T1059 MicroSCADA SCILC Command Execution
T1059 - MicroSCADA SCILC Command Execution¶
DESCRIPTION¶
Identification of Events or Host Commands that are related to the MicroSCADA SCILC programming language and specifically command execution
Example:
C:\sc\prog\exec\scilc.exe -do pack\scil\s1.txt
Related
SCADA Sandworm
Reference:
https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology
ATT&CK TACTICS¶
T1059 - Command and Scripting Interpreter
Data Source(s): Application Log
SENTINEL RULE QUERY¶
Triage¶
- Evaluate the commandlines
- Analyse the sample files being executed
FalsePositive¶
- Red Team activity
VERSION¶
Version 1.0 (date: 10/11/2023)