detecting-stuxnet-style-attacks - Detect Stuxnet-style PLC logic and process manipulation
Detects PLC logic modifications and spoofed sensor readings associated with Stuxnet-style cyber-physical attacks in ICS/SCADA environments.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Map attack-chain detection points
- Monitor PLC logic integrity
- Compare PLC blocks against baselines
- Detect process-model deviations
- Cross-validate sensor readings
- Correlate IT-to-OT indicators
Inputs
- Known-good PLC logic baselines
- Current PLC program blocks
- PLC names and IP addresses
- Physics-based process models
- Industrial protocol traffic
- Engineering workstation telemetry
Outputs
- PLC integrity alerts
- Process anomaly findings
- Attack-chain detection indicators
- Unauthorized block modification alerts
Requirements
- PLC logic baseline repository
- OT-aware endpoint monitoring
- Industrial network monitoring
- ICS/SCADA environment access
- Physics-based process models
