Skip to content

DET0727 Detection of Monitor Process State

Item Value
ID DET0727
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T0801 (Monitor Process State)

Analytics

ICS

AN1860

Monitor ICS automation network protocols for functions related to reading an operational process state (e.g., “Read” function codes in protocols like DNP3 or Modbus). In some cases, there may be multiple ways to monitor an operational process’ state, one of which is typically used in the operational environment. Monitor for the operating mode being checked in unexpected ways. Monitor applications logs for any access attempts to operational databases (e.g., historians) or other sources of operational data within the ICS environment. These devices should be monitored for adversary collection using techniques relevant to the underlying technologies (e.g., Windows, Linux).

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Network Traffic None
Application Log Content (DC0038) Application Log None
Mutable Elements
Field Description