Detection of Modify Program

Technique Detected:  Modify Program | T0889

ID: DET0783
Domains: ICS
Analytics: AN1915
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1915

Monitor device management protocols for functions that modify programs such as online edit and program append events.
Monitor device alarms that indicate the program has changed, although not all devices produce such alarms.
Engineering and asset management software will often maintain a copy of the expected program loaded on a controller and may also record any changes made to controller programs. Data from these platforms can be used to identify modified controller programs.
Monitor device application logs that indicate the program has changed, although not all devices produce such logs.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Network Traffic None
Device Alarm (DC0108) Operational Databases None
Software (DC0111) Asset None
Application Log Content (DC0038) Application Log None