Detection of Program Append

Technique Detected:  Program Append | T0843.003

ID: DET0914
Domains: ICS
Analytics: AN2057
Version: 1.0
Created: 23 April 2026
Last Modified: 24 April 2026

Analytics

AN2057

Monitor device alarms for program downloads, although not all devices produce such alarms.

Monitor for protocol functions related to program download or modification. Program downloads may be observable in ICS automation protocols and remote management protocols.

Consult asset management systems to understand expected program versions.

Monitor devices configuration logs which may contain alerts that indicate whether a program download has occurred. Devices may maintain application logs that indicate whether a full program download, online edit, or program append function has occurred.

Log Sources
Data Component Name Channel
Device Alarm (DC0108) Operational Databases None
Network Traffic Content (DC0085) Traffic None
Asset Inventory (DC0110) Asset None
Application Log Content (DC0038) Application Log None