{ "Activate Firmware Update Mode": { "Activate Firmware Update Mode": 22.545005790551066, "Alarm Suppression": 4.556440346126435, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.515444027372189, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 5.064620754994866, "Device Restart/Shutdown": 1.41092616962108, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.6722948035851806, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.8891781772417948, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 8.389244977793615, "Loss of Safety": 3.477545192754817, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.4898709127081236, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 13.455421290384386, "Monitor Process State": 16.566171219384756, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.225028161982792, "Supply Chain Compromise": 0.0, "System Firmware": 8.22861810240404, "Theft of Operational Information": 2.668381532206034, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Alarm Suppression": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 13.27034216569488, "Automated Collection": 0.0, "Block Command Message": 4.822129959920033, "Block Reporting Message": 10.17259855267286, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.3076689209738057, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.5499095476708231, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.7509205242287749, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 7.775286307746707, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 6.6773713342841186, "Modify Controller Tasking": 3.3514292315257106, "Modify Parameter": 5.11318659394686, "Modify Program": 5.4782506496223355, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.1063333297390985, "Remote System Information Discovery": 1.8127390504933134, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 8.12116964403938, "Standard Application Layer Protocol": 5.871891313856656, "Supply Chain Compromise": 0.0, "System Firmware": 2.656906443985061, "Theft of Operational Information": 2.473098645482918, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 3.8655370056767993, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Automated Collection": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 12.111617453775162, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.3787740049464423, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 5.905061708217536, "Default Credentials": 0.0, "Denial of Control": 3.5757280790273747, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 2.0799538968103266, "Drive-by Compromise": 0.0, "Execution through API": 5.93305312495563, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 3.2342657372400963, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.784981663908315, "Lateral Tool Transfer": 7.448307237799622, "Loss of Availability": 0.0, "Loss of Control": 3.0615874074898715, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 5.126514647429736, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.989683263728816, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 13.048207067652804, "Network Connection Enumeration": 16.458577508469656, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 3.303328679738827, "Remote Services": 0.0, "Remote System Discovery": 3.3502946708481627, "Remote System Information Discovery": 9.100682493849718, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 6.059637512020954, "Supply Chain Compromise": 0.0, "System Firmware": 4.22602603991832, "Theft of Operational Information": 4.61081406519792, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 6.318321596111072, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Block Command Message": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 18.988020770642457, "Block Reporting Message": 12.53588663070323, "Block Serial COM": 14.046305931225127, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.981328146895957, "Commonly Used Port": 7.765250589719992, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 3.3899031850598047, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.9718620050920548, "Drive-by Compromise": 0.0, "Execution through API": 5.624721802360002, "Exploit Public-Facing Application": 2.337141840233984, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.6402506018813177, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.9024815854599137, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.834314185543726, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 2.7385144845505054, "Native API": 0.0, "Network Connection Enumeration": 1.824547755149581, "Network Sniffing": 2.073870339715981, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 3.1316599487598564, "Remote Services": 0.0, "Remote System Discovery": 3.176185192103958, "Remote System Information Discovery": 2.733468083154064, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 5.1426586666105525, "Standard Application Layer Protocol": 3.109623017377284, "Supply Chain Compromise": 0.0, "System Firmware": 4.006406196514115, "Theft of Operational Information": 3.729238475929241, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 9.706804070158508, "User Execution": 5.98996848460442, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Block Reporting Message": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 12.124051442668794, "Block Reporting Message": 18.364216859930103, "Block Serial COM": 12.034782157444875, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 6.6532154221063164, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.904446661405229, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.6894783434177634, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 2.002447693791088, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.2621492789836273, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.4868270538913575, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.4284216758334134, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 9.12369522358157, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.6831855620300167, "Remote Services": 0.0, "Remote System Discovery": 2.7213344964742165, "Remote System Information Discovery": 2.3420174013124533, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 10.492365473218367, "Standard Application Layer Protocol": 2.664304464757441, "Supply Chain Compromise": 0.0, "System Firmware": 3.432662370118206, "Theft of Operational Information": 3.195186897588499, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 4.994185418054849, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Block Serial COM": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 15.974024902404954, "Block Reporting Message": 10.546047301685324, "Block Serial COM": 19.05528230667441, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.349366199424585, "Commonly Used Port": 6.532661186329899, "Connection Proxy": 5.855120160715865, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.851818973076415, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.6588655107301582, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.9661639518570548, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.2211598234740526, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.4417665055745443, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.3844194151670512, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 2.3038261386063534, "Native API": 0.0, "Network Connection Enumeration": 5.940725565184633, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.6345670573890776, "Remote Services": 0.0, "Remote System Discovery": 2.672024744767637, "Remote System Information Discovery": 2.299580759767348, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 4.326357054128404, "Standard Application Layer Protocol": 2.6160280798447695, "Supply Chain Compromise": 0.0, "System Firmware": 3.370463574129565, "Theft of Operational Information": 3.137291084787709, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 8.166029088150797, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Brute Force I/O": { "Activate Firmware Update Mode": 4.033963187837769, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 16.621178539033167, "Change Operating Mode": 10.66450312006727, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 8.321080429274257, "Data Destruction": 0.0, "Data from Information Repositories": 3.942328559117214, "Default Credentials": 6.266329754367496, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 4.984535875865361, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.6458514559600026, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 8.88924561513341, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 6.564642482684624, "Monitor Process State": 7.49894597198586, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 5.855763534328214, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 4.150833648839812, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.1898446566361374, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 3.078264862958731, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Change Operating Mode": { "Activate Firmware Update Mode": 3.575571191072747, "Alarm Suppression": 3.9748155781032533, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 6.87652542480563, "Change Operating Mode": 14.615554578598372, "Command-Line Interface": 9.916520430895325, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.1159546690072895, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 9.159013670109678, "Device Restart/Shutdown": 1.2308229434696967, "Drive-by Compromise": 0.0, "Execution through API": 9.964329164476121, "Exploit Public-Facing Application": 1.4588281490664878, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.783863476286057, "External Remote Services": 2.7913102299651835, "Graphical User Interface": 3.4939500107354684, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.6480265905592582, "Lateral Tool Transfer": 5.4832819915235085, "Loss of Availability": 0.0, "Loss of Control": 1.8117093991146638, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.0336402445103725, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.7691597685640204, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.044392599410265, "Modify Controller Tasking": 4.13601899600015, "Modify Parameter": 0.0, "Modify Program": 5.092626664086755, "Module Firmware": 0.0, "Monitor Process State": 14.451517068212071, "Native API": 5.039258584669765, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 11.454036180673466, "Program Download": 11.691809244505235, "Program Upload": 13.338557717322836, "Project File Infection": 0.0, "Remote Services": 3.9214527469788796, "Remote System Discovery": 5.406681934565626, "Remote System Information Discovery": 4.65306385176834, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 6.684022046010203, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 5.5268259685128385, "Supply Chain Compromise": 0.0, "System Firmware": 2.500771684222663, "Theft of Operational Information": 2.3277654653269675, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 9.356740296943617, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Command-Line Interface": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.667304376740755, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.636901349214971, "Command-Line Interface": 17.490357264851998, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.5698693327532816, "Denial of Service": 3.9657795181312268, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.4948591209450919, "Drive-by Compromise": 0.0, "Execution through API": 4.264074599197948, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 2.3244609624702885, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.0015613078455776, "Lateral Tool Transfer": 5.353085002076584, "Loss of Availability": 0.0, "Loss of Control": 2.200357357764176, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.148679979097372, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 5.023277924234768, "Modify Parameter": 7.491131782440454, "Modify Program": 0.0, "Module Firmware": 7.066905112732007, "Monitor Process State": 2.076054685621603, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.374096374905081, "Remote Services": 0.0, "Remote System Discovery": 2.407850748159066, "Remote System Information Discovery": 2.072229032946142, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.5479687255175785, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 7.741710338543515, "System Firmware": 3.037237306466822, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.9398006476803804, "User Execution": 4.540966355790476, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Commonly Used Port": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 4.778109627660424, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.932428854688377, "Commonly Used Port": 7.669876572899037, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 5.529427274470679, "Default Credentials": 8.78902256243848, "Denial of Control": 3.348267866320534, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.9476432889193633, "Drive-by Compromise": 8.910529950803092, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.607822632892303, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.866832854700261, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 4.80040536664061, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.799502697403758, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.8021383755320526, "Network Sniffing": 2.048398741294366, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 3.1371747910308465, "Remote System Information Discovery": 8.521767338648223, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 5.6741701590936175, "Supply Chain Compromise": 6.133365648107535, "System