Microsoft Sentinel low experimental kql

Cyble Vision Alerts OT/ICS Threat Activity Detected

'This alert indicates detection of OT/ICS-related network activity involving industrial control protocols (e.g., IEC104). May indicate probing, reconnaissance, or attempted access against critical infrastructure assets.'

View Source

Detection Logic

Alerts_ot_ics
| where Service == "ot_ics"
| extend MappedSeverity = Severity

Field Validations

Loading…

Comments (0)

Loading comments...