Detection Engineering

Shared Attack Paths

Two ATT&CK Matrices, One Attack Path

Most detection programs map only to MITRE ATT&CK for Enterprise and miss the IT-to-OT pivot. Industrial defense needs both matrices and the path between them.

Two ATT&CK Matrices, One Attack Path

A ransomware responder finds an encrypted Windows server, documents it as an IT incident, and moves on. What the report never captures is that the server was an engineering workstation running SCADA software, the machine that programs the controllers on the plant floor. The attack had reached the edge of the physical process, and the paperwork filed it under laptops and email.

That gap is not a documentation quirk. It is how most detection programs are built. They map their detections to MITRE ATT&CK for Enterprise, the framework for IT attacks, and treat operational technology as a separate monitoring problem. The move between the two, the pivot from IT into OT, becomes a footnote. That pivot is the attack. Dragos, in its 2026 Year in Review, reports that OT incidents are routinely mischaracterized as IT-only for exactly this reason. Industrial environments need both ATT&CK matrices, and the path between them is the most important thing to detect.

One Path, Two Matrices

MITRE maintains two ATT&CK matrices, and the split is deliberate. ATT&CK for Enterprise, as of its October 2025 release, catalogs 222 techniques across 15 tactics. ATT&CK for ICS catalogs 79 techniques across 12 tactics.

The two describe different halves of the same intrusion. Enterprise is how attackers travel. ICS is what they do when they arrive. A detection program mapped to only one sees half the attack in industrial environments where the attacks that matter cross both layers. Mapped together, the matrices provide end-to-end coverage from initial access to controller-level consequence.

The IT-to-OT Pivot Is the Whole Game

Industrial attacks rarely begin on the factory floor. A synthesis of Dragos, Sophos, and CISA reporting points to roughly three-quarters of OT attacks starting as an IT breach, a consequence of how tightly connected the two environments are.

When Colonial Pipeline was hit by ransomware in May 2021, the compromise sat in IT business systems, yet the operator shut down the pipeline itself as a precaution. An intrusion that never reached a controller still produced an operational outcome because the company could not confirm where IT impact ended and OT risk began.

US advisories on Volt Typhoon show the path in sequence: exploit public-facing infrastructure, steal domain controller data, crack credentials offline, abuse jump hosts, and move toward engineering workstations that can program Level 1 controllers. Read that chain against ATT&CK and the pattern is clear. Most steps map to Enterprise techniques before the final operational effect maps to ICS.

Why the Boundary Stays Invisible

The pivot often goes undetected because engineering workstations and HMIs run Windows. Responders log a familiar host as an IT incident and miss the OT role of the system. Dragos describes this mislabeling as a persistent industry problem.

Valid credentials are the connective tissue. A stolen account that looks routine on the IT side becomes OT access on the other side. Through 2025, Dragos also observed attackers using compromised remote access and valid credentials to reach VMware ESXi layers hosting SCADA, HMI, historian, and engineering workloads.

The blind spot is measured in dwell time. Dragos reports average ransomware dwell time in OT environments at 42 days. For organizations with comprehensive OT visibility, the average falls to 5 days.

Make the Pivot a First-Class Detection Target

If the pivot is the attack, it needs dedicated detections, not leftovers from separate programs. In practice that means detections for domain-controller credential theft, jump-host misuse, remote access behavior toward control networks, engineering-workstation anomalies, and access to virtualization hosts running OT workloads.

Many teams still treat operational technology as a separate monitoring problem, which leaves boundary detections unowned. A unified coverage map should show both Enterprise and ICS techniques and expose where the path between them is not covered.

That is why a coverage review can show where Enterprise techniques and ICS techniques are covered, and where the seam is open. NERC CIP-015 now requires Internal Network Security Monitoring, east-west visibility precisely where movement toward OT first appears.

How PhishCloud Approaches It

We baseline every detection engagement against both ATT&CK matrices, Enterprise and ICS, and treat IT-to-OT pivot detection as a primary target. We build and tune detections for credential abuse, jump-host misuse, remote access anomalies, engineering-workstation activity, and OT-hosting hypervisors.

If your detections map to one matrix and your OT monitoring is isolated, a dual-matrix detection coverage review will show the exact path an attacker would take from email to controllers, and where to place the first detection that can stop the campaign early.

Sources: MITRE ATT&CK for Enterprise, MITRE ATT&CK for ICS, CISA and NSA Volt Typhoon advisory AA24-038A, Dragos 2026 OT Cybersecurity Year in Review, NERC CIP Standards.

One attacker path crosses two matrices.
The blind spot is the boundary.
Detect the pivot first.

222Enterprise techniques in ATT&CK October 2025 release
79ICS techniques in ATT&CK for ICS
~75%OT attacks start as IT compromise, synthesis of Dragos Sophos CISA
42Average OT ransomware dwell time in days
5Average dwell time with comprehensive OT visibility
Enterprise Layer

Reconnaissance, initial access, credential theft, and movement.

Click to explore

Enterprise ATT&CK captures the travel path through IT, which is where most OT campaigns start and stage.

ICS Layer

Controller impact, safety effects, and process disruption.

Click to explore

ICS ATT&CK captures what adversaries do when they reach operational systems and physical process control.

Credential Bridge

Valid credentials often move cleanly across the seam.

Click to explore

Identity misuse is the connective thread from domain compromise to engineering access, often with low noise.

Virtualization Risk

ESXi layers can centralize OT operational consequence.

Click to explore

Compromise of OT-hosting hypervisors can remove visibility and control in one move without direct controller access.

Detection Ownership

Boundary detections fail when no team owns the seam.

Click to explore

Pivot-focused detections need explicit ownership across SOC, OT monitoring, and identity telemetry workflows.

Pivot Detection PriorityOwn detections that cross IT and OT boundaries

Start with domain controller credential theft, jump-host abuse, remote access behavior toward control zones, and engineering workstation anomalies.

Coverage Review MethodMap both ATT&CK matrices in one review

Run one detection map that includes Enterprise and ICS techniques together so seams are visible and remediation is prioritized by attack path, not team boundary.

Operational Outcome LensTrack physical consequence, not just host compromise

Industrial incidents should be triaged by potential process impact so teams can detect and interrupt campaigns before controller-level effect.

Travel is primarily Enterprise ATT&CK activity, initial access, credential theft, and lateral movement through IT systems.

Pivot is where identity abuse, remote access misuse, and bastion pathways cross from IT into operational environments.

Impact is where ICS ATT&CK behaviors affect process control, safety posture, and production continuity.

Takeaway 1

Enterprise and ICS ATT&CK are not alternatives. They are two halves of one industrial intrusion.

Takeaway 2

The IT-to-OT pivot is the most important detection target because it links attacker movement to physical consequence.

Takeaway 3

Dual-matrix mapping exposes blind seams and tells teams exactly where to place first-detection controls.

Scroll to Top