Firmware": 3.957198891796381, "Theft of Operational Information": 4.317509673800551, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 3.83024923351677, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 8.07600170964988, "Wireless Sniffing": 0.0 }, "Connection Proxy": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.2274850324859257, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 2.6562503288642647, "Commonly Used Port": 0.0, "Connection Proxy": 16.57766392689203, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 5.93674925460862, "Denial of Control": 2.26166523278254, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 7.897412453182653, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 5.974443149423247, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 7.574121370290069, "Loss of Control": 14.118746315080383, "Loss of Productivity and Revenue": 6.590327211432637, "Loss of Protection": 9.774436838481611, "Loss of Safety": 11.593378768818443, "Loss of View": 9.175803925748534, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.890989064371618, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 5.92865149977621, "Network Sniffing": 1.3836384665221053, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.1190775162900484, "Remote System Information Discovery": 1.8237068704017323, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.6729818252613757, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.5872307324851165, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Damage to Property": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 1.510362722020923, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 13.932693764165757, "Data Destruction": 6.451021365474071, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 1.598404150955352, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 7.753018324619335, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.1029462499195444, "External Remote Services": 2.1085715698596177, "Graphical User Interface": 1.4457653561574597, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.2449286281121363, "Lateral Tool Transfer": 0.0, "Loss of Availability": 5.352917338352756, "Loss of Control": 9.97825071067002, "Loss of Productivity and Revenue": 4.6576328884659395, "Loss of Protection": 6.907963295990638, "Loss of Safety": 10.4851072219467, "Loss of View": 6.484886830587394, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.3364333174030762, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 3.124372194012277, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 1.2912619271395682, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 2.9622876332634305, "Remote System Discovery": 4.084238180376273, "Remote System Information Discovery": 3.5149508088545875, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 5.645361630745214, "Scripting": 0.0, "Service Stop": 5.049148140981742, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 1.8890971055294101, "Theft of Operational Information": 1.758407227114526, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Data Destruction": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.485027345124752, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.958775361720471, "Command-Line Interface": 5.175833459476724, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 14.053062314286205, "Data from Information Repositories": 3.421140340106453, "Default Credentials": 0.0, "Denial of Control": 2.4421384150290284, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 5.471714919333551, "Device Restart/Shutdown": 1.4205597295506587, "Drive-by Compromise": 7.656993742716953, "Execution through API": 4.052136134133382, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 2.208927644037933, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.9020771591871073, "Lateral Tool Transfer": 5.087019155359536, "Loss of Availability": 0.0, "Loss of Control": 2.0909923947108138, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.041883550917969, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 1.9728679722504292, "Native API": 0.0, "Network Connection Enumeration": 1.3144322771646237, "Network Sniffing": 1.4940481034181354, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.256096014004412, "Remote Services": 0.0, "Remote System Discovery": 2.2881726844203625, "Remote System Information Discovery": 1.9692324670353478, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 5.748901228629568, "Supply Chain Compromise": 0.0, "System Firmware": 2.886276670625579, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.7936829327177035, "User Execution": 4.315265464080679, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Data from Information Repositories": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 8.518163006286974, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 4.153060347617064, "Default Credentials": 0.0, "Denial of Control": 2.514827995481205, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.462842300478182, "Drive-by Compromise": 6.6925500197445045, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.7338281975528436, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.3086426227865875, "External Remote Services": 3.317493145390886, "Graphical User Interface": 4.15258579520124, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.9586919644078566, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.1532302101289926, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.1026596550630177, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 6.915546480282429, "Monitor Process State": 2.0315898466158977, "Native API": 0.0, "Network Connection Enumeration": 1.3535559935649324, "Network Sniffing": 1.5385180356482229, "Point & Tag Identification": 0.0, "Program Download": 8.590121346221395, "Program Upload": 0.0, "Project File Infection": 2.323248093390485, "Remote Services": 4.660676003841738, "Remote System Discovery": 6.4258820337049825, "Remote System Information Discovery": 9.902912081681366, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.306899811758243, "Supply Chain Compromise": 4.606668359342956, "System Firmware": 2.972185904502556, "Theft of Operational Information": 6.009376022420347, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 6.676847868352135, "Valid Accounts": 0.0, "Wireless Compromise": 6.065749815082839, "Wireless Sniffing": 0.0 }, "Default Credentials": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 6.342371622864489, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 7.590015752897053, "Denial of Control": 2.8914939823798798, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.681943940740187, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.252060991287573, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.475736792517776, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 4.145529505044869, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.4175918792586493, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.428315216893779, "Modify Controller Tasking": 4.310659983099136, "Modify Parameter": 6.576659482859385, "Modify Program": 7.0462105034404585, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.7091984250077203, "Remote System Information Discovery": 2.3315729334989848, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 3.4173540587371236, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Denial of Control": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 5.7851689983070615, "Automated Collection": 0.0, "Block Command Message": 6.249566987082432, "Block Reporting Message": 5.5364747456602625, "Block Serial COM": 20.577796101584394, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 16.46096977253278, "Denial of Service": 12.654234881137905, "Denial of View": 9.368042444269674, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.7914085811155505, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.3986301132085983, "Lateral Tool Transfer": 0.0, "Loss of Availability": 10.31357816934451, "Loss of Control": 19.2253050426296, "Loss of Productivity and Revenue": 8.973959028869597, "Loss of Protection": 13.309717849311408, "Loss of Safety": 15.786546364050254, "Loss of View": 12.494567544956233, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.574934118335288, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.430979334439502, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 9.674149407528379, "Native API": 0.0, "Network Connection Enumeration": 1.6575756806458095, "Network Sniffing": 1.884081702012809, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Denial of Service": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 2.554165803025843, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 4.367168102170103, "Command-Line Interface": 2.1021023137125394, "Commonly Used Port": 4.09997634682149, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 9.566722178034915, "Denial of Service": 10.116383496904124, "Denial of View": 5.444482351575172, "Detect Operating Mode": 4.010203004696305, "Device Restart/Shutdown": 1.041123848697965, "Drive-by Compromise": 0.0, "Execution through API": 2.9697980870902856, "Exploit Public-Facing Application": 4.499526734258558, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.3940264892063121, "Lateral Tool Transfer": 3.728260664620877, "Loss of Availability": 0.0, "Loss of Control": 1.532481883227891, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 2.5660841176929488, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.4964901629283958, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 4.307731750229938, "Module Firmware": 4.921884173740225, "Monitor Process State": 5.622384401984405, "Native API": 0.0, "Network Connection Enumeration": 0.9633433658487089, "Network Sniffing": 1.0949832514699018, "Point & Tag Identification": 0.0, "Program Download": 3.776122474732839, "Program Upload": 3.3099308481551946, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 1.6769947099956335, "Remote System Information Discovery": 1.443244407406466, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 8.821376946697754, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 4.675010612981486, "Supply Chain Compromise": 0.0, "System Firmware": 2.11534327858172, "Theft of Operational Information": 1.9690014335413544, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.047481613372844, "User Execution": 3.1626447622432554, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Denial of View": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 10.435193528770698, "Block Reporting Message": 9.244510148868384, "Block Serial COM": 16.703580558135066, "Brute Force I/O": 0.0, "Change Operating Mode": 5.483344540721716, "Command-Line Interface": 2.3621681095630005, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 13.361835898420487, "Denial of Service": 10.271801250979209, "Denial of View": 19.086016621731076, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.4541371388597877, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 2.261139505387524, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.947036073608659, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.1404166505438926, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 10.576782820912191, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.0901470334907417, "Manipulation of View": 10.433688839278656, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 7.8527813747577655, "Native API": 0.0, "Network Connection Enumeration": 1.3455011788527265, "Network Sniffing": 1.5293625387441792, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.342257640650294, "Remote System Information Discovery": 2.0157787144017907, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 3.792421041779975, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.954498858776471, "Theft of Operational Information": 2.7501032797984375, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 4.298504637860158, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Detect Operating Mode": { "Activate Firmware Update Mode": 3.4321801863088046, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 6.600756369386026, "Change Operating Mode": 14.029427511281135, "Command-Line Interface": 9.51883856347832, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.354215529114441, "Default Credentials": 5.331524315507059, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 15.278246075628433, "Device Restart/Shutdown": 1.1814632945858259, "Drive-by Compromise": 0.0, "Execution through API": 3.3701153197252953, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.6722222979515435, "External Remote Services": 2.679370414731775, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.5819358386010822, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 7.563155946360182, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 3.970152372776439, "Modify Parameter": 0.0, "Modify Program": 4.888397237450178, "Module Firmware": 0.0, "Monitor Process State": 13.871968391360667, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 10.99469537362983, "Program Download": 11.222933032708992, "Program Upload": 12.803642009878919, "Project File Infection": 1.8763692748426228, "Remote Services": 3.764190866435837, "Remote System Discovery": 5.189857960546575, "Remote System Information Discovery": 7.998078214030666, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 6.415972946768466, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.400483325993017, "Theft of Operational Information": 2.6190520782914084, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.588956976710763, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Device Restart/Shutdown": { "Activate Firmware Update Mode": 6.484428726713198, "Alarm Suppression": 5.255804832109902, "Automated Collection": 0.0, "Block Command Message": 