Detecting Attacks On Scada Systems
Overview
Cybersecurity skill for detecting attacks on scada systems. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"detecting attacks on scada systems"
"This skill covers detecting cyber attacks targeting Supervisory Control and Data"
When deploying intrusion detection capabilities in a SCADA environment for the first time
When investigating suspected cyber attacks against industrial control systems
When building detection rules for OT-specific attack patterns (Stuxnet, TRITON, Industroyer)
When integrating OT network monitoring with an enterprise SOC for unified threat visibility
When responding to alerts from OT security monitoring tools (Dragos, Nozomi, Claroty)
Do not use for detecting attacks on IT-only networks without SCADA/ICS components, for building generic network IDS rules (see building-detection-rules-with-sigma), or for incident response procedures after an attack is confirmed (see performing-ot-incident-response).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Passive network monitoring sensors deployed on SPAN/TAP ports at OT network boundaries
- OT intrusion detection system (Dragos Platform, Nozomi Guardian, Claroty xDome, or Suricata with OT rulesets)
- Understanding of industrial protocols in use (Modbus, DNP3, OPC UA, EtherNet/IP, S7comm)
- Baseline of normal SCADA communication patterns (polling intervals, function codes, register ranges)
- Access to process historian data for physical process anomaly correlation
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Detection Scope — Identify the specific attacks on scada systems techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.
- Collect Baseline Data — Gather historical logs and establish normal behavior patterns for attacks on scada systems.
- Build Detection Queries — Write detection rules, Sigma rules, or SIEM queries targeting attacks on scada systems indicators.
- Execute Hunts — Run queries against the collected data, starting with broad filters and narrowing down.
- Triage Results — Investigate alerts, filter false positives, and validate findings against known-good behavior.
- Document Findings — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.
Tools
- SIEM Platform — Central log aggregation and query execution
- Sigma Rules — Vendor-agnostic detection rule format
- MITRE ATT&CK Navigator — Technique mapping and coverage analysis
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: detecting-attacks-on-scada-systems3description: Use when this skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation, and denial-of-service against control system communications. It leverages OT-specific intrusion detection systems, industrial protocol anomaly detection, and process data analytics to identify attacks that traditional IT security t...4license: Apache-2.05---67# Detecting Attacks On Scada Systems89## Overview1011Cybersecurity skill for detecting attacks on scada systems. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "detecting attacks on scada systems"16- "This skill covers detecting cyber attacks targeting Supervisory Control and Data"171819- When deploying intrusion detection capabilities in a SCADA environment for the first time20- When investigating suspected cyber attacks against industrial control systems21- When building detection rules for OT-specific attack patterns (Stuxnet, TRITON, Industroyer)22- When integrating OT network monitoring with an enterprise SOC for unified threat visibility23- When responding to alerts from OT security monitoring tools (Dragos, Nozomi, Claroty)2425**Do not use** for detecting attacks on IT-only networks without SCADA/ICS components, for building generic network IDS rules (see building-detection-rules-with-sigma), or for incident response procedures after an attack is confirmed (see performing-ot-incident-response).262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Passive network monitoring sensors deployed on SPAN/TAP ports at OT network boundaries38- OT intrusion detection system (Dragos Platform, Nozomi Guardian, Claroty xDome, or Suricata with OT rulesets)39- Understanding of industrial protocols in use (Modbus, DNP3, OPC UA, EtherNet/IP, S7comm)40- Baseline of normal SCADA communication patterns (polling intervals, function codes, register ranges)41- Access to process historian data for physical process anomaly correlation4243## Workflow4445```python46# Example: IOC detection47import re4849IOC_PATTERNS = {50 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",51 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",52 "hash_md5": r"\b[a-f0-9]{32}\b",53 "hash_sha256": r"\b[a-f0-9]{64}\b",54}5556def extract_iocs(text: str) -> dict:57 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}58```59601. **Define Detection Scope** — Identify the specific attacks on scada systems techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.612. **Collect Baseline Data** — Gather historical logs and establish normal behavior patterns for attacks on scada systems.623. **Build Detection Queries** — Write detection rules, Sigma rules, or SIEM queries targeting attacks on scada systems indicators.634. **Execute Hunts** — Run queries against the collected data, starting with broad filters and narrowing down.645. **Triage Results** — Investigate alerts, filter false positives, and validate findings against known-good behavior.656. **Document Findings** — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.6667## Tools6869- **SIEM Platform** — Central log aggregation and query execution70- **Sigma Rules** — Vendor-agnostic detection rule format71- **MITRE ATT&CK Navigator** — Technique mapping and coverage analysis727374## Process75761. **Reconnaissance** — Gather target information, identify attack surface, enumerate services771. **Analysis/Exploitation** — Execute the technique, analyze results, document findings781. **Reporting** — Document IOCs, write findings, provide remediation recommendations7980## Verification8182- [ ] All attacks on scada systems procedures executed completely and documented83- [ ] Findings validated against multiple data sources84- [ ] False positives identified and filtered85- [ ] Results documented with evidence and timestamps86- [ ] Recommendations provided with risk-based prioritization8788## Anti-Rationalization Table8990| Rationalization | Reality |91|---|---|92| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |93| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |94| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |