Detection of Modify Controller Tasking

ID: DET0741
Domains: ICS
Analytics: AN1874
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1874

Monitor asset application logs for information that indicate task parameters have changed.
Monitor device alarms that indicate controller task parameters have changed, although not all devices produce such alarms.

Program Download may be used to enable this technique. Monitor for program downloads which may be noticeable via operational alarms. Asset management systems should be consulted to understand expected program versions.
Engineering and asset management software will often maintain a copy of the expected program loaded on a controller and may also record any changes made to controller programs and tasks. Data from these platforms can be used to identify modified controller tasking.

Log Sources
Data Component Name Channel
Application Log Content (DC0038) Application Log None
Device Alarm (DC0108) Operational Databases None
Software (DC0111) Asset None