3.9926801529056726, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 5.929780596214541, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.797876921676171, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 25.56629530695901, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 7.033674582934212, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 2.5306950821756704, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.179146666784537, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.3955805815749542, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.3393182092816263, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.025528485639957, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 7.6939050832614635, "Monitor Process State": 8.788929280634656, "Native API": 0.0, "Network Connection Enumeration": 1.5059014307923424, "Network Sniffing": 1.7116813210515618, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.6214834946091488, "Remote System Information Discovery": 2.2560842739407714, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 13.894316861288347, "Supply Chain Compromise": 0.0, "System Firmware": 3.3067113791007854, "Theft of Operational Information": 3.077949338852628, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 3.2006298069876418, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Drive-by Compromise": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 1.713865685285904, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 4.561000532247069, "Execution through API": 0.0, "Exploit Public-Facing Application": 3.1269320815588206, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 2.8300044028415834, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.4674352982756977, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.4329712557371337, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 1.3845368871933503, "Native API": 0.0, "Network Connection Enumeration": 0.9224540106330876, "Network Sniffing": 1.048506407686311, "Point & Tag Identification": 0.0, "Program Download": 5.8542032433966655, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 1.6058142412005656, "Remote System Information Discovery": 1.381985529908087, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 3.1394635492991165, "System Firmware": 2.0255569928322945, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 6.4334203410648705, "Unauthorized Command Message": 0.0, "User Execution": 60.0, "Valid Accounts": 0.0, "Wireless Compromise": 4.1338335990690975, "Wireless Sniffing": 0.0 }, "Execution through API": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 8.74930103025296, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 3.988815664443926, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 2.3202415009071222, "Drive-by Compromise": 0.0, "Execution through API": 18.78389591190287, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 3.1067179160917267, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 3.4152786619002797, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 3.3350677597752663, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 9.600181567407711, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 9.499576656405697, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 22.04039270938281, "Program Upload": 7.376489289556512, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 6.759679845503197, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 7.04824852409289, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Exploit Public-Facing Application": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 6.3797349401207795, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.785059354296072, "Denial of Service": 4.297857172455507, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 7.001452079793352, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.6641734954327396, "External Remote Services": 3.673975052761432, "Graphical User Interface": 4.598802754790091, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 8.028837739931106, "Lateral Tool Transfer": 5.801329767767882, "Loss of Availability": 0.0, "Loss of Control": 2.3846060046445294, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.328601380196451, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.4990026308817996, "Network Sniffing": 1.7038398071894394, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 5.161489901164765, "Remote System Discovery": 7.1163765075506475, "Remote System Information Discovery": 6.124450205062347, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.928796449147999, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 7.27451234595428, "Supply Chain Compromise": 0.0, "System Firmware": 3.291562751375311, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 4.938991774301132, "Unauthorized Command Message": 0.0, "User Execution": 7.3943099275096635, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Exploitation for Evasion": { "Activate Firmware Update Mode": 4.31995805845521, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 6.313423030103743, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.5874868536231626, "Denial of Service": 3.992966582677878, "Denial of View": 0.0, "Detect Operating Mode": 5.797374273882423, "Device Restart/Shutdown": 1.5051070006427596, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 4.720845818122701, "Exploitation for Evasion": 21.553298824114037, "Exploitation for Privilege Escalation": 6.74581968245865, "Exploitation of Remote Services": 9.108881432033881, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.0152828413351953, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.215441720683933, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.163410072138284, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 6.227498507762156, "Module Firmware": 7.238233373815689, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 5.458974337311199, "Program Upload": 4.785021587424086, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.424357564387657, "Remote System Information Discovery": 2.086435023021127, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.579146938711604, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 11.835945991266303, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Exploitation for Privilege Escalation": { "Activate Firmware Update Mode": 3.632461261015923, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.308677600786337, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.593019452326823, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 3.3575086220386066, "Denial of View": 0.0, "Detect Operating Mode": 4.8747550741311345, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 5.790058509602348, "Execution through API": 10.245692543660097, "Exploit Public-Facing Application": 3.969550009865571, "Exploitation for Evasion": 6.525698878813886, "Exploitation for Privilege Escalation": 20.849999643038007, "Exploitation of Remote Services": 7.659254669912759, "External Remote Services": 0.0, "Graphical User Interface": 3.5926088933851066, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.1193013318083462, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 5.236427478319008, "Module Firmware": 6.086309629121757, "Monitor Process State": 1.757629609747642, "Native API": 5.181552441141244, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 4.590209566121091, "Program Upload": 4.0235125698554555, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.038534822867746, "Remote System Information Discovery": 5.537440732303967, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 3.8504017025844965, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 3.98545834640588, "System Firmware": 9.9523223880849, "Theft of Operational Information": 2.8055159193787627, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 9.620947151679063, "Valid Accounts": 0.0, "Wireless Compromise": 5.247782419305705, "Wireless Sniffing": 0.0 }, "Exploitation of Remote Services": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.9785999628229054, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 6.802696531427778, "Command-Line Interface": 3.27442493250781, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 4.302410877992992, "Denial of View": 0.0, "Detect Operating Mode": 6.246655368455572, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 7.008870323310265, "Exploitation for Evasion": 8.362223601876638, "Exploitation for Privilege Escalation": 7.268602774863421, "Exploitation of Remote Services": 13.482851322659767, "External Remote Services": 3.6778677369226376, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 7.943328360504824, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 60.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 6.710113087025177, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.5005908680676927, "Network Sniffing": 1.705645075362312, "Point & Tag Identification": 0.0, "Program Download": 5.882030336397389, "Program Upload": 5.155848040019897, "Project File Infection": 0.0, "Remote Services": 5.166958650869907, "Remote System Discovery": 7.1239165168643455, "Remote System Information Discovery": 6.130939239409878, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.934018653326273, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.5574950778018435, "Supply Chain Compromise": 0.0, "System Firmware": 3.2950502585042076, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 4.944224780724977, "Unauthorized Command Message": 3.1893427831487395, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "External Remote Services": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 5.148114609574893, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.5074619335160757, "Denial of Service": 3.8694734598735514, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 6.672947192736556, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.7287497246063794, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.298951436501201, "External Remote Services": 12.063475514148356, "Graphical User Interface": 4.14042265548038, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 7.228573054358796, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.1469232868795705, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.0965008555989577, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 6.57297452217642, "Network Sniffing": 1.5340116363217413, "Point & Tag Identification": 6.1507067121226235, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 4.6470246414800265, "Remote System Discovery": 6.407060291094383, "Remote System Information Discovery": 5.514003042419907, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.437524627697391, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.300142782255116, "Supply Chain Compromise": 4.593175188180279, "System Firmware": 2.963480217440145, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 6.657291033762096, "Valid Accounts": 7.173524970529888, "Wireless Compromise": 6.0479829184667855, "Wireless Sniffing": 0.0 }, "Graphical User Interface": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 12.541994483691788, "Command-Line Interface": 2.557747255636981, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 6.064795411768518, "Device Restart/Shutdown": 1.5745345393417, "Drive-by Compromise": 0.0, "Execution through API": 4.491348141570724, "Exploit Public-Facing Application": 1.866210993105086, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 19.245715035258343, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.1082437586629053, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 6.514760405727289, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 5.710785771248016, "Program Upload": 5.005744945493831, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.5361882704768006, "Remote System Information Discovery": 2.1826780464352513, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 13.879510326610223, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 7.070211378919067, "Supply Chain Compromise": 0.0, "System Firmware": 3.1991208911952187, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 11.969642629229032, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Hooking": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.6404519317347193, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.5956272775987035, "Command-Line Interface": 5.406664295546508, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 12.013265971850966, "Exploit Public-Facing Application": 1.7588028529244362, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 17.796182446873534, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 2.307440978920714, "Hooking": 17.47770513788639, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.9069299143756098, "Modify Controller Tasking": 3.803127287421338, "Modify Parameter": 5.802330324684672, "Modify Program": 6.216596888554215, "Module Firmware": 7.015160381068594, "Monitor Process State": 2.0608535627945086, "Native API": 6.075467066503112, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 11.084713501772173, "Remote Services": 0.0, "Remote System Discovery": 2.390220174539991, "Remote System Information Discovery": 2.0570559220093974, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.3401291869966725, "Supply Chain Compromise": 0.0, "System Firmware": 3.0149982885496174, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.9182750727318663, "User Execution": 4.507716852390517, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "I/O Image": { "Activate Firmware Update Mode": 5.24003427498293, "Alarm Suppression": 0.0, "Automated Collection": 7.658234717027492, "Block Command Message": 4.588127876844558, "Block Reporting Message": 4.064610263801414, "Block Serial COM": 3.846223203655297, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.733799284253772, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.3151649813216733, "Drive-by Compromise": 0.0, "Execution through API": 6.89563558227934, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 3.733372639003706, "Hooking": 0.0, "I/O Image": 12.195803782991351, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.7609574729574826, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 8.692325092095263, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 5.4415984744899335, "Module Firmware": 6.217406042057131, "Monitor Process State": 7.102289594332619, "Native API": 13.635018244376928, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 5.546023210741718, "Program Download": 4.770060785910485, "Program Upload": 4.1811597607086535, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 3.931275507530259, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 7.985390910548467, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 2.915440194724043, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 6.002804607987173, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Indicator Removal on Host": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 6.9169989108063215, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.8343302943958917, "Drive-by Compromise": 0.0, "Execution through API": 14.850121982781403, "Exploit Public-Facing Application": 2.1741329103002935, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 28.93271352703034, "Internet Accessible Device": 2.4561007065003984, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 4.521119981008009, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 6.164026258051914, "Modify Parameter": 0.0, "Modify Program": 7.589685760690093, "Module Firmware": 0.0, "Monitor Process State": 9.905939671055277, "Native API": 7.510149800341203, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 6.653056559422919, "Program Upload": 5.83168509175889, "Project File Infection": 2.91323566300387, "Remote Services": 0.0, "Remote System Discovery": 2.9546553985231516, "Remote System Information Discovery": 2.5428165362208954, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.8927357442843094, "Supply Chain Compromise": 0.0, "System Firmware": 3.726970872679388, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 5.572185388943378, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Internet Accessible Device": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 18.977631830158927, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.725668675296424, "Denial of Service": 4.206206466583871, "Denial of View": 0.0, "Detect Operating Mode": 8.704721613289877, "Device Restart/Shutdown": 1.5854855451253222, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 6.852147903434955, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.5860359320337474, "External Remote Services": 3.5956284736572246, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 18.601314115034157, "Lateral Tool Transfer": 5.67761789301838, "Loss of Availability": 0.0, "Loss of Control": 2.3337548909890824, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 9.427159927424917, "Loss of Safety": 3.9077860729690426, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.2789445508452, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.4670367828531028, "Network Sniffing": 1.6675058587227696, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 5.051422448057474, "Remote System Discovery": 6.964621597139625, "Remote System Information Discovery": 5.993847869561989, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.823691124439421, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 7.119385229201414, "Supply Chain Compromise": 0.0, "System Firmware": 3.2213710168714917, "Theft of Operational Information": 2.9985129195868714, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Lateral Tool Transfer": { "Activate Firmware Update Mode": 6.959908529048656, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 6.094034631580795, "Block Reporting Message": 5.39868904624337, "Block Serial COM": 5.108623393466743, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 3.003035158699749, "Denial of Service": 4.634233800455554, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 4.98280818308801, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.950954157363536, "External Remote Services": 3.9615228446062947, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 14.0374385112152, "Loss of Availability": 0.0, "Loss of Control": 2.571239877005791, "Loss of Productivity and Revenue": 50.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.51085198760303, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.6163237586221002, "Network Sniffing": 1.8371927470376441, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.7742635756282787, "Remote Services": 5.5654597165269974, "Remote System Discovery": 7.673347723004276, "Remote System Information Discovery": 6.603787192232644, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 5.314554249637164, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 5.089118662100449, "Supply Chain Compromise": 0.0, "System Firmware": 3.5491806141219238, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 5.306371591391977, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Loss of Availability": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 10.294962545508257, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 4.888544815485925, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 27.104161589277975, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 31.807249780374786, "Loss of Control": 17.06326928152042, "Loss of Productivity and Revenue": 9.230829584472906, "Loss of Protection": 13.690695142374285, "Loss of Safety": 16.238420383370553, "Loss of View": 12.852211980034545, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 11.523750493080378, "Remote Services": 0.0, "Remote System Discovery": 2.9681141469316086, "Remote System Information Discovery": 2.5543993177618383, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 5.606198940832143, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 3.7439475946775302, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Loss of Control": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.2401680283140886, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 2.6666885528995268, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 7.91440875646371, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.270552862135848, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 9.692507728294618, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 12.247601103805108, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 7.603885272763507, "Loss of Control": 14.174228524543993, "Loss of Productivity and Revenue": 6.616225113882228, "Loss of Protection": 9.812847285128864, "Loss of Safety": 11.638937082204636, "Loss of View": 9.211861934302853, "Man in the Middle": 0.0, "Manipulate I/O Image": 8.72924263844351, "Manipulation of Control": 1.8984200535700575, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 10.357265001930235, "Remote Services": 0.0, "Remote System Discovery": 2.127404820995769, "Remote System Information Discovery": 1.8308734618487212, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.683485798787919, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.5973977313267285, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Loss of Productivity and Revenue": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 4.557331973392203, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 4.88804089679467, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 1.4023227242831002, "Denial of Service": 2.1640410533300103, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 6.801930395325079, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.092209191441845, "Lateral Tool Transfer": 0.0, "Loss of Availability": 14.080303426943427, "Loss of Control": 8.754186300006312, "Loss of Productivity and Revenue": 16.18218999827134, "Loss of Protection": 6.060541010664486, "Loss of Safety": 7.188357615036351, "Loss of View": 5.6893647088576245, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.1724887034128657, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 1.132858634249121, "Native API": 0.0, "Network Connection Enumeration": 0.7547722276737637, "Network Sniffing": 0.8579110805930363, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 6.396780412311681, "Remote Services": 0.0, "Remote System Discovery": 1.3139126483166175, "Remote System Information Discovery": 1.1307710574164629, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 2.481729250525454, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 4.224485733259359, "System Firmware": 1.6573554303384184, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Loss of Protection": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 7.705474899647596, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 11.815783966808786, "Denial of Service": 9.083286567373104, "Denial of View": 6.72443769978166, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 9.436633526669807, "Drive-by Compromise": 5.882959930406294, "Execution through API": 3.6679744607477116, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 7.403148979540311, "Loss of Control": 13.800040594130708, "Loss of Productivity and Revenue": 6.4415622334139835, "Loss of Protection": 17.19955095813555, "Loss of Safety": 11.331678752662448, "Loss of View": 8.968676384804976, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.8483033315438533, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 6.0789807652295975, "Monitor Process State": 1.7858307561992444, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.071243090165676, "Remote System Information Discovery": 1.782539914075628, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 4.049404978779632, "System Firmware": 2.6126439892599325, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.9061578855320715, "Valid Accounts": 0.0, "Wireless Compromise": 5.331983026607849, "Wireless Sniffing": 0.0 }, "Loss of Safety": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 7.0641437868488355, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.0266216197981057, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 8.651217084522935, "Drive-by Compromise": 5.393317787922572, "Execution through API": 3.3626868343177887, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 6.786980627154822, "Loss of Control": 12.65145526925908, "Loss of Productivity and Revenue": 5.905427299601299, "Loss of Protection": 8.75862825810283, "Loss of Safety": 13.294100224400623, "Loss of View": 8.222208285030618, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.6944679809851375, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 6.366196438812602, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 1.8988523351255886, "Remote System Information Discovery": 1.6341780906201249, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 3.712370670701831, "System Firmware": 2.3951921256433635, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.5810461155085895, "Valid Accounts": 0.0, "Wireless Compromise": 4.8881990090861125, "Wireless Sniffing": 0.0 }, "Loss of View": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 10.951810863266806, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 10.222961192503636, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 12.862188917568698, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 7.985450216485016, "Loss of Control": 12.843862147276782, "Loss of Productivity and Revenue": 6.948229013555718, "Loss of Protection": 10.305258518042846, "Loss of Safety": 12.222981976813571, "Loss of View": 19.76276224194398, "Man in the Middle": 0.0, "Manipulate I/O Image": 9.167278307918911, "Manipulation of Control": 0.0, "Manipulation of View": 9.952156720149889, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 7.490362434084866, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 10.87699525768855, "Remote Services": 0.0, "Remote System Discovery": 2.234158549080504, "Remote System Information Discovery": 1.922747169088075, "Replication Through Removable Media": 0.0, "Rogue Master": 8.308944296851687, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.818143815191664, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Man in the Middle": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 11.367978292099561, "Block Reporting Message": 17.21899808840965, "Block Serial COM": 4.632787087180447, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 6.238311413376671, "Connection Proxy": 14.370233327470917, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.723321222575389, "Denial of Service": 4.202583916673565, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.5841200628160457, "Drive-by Compromise": 0.0, "Execution through API": 12.82450398385696, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.121078421563826, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.3317449697837898, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 21.206069689674806, "Manipulate I/O Image": 10.140769609804671, "Manipulation of Control": 2.276981834453639, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.17075908990634, "Modify Controller Tasking": 4.059946825695331, "Modify Parameter": 6.194153075352867, "Modify Program": 6.636394445116291, "Module Firmware": 7.488883744455049, "Monitor Process State": 2.2000199436300187, "Native API": 6.485734335752498, "Network Connection Enumeration": 1.4657733132615935, "Network Sniffing": 1.6660697373038762, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.81953677253373, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 9.838046588332986, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 4.682740888030284, "User Execution": 