Unauthorized PLC changes (Microsoft Defender for IoT)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert leverages Defender for IoT to detect unauthorized changes to PLC ladder logic code indicating new functionality in the PLC, improper configuration of an application, or malicious activity on the network.

Attribute Value
Type Analytic Rule
Solution IoTOTThreatMonitoringwithDefenderforIoT
ID c2fb27c7-5f67-49c4-aaf3-d82934234a69
Severity Medium
Status Available
Kind Scheduled
Tactics Persistence
Techniques T0839
Required Connectors IoT
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SecurityAlert ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to IoTOTThreatMonitoringwithDefenderforIoT