detecting-stuxnet-style-attacks - Detect Stuxnet-style attacks in OT environments
Detects PLC logic modifications and process anomalies associated with Stuxnet-style cyber-physical attacks in ICS/SCADA environments.
Tags
Updated: 2026-10-06Capabilities
What this skill does
- Map attack-chain detection points
- Monitor PLC logic integrity
- Compare PLC logic baselines
- Detect unauthorized program blocks
- Detect modified PLC blocks
- Detect process-model deviations
- Cross-validate sensor readings
- Analyze industrial protocol traffic
Inputs
- Known-good PLC baselines
- Current PLC program blocks
- PLC network traffic
- Engineering workstation telemetry
- Physics-based process models
- Independent sensor measurements
Outputs
- PLC integrity alerts
- Process anomaly findings
- Attack-chain detection findings
- Sensor discrepancy findings
Requirements
- Stuxnet attack-chain knowledge
- MITRE ATT&CK for ICS knowledge
- PLC baseline repository
- OT-aware EDR monitoring
- Physics-based process models
- Industrial protocol monitoring