4.8121162777081405, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Manipulate I/O Image": { "Activate Firmware Update Mode": 5.175477701992284, "Alarm Suppression": 4.1948646304877775, "Automated Collection": 0.0, "Block Command Message": 3.186715125331411, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 7.257215515627063, "Change Operating Mode": 10.346916971920873, "Command-Line Interface": 2.622696314454621, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 5.00334573251895, "Device Restart/Shutdown": 1.2989623117099918, "Drive-by Compromise": 7.001568526748711, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 3.6873779506823383, "Hooking": 0.0, "I/O Image": 12.04555299153086, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.7392626950856767, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 16.90056448486141, "Manipulation of Control": 12.408572113105139, "Manipulation of View": 9.441548339743134, "Masquerading": 0.0, "Modify Alarm Settings": 6.632912632096938, "Modify Controller Tasking": 3.3291150323226817, "Modify Parameter": 5.079142412692391, "Modify Program": 10.816334485661047, "Module Firmware": 6.140808369999375, "Monitor Process State": 1.8039939388846609, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 5.477696891976707, "Program Download": 4.711294228072187, "Program Upload": 4.129648390531858, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 2.4566324717964982, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 11.763943780367194, "User Execution": 5.928850799006529, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Manipulation of Control": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 7.007447734369704, "Block Reporting Message": 3.727825299408309, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 4.302998708021679, "Command-Line Interface": 4.157687480647819, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 17.09977185203013, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 1.9617416969984633, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.141119290121507, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.580972617312076, "External Remote Services": 2.5878766438555525, "Graphical User Interface": 1.7744061672729898, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.5279167024778892, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.6796701380917076, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 7.3048931643824675, "Manipulation of Control": 12.540969707095254, "Manipulation of View": 8.29426138231252, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 3.834581639614163, "Modify Parameter": 5.718448556129256, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 6.162390099512489, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 10.61925413794333, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 3.635653201477509, "Remote System Discovery": 5.012637344646804, "Remote System Information Discovery": 4.313943729755197, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 6.9286239647518775, "Scripting": 0.0, "Service Stop": 6.196883583270199, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 2.9760637366233396, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.3185128488193394, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 13.707659304514069, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Manipulation of View": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 15.483612918662487, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.6725127080615585, "Default Credentials": 0.0, "Denial of Control": 2.2238390485447597, "Denial of Service": 0.0, "Denial of View": 10.213952137133743, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 11.995621876876662, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 7.44744474890547, "Loss of Control": 13.882611324110181, "Loss of Productivity and Revenue": 6.480104474807636, "Loss of Protection": 17.302462211783343, "Loss of Safety": 11.399480363832938, "Loss of View": 18.4312813795762, "Man in the Middle": 0.0, "Manipulate I/O Image": 16.830508421548444, "Manipulation of Control": 14.21649862666767, "Manipulation of View": 18.684059230232698, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 4.346898675831858, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 6.115353548040807, "Monitor Process State": 6.985712622935717, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.0836361010958515, "Remote System Information Discovery": 5.659953064366048, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.6282764013458384, "Theft of Operational Information": 2.8675861634746087, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Masquerading": { "Activate Firmware Update Mode": 5.447738976332253, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 3.6273603302124062, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 3.9002004462128017, "Exploit Public-Facing Application": 1.6205817760299932, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 5.657292786147951, "Module Firmware": 0.0, "Monitor Process State": 1.8988948769204383, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 4.95913665812105, "Program Upload": 4.3468927490476705, "Project File Infection": 2.1715032242866132, "Remote Services": 0.0, "Remote System Discovery": 2.2023771732676156, "Remote System Information Discovery": 1.8953956857302339, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.1598685107343005, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.156222744179062, "Supply Chain Compromise": 0.0, "System Firmware": 2.7780551259971418, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 4.15346368715562, "Valid Accounts": 6.724677188182227, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Modify Alarm Settings": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 13.580611050665931, "Automated Collection": 0.0, "Block Command Message": 4.9348743690067565, "Block Reporting Message": 10.410440257942161, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.046324348460369, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.799318689147219, "Default Credentials": 0.0, "Denial of Control": 2.300624648689398, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.338243036769455, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.5861474005579146, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.7918581392459494, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.969826367698568, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.2984012483835743, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.923563217418811, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 6.83349244499532, "Modify Controller Tasking": 3.4297877393728533, "Modify Parameter": 5.232736088853931, "Modify Program": 5.606335570073312, "Module Firmware": 0.0, "Monitor Process State": 7.226918089914591, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.1555807180457056, "Remote System Information Discovery": 5.855382177422692, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 8.311047660646265, "Standard Application Layer Protocol": 7.526178584712313, "Supply Chain Compromise": 0.0, "System Firmware": 2.7190265754447216, "Theft of Operational Information": 2.9665993203273704, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 3.955915674258996, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Modify Controller Tasking": { "Activate Firmware Update Mode": 3.723990358755383, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 11.667773160713168, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 7.123427243048877, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 3.7010156511852603, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 8.30575688790244, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.416043591531566, "Modify Controller Tasking": 17.660044653463896, "Modify Parameter": 5.0732963621017655, "Modify Program": 10.803884974804587, "Module Firmware": 6.2396696759019115, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 4.705871567676642, "Program Upload": 4.12489519964825, "Project File Infection": 2.060603687045861, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 7.045935833289782, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 7.5669177156457215, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.941344637227362, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Modify Parameter": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 3.446972235382242, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 8.502189859668812, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 1.8349623654428784, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 4.111311172872254, "Device Restart/Shutdown": 1.0673734238598382, "Drive-by Compromise": 5.753275598078748, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.2651002360280135, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.4141749274394786, "External Remote Services": 2.42063277502292, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.4291737035860672, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.5711199361630026, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 2.6307821053562885, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.534220766314265, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 5.450346482312049, "Modify Controller Tasking": 2.735575065142349, "Modify Parameter": 9.522482889862609, "Modify Program": 8.887916046136096, "Module Firmware": 0.0, "Monitor Process State": 5.76414006547574, "Native API": 0.0, "Network Connection Enumeration": 0.9876318826473224, "Network Sniffing": 1.1225907692463863, "Point & Tag Identification": 0.0, "Program Download": 3.8713288335583527, "Program Upload": 3.393383243072389, "Project File Infection": 0.0, "Remote Services": 3.4006958248990973, "Remote System Discovery": 4.688691122339749, "Remote System Information Discovery": 4.035151214275929, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 1.683246068132644, "Supply Chain Compromise": 0.0, "System Firmware": 2.168676858879334, "Theft of Operational Information": 2.018645336318356, "Transient Cyber Asset": 3.25410085608936, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Modify Program": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 5.3028686934881275, "Block Reporting Message": 4.697797249270798, "Block Serial COM": 4.445389745513905, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.5200420287803753, "Drive-by Compromise": 0.0, "Execution through API": 7.969841083880221, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 6.902962011350694, "Internet Accessible Device": 2.0352802939599863, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.002050890830501, "Modify Controller Tasking": 9.003622790689933, "Modify Parameter": 5.943598107392269, "Modify Program": 12.65724406885029, "Module Firmware": 0.0, "Monitor Process State": 2.1110286126468893, "Native API": 15.759088090843, "Network Connection Enumeration": 1.4064824334473525, "Network Sniffing": 1.5986768194066197, "Point & Tag Identification": 0.0, "Program Download": 5.513143200585004, "Program Upload": 4.8325028841137945, "Project File Infection": 11.920098475622847, "Remote Services": 0.0, "Remote System Discovery": 2.448414225093048, "Remote System Information Discovery": 2.107138511718489, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 3.0884036445457452, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Module Firmware": { "Activate Firmware Update Mode": 3.3869504665416024, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 4.949874695063794, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.0286515950997615, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 4.545280124470435, "Device Restart/Shutdown": 1.1800398959995784, "Drive-by Compromise": 5.398720030648355, "Execution through API": 3.3660550857734064, "Exploit Public-Facing Application": 3.701256060777432, "Exploitation for Evasion": 6.084639938025704, "Exploitation for Privilege Escalation": 5.288884014970983, "Exploitation of Remote Services": 7.141580959453002, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 7.9962772471657155, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.7369593102367793, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 2.9084739910198887, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.6961652529954845, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 4.88250781392878, "Module Firmware": 11.253554071082188, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 4.976203552985413, "Program Download": 4.279966478472351, "Program Upload": 3.751571399221648, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 1.9007543297081695, "Remote System Information Discovery": 1.6358149729715512, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 3.7160891846555453, "System Firmware": 9.279664814944, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.5846330875893964, "Valid Accounts": 0.0, "Wireless Compromise": 4.893095297155424, "Wireless Sniffing": 0.0 }, "Monitor Process State": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 6.865574292241836, "Block Reporting Message": 6.082193976321623, "Block Serial COM": 5.755404351850952, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 5.587175655617008, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 4.850539969196925, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 9.303590534650363, "Monitor Process State": 23.106781129285796, "Native API": 0.0, "Network Connection Enumeration": 1.8209595967223813, "Network Sniffing": 2.069791863109726, "Point & Tag Identification": 10.015109045351432, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 3.169938901410152, "Remote System Information Discovery": 8.610767201361798, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 5.73343020986765, "Supply Chain Compromise": 0.0, "System Firmware": 