Detection of Multicast Discovery

Technique Detected:  Multicast Discovery | T0846.003

ID: DET0909
Domains: ICS
Analytics: AN2052
Version: 1.0
Created: 22 April 2026
Last Modified: 24 April 2026

Analytics

AN2052

Monitor for anomalies related to discovery related ICS functions, including devices that have not previously used these functions or for functions being sent to many outstations.

Monitor for new ICS protocol connections to existing assets or for device scanning (i.e., a host connecting to many devices) over ICS and enterprise protocols (e.g., ICMP, DCOM, WinRM). For added context on adversary enterprise procedures and background see Remote System Discovery.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Traffic None
Network Traffic Flow (DC0078) Network Traffic None