Commonly Used PortCommonly Used Port targets this object.
ICST0809Data DestructionData Destruction targets this object.
ICST1694Insecure CredentialsInsecure Credentials targets this object.
ICST0822External Remote ServicesExternal Remote Services targets this object.
ICST0884Connection ProxyConnection Proxy targets this object.
ICST0816Device Restart/ShutdownDevice Restart/Shutdown targets this object.
ICST0866Exploitation of Remote ServicesExploitation of Remote Services targets this object.
ICST0846.002Broadcast DiscoverySub-techniqueBroadcast Discovery targets this object.
ICST1695.003Wi-FiSub-techniqueWi-Fi targets this object.
ICST0846.003Multicast DiscoverySub-techniqueMulticast Discovery targets this object.
ICST0846.001Port ScanSub-techniquePort Scan targets this object.
ICST0820Exploitation for EvasionExploitation for Evasion targets this object.
ICST0874HookingHooking targets this object.
ICST0890Exploitation for Privilege EscalationExploitation for Privilege Escalation targets this object.
ICST1695.002EthernetSub-techniqueEthernet targets this object.
ICST1694.001Default CredentialsSub-techniqueDefault Credentials targets this object.
ICST0892Change CredentialChange Credential targets this object.
ICST1695Block CommunicationsBlock Communications targets this object.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
051ba95b22d7afad...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle051ba95b22d7…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    IETF RFC4949 2007

    Internet Engineering Task Force. (2007, August). Internet Security Glossary, Version 2. Retrieved September 29, 2023.

    Open source URL
  2. [2]
    mitre-attackA0014
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.