3.998527191913532, "Theft of Operational Information": 8.084505547139564, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Native API": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 8.032385085904286, "Block Reporting Message": 4.17789081683508, "Block Serial COM": 3.9534173165770863, "Brute Force I/O": 0.0, "Change Operating Mode": 5.670429137335655, "Command-Line Interface": 4.925373936254522, "Commonly Used Port": 0.0, "Connection Proxy": 4.7713694710954035, "Damage to Property": 0.0, "Data Destruction": 3.9937181697551907, "Data from Information Repositories": 3.2555907363241996, "Default Credentials": 0.0, "Denial of Control": 2.323962892601645, "Denial of Service": 3.5863007986100626, "Denial of View": 0.0, "Detect Operating Mode": 5.206937638411796, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 10.943869245920546, "Exploit Public-Facing Application": 1.6022377675528454, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 5.939458843705749, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.9898088921231036, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.331861244954109, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.9430764342203093, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.559142887212242, "Modify Controller Tasking": 8.007189535757286, "Modify Parameter": 5.285818572882631, "Modify Program": 5.66320796212684, "Module Firmware": 0.0, "Monitor Process State": 1.8774005319668792, "Native API": 14.015025749918822, "Network Connection Enumeration": 4.841129783818537, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.177447591722359, "Remote System Information Discovery": 1.8739409495108994, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.11278130763637, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.131815602939491, "Supply Chain Compromise": 0.0, "System Firmware": 2.746609217166725, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.6584961070903543, "User Execution": 10.27655155580866, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Network Connection Enumeration": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 5.773139354853783, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 4.6436356654237905, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.6356388086892826, "Drive-by Compromise": 0.0, "Execution through API": 13.241582447291178, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.1900601248720313, "Lateral Tool Transfer": 5.857216544976761, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 7.732437189399705, "Monitor Process State": 8.832945414472812, "Native API": 6.696663359939574, "Network Connection Enumeration": 20.313722418629347, "Network Sniffing": 1.7202536501385282, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.63461223471717, "Remote System Information Discovery": 7.156615103501585, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 4.765191332582056, "Supply Chain Compromise": 0.0, "System Firmware": 3.323271832141105, "Theft of Operational Information": 3.6258623021661345, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 4.96861590260589, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Network Sniffing": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.9877324592359757, "Block Reporting Message": 3.5327215627328803, "Block Serial COM": 3.342912300262907, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 1.856847219308512, "Commonly Used Port": 4.501421620335966, "Connection Proxy": 14.403781393060855, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.2452000035210133, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.1430644973378086, "Drive-by Compromise": 6.1612599045068, "Execution through API": 3.260583034247113, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 5.022260094393478, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.530521263299266, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 5.403805768206378, "Monitor Process State": 7.2482200491562345, "Native API": 0.0, "Network Connection Enumeration": 5.151208308662384, "Network Sniffing": 12.489540994134444, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 1.841196047537115, "Remote System Information Discovery": 5.001393096364363, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 6.940434832775885, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 7.956047395194051, "Supply Chain Compromise": 0.0, "System Firmware": 2.3224650981272363, "Theft of Operational Information": 2.5339301365457993, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 8.689598858220826, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 9.112041715445041 }, "Point & Tag Identification": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 4.9489389723772845, "Default Credentials": 0.0, "Denial of Control": 2.9967612396490866, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.7431765169105704, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.3340491556069374, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.5658680614939295, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.5056063340272536, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 2.420916944674858, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 16.22199764793839, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 5.210682495017175, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 3.8642504598874403, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Program Download": { "Activate Firmware Update Mode": 3.7025278228958807, "Alarm Suppression": 4.115948049237945, "Automated Collection": 0.0, "Block Command Message": 4.446351188114158, "Block Reporting Message": 3.939010672933496, "Block Serial COM": 3.727371941317049, "Brute Force I/O": 0.0, "Change Operating Mode": 9.788294459021465, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.1910851764177717, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 4.575000292579862, "Device Restart/Shutdown": 1.2745253694383614, "Drive-by Compromise": 0.0, "Execution through API": 6.682555126418233, "Exploit Public-Facing Application": 1.5106262809780193, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 3.6180085461182556, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.7065425293873682, "Lateral Tool Transfer": 5.677975084117594, "Loss of Availability": 0.0, "Loss of Control": 1.8760371696616973, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.141354712220521, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.8319767433552552, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.152488847454048, "Modify Controller Tasking": 4.282875263944052, "Modify Parameter": 0.0, "Modify Program": 5.273448886287051, "Module Firmware": 0.0, "Monitor Process State": 6.882823370173809, "Native API": 5.218185884003872, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 12.106946474972633, "Program Upload": 4.051958700529452, "Project File Infection": 7.970600277785174, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 6.921349421315079, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 5.72306516279511, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 2.4104166691094484, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 5.817313317582835, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Program Upload": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.4536043176597455, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 6.0358421669195295, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 2.1260190080902497, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 2.5198558337800683, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 9.34104807657077, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.8466611513513875, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 5.24005248501073, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 8.796570738626508, "Module Firmware": 0.0, "Monitor Process State": 2.9526071464686727, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 7.711002075496403, "Program Upload": 23.039891641600224, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 6.355070712611013, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 3.3527283480622816, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 4.712930589669976, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 9.703783844371557, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Project File Infection": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 7.190814734920253, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.947076174798973, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 6.603049431933332, "Device Restart/Shutdown": 1.7142753695178476, "Drive-by Compromise": 0.0, "Execution through API": 4.889957827310356, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.2953515836664837, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.523327027745412, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.4640644148553488, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 7.092949073392623, "Module Firmware": 0.0, "Monitor Process State": 2.380779140634455, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 8.723980252650275, "Program Download": 16.284211079503542, "Program Upload": 5.450007638280373, "Project File Infection": 23.526196968861697, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 5.207491909083227, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Remote Services": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.637867102186835, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 5.402825402494579, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 4.380857627708548, "Data from Information Repositories": 3.571178261383781, "Default Credentials": 0.0, "Denial of Control": 2.549241116127535, "Denial of Service": 3.9339463980782647, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.4828599592060816, "Drive-by Compromise": 6.784131444666965, "Execution through API": 4.229847078981439, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.35391837045527, "External Remote Services": 3.3628900043652763, "Graphical User Interface": 2.30580262694295, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.9854948722016625, "Lateral Tool Transfer": 6.606099889026143, "Loss of Availability": 0.0, "Loss of Control": 2.1826951958590852, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.1314326290071093, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.3720781691538042, "Network Sniffing": 1.5595712475865549, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.3550396183269267, "Remote Services": 4.7244530915399245, "Remote System Discovery": 6.513814351176526, "Remote System Information Discovery": 5.605877035380735, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.511462400903562, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 10.321118487500833, "Supply Chain Compromise": 4.6697064018303776, "System Firmware": 3.0128575497597088, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 4.520794461289478, "Unauthorized Command Message": 2.9162030103126115, "User Execution": 4.504516238858998, "Valid Accounts": 7.293049819822962, "Wireless Compromise": 6.148754052578196, "Wireless Sniffing": 0.0 }, "Remote System Discovery": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 6.348817927344988, "Command-Line Interface": 0.0, "Commonly Used Port": 5.960385019174333, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 4.01535232195239, "Denial of View": 0.0, "Detect Operating Mode": 14.139626040346961, "Device Restart/Shutdown": 1.5135450709844445, "Drive-by Compromise": 6.924516806350186, "Execution through API": 4.3173761336424175, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 6.8734573976587665, "Internet Accessible Device": 2.02658110675175, "Lateral Tool Transfer": 5.419999320291382, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.7304725781883064, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 5.086069607418057, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.400470851637238, "Network Sniffing": 1.591843761090889, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.4037729147398426, "Remote Services": 0.0, "Remote System Discovery": 2.4379492224245696, "Remote System Information Discovery": 2.098132188392153, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.60481897661805, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 4.766337551672079, "System Firmware": 3.075203201560947, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 4.597729076280841, "Valid Accounts": 0.0, "Wireless Compromise": 6.275991425352117, "Wireless Sniffing": 0.0 }, "Remote System Information Discovery": { "Activate Firmware Update Mode": 6.032802347213828, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 4.0834420582826185, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 2.965657110368456, "Default Credentials": 0.0, "Denial of Control": 1.7958124616300826, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 3.7496682583597036, "Device Restart/Shutdown": 1.0446004407930372, "Drive-by Compromise": 5.630526385062094, "Execution through API": 5.4770192873888135, "Exploit Public-Facing Application": 1.2381086456353199, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.362667213724757, "External Remote Services": 2.3689872796749127, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.398681517980033, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.5375992517405175, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 2.5746529616110077, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.5014873454223872, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 4.322116423263094, "Module Firmware": 9.961923815451179, "Monitor Process State": 5.641159053234438, "Native API": 4.276822890526281, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 9.922848087352843, "Program Upload": 3.3209835960452008, "Project File Infection": 0.0, "Remote