Threat Hunting With Python Part 4: Examining Microsoft SQL Based Historian Traffic
ID: 3debf532-2e7c-55e0-843e-3356562d4bf1
STIX ID: report--3debf532-2e7c-55e0-843e-3356562d4bf1
Feed Name: Dragos Blog
The post explains how the Tabular Data Stream (TDS) protocol underpins Microsoft SQL Server communications in ICS historians and demonstrates using Python (pyshark and pandas) to parse PCAPs, enumerate SQL queries and RPC procedure calls, and baseline normal behavior to detect anomalies—flagging suspicious statements like DROP TABLE or CREATE USER and emphasizing ongoing monitoring of TDS traffic for threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
