Detection of Change Operating Mode

Technique Detected:  Change Operating Mode | T0858

ID: DET0755
Domains: ICS
Analytics: AN1887
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1887

Monitor ICS management protocols for functions that change an asset’s operating mode.
Monitor device application logs which may contain information related to operating mode changes, although not all devices produce such logs.
Monitor alarms for information about when an operating mode is changed, although not all devices produce such logs.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Network Traffic None
Application Log Content (DC0038) Application Log None
Device Alarm (DC0108) Operational Databases None