Services": 3.328140160026241, "Remote System Discovery": 4.588655388689589, "Remote System Information Discovery": 7.071566307781471, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 4.690621728759689, "Supply Chain Compromise": 0.0, "System Firmware": 8.214588327872608, "Theft of Operational Information": 4.291232786924068, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Replication Through Removable Media": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.124859433506108, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.236002727617191, "Drive-by Compromise": 6.662208532646156, "Execution through API": 3.5256886495362476, "Exploit Public-Facing Application": 3.8767863715789144, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 6.317771590396945, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 14.501094036545798, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.8193337805703318, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.0464069886883927, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.7766050845391679, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.1436631956035002, "Network Sniffing": 1.2999436015268606, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 9.692675564475534, "Remote Services": 0.0, "Remote System Discovery": 1.9908967010470655, "Remote System Information Discovery": 1.7133927211479647, "Replication Through Removable Media": 11.578409051407409, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.5112959091692044, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.7546326092765514, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Rogue Master": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 10.181273089687487, "Block Reporting Message": 5.4162383855918765, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.3475318803657914, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.850257141499013, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.6579570138859405, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.9650871594745964, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.2199433796592425, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.440429243963954, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.3831135603524447, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 2.3025644216298944, "Native API": 0.0, "Network Connection Enumeration": 1.5340940390394484, "Network Sniffing": 1.7437264203798124, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.670561379574623, "Remote System Information Discovery": 2.298321367821612, "Replication Through Removable Media": 0.0, "Rogue Master": 20.8395911169038, "Rootkit": 0.0, "Screen Capture": 10.06674832191769, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 4.323987674751225, "Standard Application Layer Protocol": 2.6145953818716356, "Supply Chain Compromise": 0.0, "System Firmware": 3.368617700850001, "Theft of Operational Information": 3.1355729111132984, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 8.161556868065208, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Rootkit": { "Activate Firmware Update Mode": 3.444350349547254, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 7.1305211703573335, "Block Reporting Message": 3.708803624114369, "Block Serial COM": 3.5095336652346973, "Brute Force I/O": 0.0, "Change Operating Mode": 5.033762024151136, "Command-Line Interface": 2.422962100402854, "Commonly Used Port": 0.0, "Connection Proxy": 4.2356474025314, "Damage to Property": 7.191058154563039, "Data Destruction": 0.0, "Data from Information Repositories": 3.4069510773229212, "Default Credentials": 0.0, "Denial of Control": 2.063031892469996, "Denial of Service": 3.183636428566415, "Denial of View": 0.0, "Detect Operating Mode": 4.622310642025928, "Device Restart/Shutdown": 1.2000384618603719, "Drive-by Compromise": 11.958570769262735, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 3.406561779617371, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.6068073034652661, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.7663961922278446, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.7249107832422277, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.159527765934605, "Modify Controller Tasking": 3.0755827530404107, "Modify Parameter": 4.692334945787073, "Modify Program": 9.99260508340131, "Module Firmware": 11.44427215020942, "Monitor Process State": 9.276103225104118, "Native API": 0.0, "Network Connection Enumeration": 5.407960889211941, "Network Sniffing": 1.2621188329324435, "Point & Tag Identification": 0.0, "Program Download": 4.352500629048009, "Program Upload": 3.815150645959955, "Project File Infection": 1.905869872371756, "Remote Services": 0.0, "Remote System Discovery": 1.9329671055445814, "Remote System Information Discovery": 5.2506784109719815, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 11.896398769177374, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 3.6510045110529576, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 9.993933797957643, "System Firmware": 9.436930674002559, "Theft of Operational Information": 2.6602292614319687, "Transient Cyber Asset": 3.6585566951428836, "Unauthorized Command Message": 2.3600042291530907, "User Execution": 5.477332890492595, "Valid Accounts": 0.0, "Wireless Compromise": 4.976020365108665, "Wireless Sniffing": 0.0 }, "Screen Capture": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 6.131558874815183, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 5.390390575569681, "Default Credentials": 0.0, "Denial of Control": 3.2640761249228567, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.898670062564025, "Drive-by Compromise": 0.0, "Execution through API": 15.370995136629261, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.5422492864680355, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.7947467313762844, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.729109581753508, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.696286430034408, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 2.6368657919707017, "Native API": 7.773570896606226, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 3.0582909563823266, "Remote System Information Discovery": 8.307488654662562, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 28.265067286531163, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 3.8576956623479512, "Theft of Operational Information": 4.208946478604928, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 5.767631714618628, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Scripting": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 9.51045196328594, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 5.326826960619492, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 3.367146069895049, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 4.227088130668879, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 3.966654458568601, "Modify Parameter": 0.0, "Modify Program": 4.884090300953816, "Module Firmware": 5.580414043678455, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 4.281353673675695, "Program Upload": 3.752787334410902, "Project File Infection": 1.8747160942769028, "Remote Services": 0.0, "Remote System Discovery": 1.9013703899745684, "Remote System Information Discovery": 1.6363451627979153, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 11.137704698768394, "Service Stop": 0.0, "Spearphishing Attachment": 6.255742731516885, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 3.4389856628399156, "Supply Chain Compromise": 0.0, "System Firmware": 2.3983683732296806, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 3.585794915806946, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Service Stop": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 9.310660523207659, "Block Reporting Message": 4.842761232506191, "Block Serial COM": 4.582564972614965, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 3.163776817777633, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 9.389706541804625, "Data Destruction": 15.501219182935683, "Data from Information Repositories": 3.773686124885505, "Default Credentials": 0.0, "Denial of Control": 2.6937988318708266, "Denial of Service": 4.157025455435778, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.5669472772372794, "Drive-by Compromise": 0.0, "Execution through API": 12.685478879486201, "Exploit Public-Facing Application": 1.8572182199438452, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.5441062563147976, "External Remote Services": 3.553586637277529, "Graphical User Interface": 4.448109685615313, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.0980846941410998, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.3064674940858416, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.2522980230887937, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 2.176170444057489, "Native API": 6.415425192094077, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.4885849097301365, "Remote Services": 4.992358760693262, "Remote System Discovery": 6.883187855089069, "Remote System Information Discovery": 5.923764885943662, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 13.276645814422954, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.4710731824695995, "Supply Chain Compromise": 0.0, "System Firmware": 3.1837051806479146, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 3.081569731862623, "User Execution": 11.911964113035815, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Spearphishing Attachment": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 4.634861734955543, "Exploit Public-Facing Application": 1.9258426754402473, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.5805384467743493, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 8.611002317145575, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.562379658907175, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 4.935830908336498, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Spoof Reporting Message": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 5.3319216155794935, "Block Reporting Message": 11.248037394352718, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.485726966166094, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.7137647239097105, "Exploitation for Evasion": 13.250087511452765, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.1283135098299106, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.0783281459611467, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 16.976982637968113, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.329013175463581, "Remote System Information Discovery": 2.0043803479097084, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 19.6868283406389, "Standard Application Layer Protocol": 2.280204881063329, "Supply Chain Compromise": 0.0, "System Firmware": 2.937792431353575, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 4.274198432580683, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Standard Application Layer Protocol": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 12.975929736961561, "Block Reporting Message": 8.566705612731287, "Block Serial COM": 3.9408468093710174, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 2.7207382442820753, "Commonly Used Port": 5.306574458665749, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 3.981019519698338, "Data from Information Repositories": 3.245239077611274, "Default Credentials": 0.0, "Denial of Control": 2.316573489978858, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.3475202675477653, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.5971432025752488, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.0478083596707015, "External Remote Services": 11.145105414979572, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.8042800095811822, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.983481984282575, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.936898119521304, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.547826037072609, "Modify Controller Tasking": 3.453564386442576, "Modify Parameter": 5.2690114879888155, "Modify Program": 5.645200908786208, "Module Firmware": 0.0, "Monitor Process State": 8.544682686437788, "Native API": 0.0, "Network Connection Enumeration": 1.2468494614855465, "Network Sniffing": 1.4172301651012291, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 4.293255242617274, "Remote System Discovery": 3.7487785731825722, "Remote System Information Discovery": 3.226249718083503, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 3.5143619403602098, "Standard Application Layer Protocol": 18.805858222095473, "Supply Chain Compromise": 0.0, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 6.633382652475774, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Supply Chain Compromise": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 1.604049183877913, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 1.697551744667254, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.9874434767752911, "Drive-by Compromise": 4.517585291202495, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 1.5354449006264652, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 4.484273907876756, "Internet Accessible Device": 1.3221504482297852, "Lateral Tool Transfer": 3.536031450630809, "Loss of Availability": 0.0, "Loss of Control": 1.4534670786402206, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 2.4337767558023407, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 10.852063265348129, "Manipulation of View": 7.177263908808007, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.9136733575853585, "Network Sniffing": 1.0385258873805931, "Point & Tag Identification": 5.025118802482032, "Program Download": 5.798478267453553, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 1.5905288204115038, "Remote System Information Discovery": 1.3688306893250028, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 3.996111461382438, "Supply Chain Compromise": 14.295555480153265, "System Firmware": 2.0062761257349147, "Theft of Operational Information": 1.8674796699193197, "Transient Cyber Asset": 9.382600378734091, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 4.09448447361453, "Wireless Sniffing": 0.0 }, "System Firmware": { "Activate Firmware Update Mode": 9.93248770246947, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 5.4641340497385915, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.4490426772247693, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 4.544997173049181, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 4.113412659804131, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 9.819114615823683, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.571491907073263, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.815119863423655, "Modify Controller Tasking": 8.583074300788523, "Modify Parameter": 5.665979723464709, "Modify Program": 6.070511320193785, "Module Firmware": 6.968613568266188, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.3407873152477352, "Network Sniffing": 1.5240045304989762, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 11.096645494252888, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.334051714695485, "Remote System Information Discovery": 2.0087165831551745, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 7.851816216577778, "Supply Chain Compromise": 0.0, "System Firmware": 11.395064177728239, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 4.417695729593444, "Unauthorized Command Message": 0.0, "User Execution": 6.613862278536, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Theft of Operational Information": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 4.951236737010186, "Block Reporting Message": 4.386287435737928, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.81191594004069, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 2.1324097649931155, "Remote Services": 0.0, "Remote System Discovery": 2.162727891880824, "Remote System Information Discovery": 5.874796636803753, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 3.501738930195622, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 0.0, "System Firmware": 2.7280419444514687, "Theft of Operational Information": 20.86788802201844, "Transient Cyber Asset": 4.093428484073266, "Unauthorized Command Message": 3.9690321475899655, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Transient Cyber Asset": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 4.668626401034536, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.273920429166381, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.3227095442245502, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.5677363883988944, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.9916917046747926, "External Remote Services": 10.93990024403076, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.7710593648210173, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.9469618488057463, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.9012356923905036, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 5.960776850322329, "Network Sniffing": 1.391135933824374, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 4.214207253102159, "Remote System Discovery": 5.8103156391254585, "Remote System Information Discovery": 5.000436495983925, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.085910694259389, "Supply Chain Compromise": 0.0, "System Firmware": 2.687465806676571, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 15.196068482451464, "Unauthorized Command Message": 0.0, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "Unauthorized Command Message": { "Activate Firmware Update Mode": 10.620714529032158, "Alarm Suppression": 5.514824109310127, "Automated Collection": 0.0, "Block Command Message": 10.486705836957434, "Block Reporting Message": 5.578722640302212, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 6.4394745959371775, "Command-Line Interface": 3.4479560463602654, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.9357633312932547, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.7076948375496213, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 2.024038723238381, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 0.0, "External Remote Services": 0.0, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 2.286540493719549, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.5136408160272565, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.454605692562509, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 4.223916651107813, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 9.222069814264403, "Native API": 0.0, "Network Connection Enumeration": 1.5801160397054421, "Network Sniffing": 1.7960372803648224, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 0.0, "Remote System Discovery": 2.750676792620825, "Remote System Information Discovery": 2.3672697796065787, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 4.453704992323069, "Standard Application Layer Protocol": 7.668147741752697, "Supply Chain Compromise": 0.0, "System Firmware": 3.4696744301813194, "Theft of Operational Information": 3.2296384213957605, "Transient Cyber Asset": 5.206248449314323, "Unauthorized Command Message": 20.513630110236026, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 0.0, "Wireless Sniffing": 0.0 }, "User Execution": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 0.0, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 0.0, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 4.210930255031686, "Data from Information Repositories": 3.4326572248909586, "Default Credentials": 0.0, "Denial of Control": 0.0, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 0.0, "Drive-by Compromise": 6.520984424093794, "Execution through API": 4.065777195402004, "Exploit Public-Facing Application": 1.689380973909903, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 50.0, "External Remote Services": 0.0, "Graphical User Interface": 4.046132970292571, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 0.0, "Lateral Tool Transfer": 50.0, "Loss of Availability": 0.0, "Loss of Control": 0.0, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 0.0, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.752719102525342, "Modify Controller Tasking": 3.653013679187626, "Modify Parameter": 5.573305978304491, "Modify Program": 5.971220986211467, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 0.0, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 10.647187693605968, "Remote Services": 0.0, "Remote System Discovery": 0.0, "Remote System Information Discovery": 0.0, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 13.44860746560535, "Service Stop": 0.0, "Spearphishing Attachment": 7.553713325806491, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 2.2477617195298456, "Supply Chain Compromise": 4.488574987055225, "System Firmware": 0.0, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 0.0, "User Execution": 10.83547712291382, "Valid Accounts": 0.0, "Wireless Compromise": 5.910252437099461, "Wireless Sniffing": 0.0 }, "Valid Accounts": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.483953366134852, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 2.8673261630637223, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 6.408506109650709, "Denial of Control": 2.44138582255602, "Denial of Service": 3.767505906837534, "Denial of View": 0.0, "Detect Operating Mode": 7.796833169266878, "Device Restart/Shutdown": 1.4201219564279972, "Drive-by Compromise": 6.49710308788924, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 7.2588886341021865, "Exploitation of Remote Services": 3.2120181601645093, "External Remote Services": 3.2206102151468663, "Graphical User Interface": 4.03131510607028, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 6.449195305851567, "Internet Accessible Device": 1.9014909970988827, "Lateral Tool Transfer": 5.08545149142091, "Loss of Availability": 0.0, "Loss of Control": 2.0903480147167506, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 3.5002102796264998, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 2.0412543047697067, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 0.0, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.3140272092814989, "Network Sniffing": 1.493587683423091, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 4.524567222788938, "Remote System Discovery": 6.238222782112353, "Remote System Information Discovery": 5.368699190746225, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 0.0, "Scripting": 0.0, "Service Stop": 4.320587909429228, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 0.0, "Supply Chain Compromise": 4.472136798988227, "System Firmware": 2.8853872083068324, "Theft of Operational Information": 2.6857728516230317, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 2.792822004961031, "User Execution": 6.481859496732373, "Valid Accounts": 6.984489745072725, "Wireless Compromise": 5.888607741095794, "Wireless Sniffing": 0.0 }, "Wireless Compromise": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 0.0, "Automated Collection": 0.0, "Block Command Message": 3.3680108142044745, "Block Reporting Message": 0.0, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 5.002044844332476, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 0.0, "Default Credentials": 0.0, "Denial of Control": 2.360138896215034, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.3728616901795743, "Drive-by Compromise": 13.680781241770163, "Execution through API": 0.0, "Exploit Public-Facing Application": 1.6271790260613286, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 3.1051253452502428, "External Remote Services": 3.11343146506749, "Graphical User Interface": 2.1347586277400223, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.8382112411700982, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 2.020783282420194, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.9733233630027016, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 3.614546338944734, "Modify Controller Tasking": 8.131833573104357, "Modify Parameter": 5.368100347863234, "Modify Program": 5.75136437475868, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 1.270297672189827, "Network Sniffing": 1.4438825498150683, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 4.37399406205439, "Remote System Discovery": 6.030620844641319, "Remote System Information Discovery": 5.190034145808429, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 8.335712566786174, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 0.0, "Standard Application Layer Protocol": 6.1646296737624215, "Supply Chain Compromise": 4.323308471348558, "System Firmware": 2.7893643512013986, "Theft of Operational Information": 0.0, "Transient Cyber Asset": 8.859367284732853, "Unauthorized Command Message": 12.433207334731458, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 15.09447563136574, "Wireless Sniffing": 7.637515145424162 }, "Wireless Sniffing": { "Activate Firmware Update Mode": 0.0, "Alarm Suppression": 3.5676351335119816, "Automated Collection": 0.0, "Block Command Message": 6.784031446365497, "Block Reporting Message": 8.59395620233568, "Block Serial COM": 0.0, "Brute Force I/O": 0.0, "Change Operating Mode": 0.0, "Command-Line Interface": 2.230542422746233, "Commonly Used Port": 0.0, "Connection Proxy": 0.0, "Damage to Property": 0.0, "Data Destruction": 0.0, "Data from Information Repositories": 3.1363878572125623, "Default Credentials": 0.0, "Denial of Control": 1.8991960934377277, "Denial of Service": 0.0, "Denial of View": 0.0, "Detect Operating Mode": 0.0, "Device Restart/Shutdown": 1.1047373368579099, "Drive-by Compromise": 0.0, "Execution through API": 0.0, "Exploit Public-Facing Application": 0.0, "Exploitation for Evasion": 0.0, "Exploitation for Privilege Escalation": 0.0, "Exploitation of Remote Services": 2.4986842659095916, "External Remote Services": 2.5053681735108944, "Graphical User Interface": 0.0, "Hooking": 0.0, "I/O Image": 0.0, "Indicator Removal on Host": 0.0, "Internet Accessible Device": 1.4792026069916049, "Lateral Tool Transfer": 0.0, "Loss of Availability": 0.0, "Loss of Control": 1.6261177347703988, "Loss of Productivity and Revenue": 0.0, "Loss of Protection": 0.0, "Loss of Safety": 0.0, "Loss of View": 0.0, "Man in the Middle": 0.0, "Manipulate I/O Image": 0.0, "Manipulation of Control": 1.587926891978425, "Manipulation of View": 0.0, "Masquerading": 0.0, "Modify Alarm Settings": 2.7325247635873557, "Modify Controller Tasking": 0.0, "Modify Parameter": 0.0, "Modify Program": 0.0, "Module Firmware": 0.0, "Monitor Process State": 0.0, "Native API": 0.0, "Network Connection Enumeration": 0.0, "Network Sniffing": 10.908876821571283, "Point & Tag Identification": 0.0, "Program Download": 0.0, "Program Upload": 0.0, "Project File Infection": 0.0, "Remote Services": 3.5197387953292103, "Remote System Discovery": 4.852820979101986, "Remote System Information Discovery": 7.478671294013392, "Replication Through Removable Media": 0.0, "Rogue Master": 0.0, "Rootkit": 0.0, "Screen Capture": 6.707720790606252, "Scripting": 0.0, "Service Stop": 0.0, "Spearphishing Attachment": 0.0, "Spoof Reporting Message": 6.860879830382601, "Standard Application Layer Protocol": 3.218488552856987, "Supply Chain Compromise": 0.0, "System Firmware": 2.244592421010417, "Theft of Operational Information": 2.44896699823258, "Transient Cyber Asset": 0.0, "Unauthorized Command Message": 5.438245095334555, "User Execution": 0.0, "Valid Accounts": 0.0, "Wireless Compromise": 7.56562603055303, "Wireless Sniffing": 14.952396896080627 } }