Detection of Broadcast Discovery

Technique Detected:  Broadcast Discovery | T0846.002

ID: DET0908
Domains: ICS
Analytics: AN2051
Version: 1.0
Created: 22 April 2026
Last Modified: 24 April 2026

Analytics

AN2051

Monitor for anomalies related to discovery related ICS functions, including devices that have not previously used these functions or for functions being sent to many outstations.
Monitor for new ICS protocol connections to existing assets or for device scanning (i.e., a host connecting to many devices) over ICS and enterprise protocols (e.g., ICMP, DCOM, WinRM). For added context on adversary enterprise procedures and background see Remote System Discovery.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Traffic None
Network Traffic Flow (DC0078) Network Traffic None