logo

Threat Hunting With Python Part 4: Examining Microsoft SQL Based Historian Traffic

ID: 3debf532-2e7c-55e0-843e-3356562d4bf1

STIX ID: report--3debf532-2e7c-55e0-843e-3356562d4bf1

Feed Name: Dragos Blog

Date Published: 2018-03-06

Date Updated: 2026-04-27

...
...

The post explains how the Tabular Data Stream (TDS) protocol underpins Microsoft SQL Server communications in ICS historians and demonstrates using Python (pyshark and pandas) to parse PCAPs, enumerate SQL queries and RPC procedure calls, and baseline normal behavior to detect anomalies—flagging suspicious statements like DROP TABLE or CREATE USER and emphasizing ongoing monitoring of TDS traffic for threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.