logo

​​Investigating industrial control systems using Microsoft’s ICSpector open-source framework

ID: a013f35b-22d0-5c7d-9a4f-ca2e901cc1d0

STIX ID: report--a013f35b-22d0-5c7d-9a4f-ca2e901cc1d0

Feed Name: Microsoft Security

Date Published: 2024-04-25

Date Updated: 2026-04-28

Author: Maayan Shaul

...
...

The report introduces **ICSpector**, an open-source Python framework from Microsoft that helps ICS/OT defenders and engineers identify, extract, and analyze PLC project configurations and logic to detect anomalous or malicious changes (e.g., timestamp outliers, authorship, task flow, network capabilities, and online vs. offline code diffs). It explains the unique challenges of ICS forensics versus IT, details ICSpector’s modular architecture (input handling, network scanner, protocol plugins, analyzer, output), current protocol support (Siemens S7Comm, Rockwell RSLogix/CIP, Codesys V3), and safe-use considerations, and positions it as a complement to solutions like **Microsoft Defender for IoT**, while inviting community contributions to expand protocols and analytics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.