The industrial malware detection engine
Understanding OT/IoT-based industrial malware is a must. The MDIoT detection engine contains this information to aid in better detection and alerting. Malicious activity on the network will be discovered by this engine.
In Figure 8.4, we can see the Suspicion of Malicious Activity pane in the MDIoT Alerts section. From the name itself, we understand that this attack could lead to exploitation by known malware – hence, further action is required from the Security Operations Center (SOC) or the admin team:
Figure 8.4 – The industrial malware detection engine
To gather further information about the malware, we can look into the full details of the Suspicion of Malware Activity alert:
Figure 8.5 – Industrial malware detection engine: Triton malware
We can see that the name of the known malware is Triton malware. The lateral movement attempted by Triton malware is shown in the...