detecting-stuxnet-style-attacks - Detect Stuxnet-style attacks in OT environments
Detects PLC logic modifications and physics-inconsistent process behavior associated with Stuxnet-style cyber-physical attacks.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Map Stuxnet attack chains
- Compare PLC logic baselines
- Detect unauthorized PLC blocks
- Identify process model deviations
- Cross-validate sensor readings
- Monitor industrial protocol traffic
Inputs
- Known-good PLC program baselines
- Current PLC program blocks
- Physics-based process models
- Independent sensor measurements
- Engineering workstation telemetry
- Industrial protocol traffic
Outputs
- PLC integrity alerts
- Process anomaly findings
- Attack-chain detection indicators
- Integrity monitoring status messages
Requirements
- PLC logic baseline repository
- OT-aware endpoint monitoring
- Physics-based process models
- Industrial network monitoring
- Stuxnet and MITRE ATT&CK knowledge
