logo

Threat Hunting Part 2: Hunting on ICS Networks

ID: b9da9d69-3fba-5006-9815-8cba2bff5f38

STIX ID: report--b9da9d69-3fba-5006-9815-8cba2bff5f38

Feed Name: Dragos Blog

Date Published: 2017-10-03

Date Updated: 2026-04-27

...
...

This post provides practical guidance for ICS threat hunting using the Purdue Model, mapping Levels 4 to 0 to appropriate data sources, tools, and behavioral baselines. It recommends passive monitoring at the control system level, deep inspection of OT protocols alongside IT telemetry, and focused scrutiny of inter-level activity (e.g., domain trust, RDP, SMB) to detect adversary movement. By leveraging the constrained and role-specific communications of OT environments and automating protocol analytics, defenders can improve visibility and raise attacker costs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.