Home >
ICS >
Participants >
Institute for Information Industry >
Discovery (TA0102)
|
|
TRITON |
||||
Step | ATT&CK Pattern |
|
||
9.A.2
|
Technique Remote System Discovery (T0846) |
|
||
9.B.2
|
Technique Remote System Discovery (T0846) |
|
||
9.C.2
|
|
|||
16.A.2
|
Technique Remote System Discovery (T0846) |
|
||
16.B.2
|
|
Criteria
Evidence that a network discovery scan for TCP port 44818 was initiated from the control EWS (10.0.100.20) on hosts across the whole subnet (10.0.100.1-10.0.100.255).
Criteria
Evidence of the network discovery broadcast request sent from the control EWS (10.0.100.15) over TCP port 44818.
Criteria
Evidence of an adversary initiated Get Attribute Single CIP request for the "Device Type" attribute (instance 0x01, class 0x01) of the control PLC (10.0.100.110).
Criteria
Evidence of the network discovery broadcast request sent from the safety EWS (10.0.100.15) over TCP port 44818.