Detection of Detect Operating Mode

Technique Detected:  Detect Operating Mode | T0868

ID: DET0768
Domains: ICS
Analytics: AN1900
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1900

Monitor ICS automation network protocols for functions related to reading an asset’s operating mode. In some cases, there may be multiple ways to detect a device’s operating mode, one of which is typically used in the operational environment. Monitor for the operating mode being checked in unexpected ways.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Network Traffic None