Skip to content

Topic

Threat Intelligence

All articles on Threat Intelligence.

Siemens S7 PLC in an industrial cabinet with indicators of anomalous S7comm traffic

Cybersecurity

Advisory AA26-231A: Active Threat to Siemens S7 PLCs, Exploitation Scripts Generated with AI

NSA, CISA, FBI, DOE and EPA warn of actors targeting internet-exposed Siemens S7 PLCs with AI-generated scripts disguised as OT monitoring tools. What the advisory says and what to do.

6 min read
OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read
Diagram of hidden C2 channels in an OT network with APT traffic

Cybersecurity

Covert networks and hidden C2 channels in OT environments: how APTs operate

APT actors targeting industrial environments do not break in and act immediately: they settle quietly, build hidden command channels, and wait. How they work and how to detect them.

4 min read
Network diagram showing an attacker's path from the IT segment to the OT segment through jump servers and industrial networks

Cybersecurity

How Attackers Cross the IT-OT Boundary: Techniques and Detection Signals

The pivot from IT into the OT network is the critical phase of nearly every documented industrial attack. Understanding the techniques used to cross this boundary is the first step to detecting it early.

6 min read
Matrix diagram of the MITRE ATT&CK for ICS framework with techniques highlighted over an industrial SCADA background

Cybersecurity

MITRE ATT&CK for ICS: How to Use It to Build Concrete Detection Rules

MITRE ATT&CK for ICS is not a document to skim once and file away. Turning its techniques into concrete detection rules means knowing what you can really see on your network and what stays out of reach without endpoint visibility.

5 min read
Integration diagram between OT monitoring sensors and a SIEM platform with a SOC, showing normalized data flows and correlation of IT and OT events

Cybersecurity

Integrating OT Monitoring with Existing SIEM and SOC: Data, Formats and Added Value

Many companies already run a SIEM or a managed SOC, but these systems are blind to OT. How to feed OT monitoring events into the SOC, which formats to use and which alerts to escalate.

6 min read
SOC with OT network monitoring sensors and industrial analysis dashboard

Cybersecurity

Building a SOC for OT Environments: Requirements, Tools, and Operational Metrics

An IT SOC cannot see OT environments. Building monitoring capabilities for industrial networks requires different sensors, different skills, and playbooks specific to OT protocols and threats.

4 min read
Industrial network map with indicators of compromise and lateral movement from IT to OT

Cybersecurity

Sandworm and Manufacturing: State APTs Do Not Target Only Large Infrastructure

Sandworm is known for shutting off the lights in Ukraine and launching NotPetya. But its techniques are being replicated against European manufacturing, often as collateral damage. How an APT attack on an industrial OT network works and why SMEs are within range too.

5 min read
Supply chain attack diagram against industrial OT environments

Cybersecurity

Supply Chain Attacks in OT: The Vector That Bypasses the Physical Perimeter

Supply chain attacks are among the hardest to detect and prevent. In industrial OT, the supplier chain is often long, poorly monitored, and holds privileged access to control systems.

3 min read
Industrial plant control room with safety systems highlighted and anomaly indicators on Safety Instrumented Systems

Cybersecurity

Triton/TRISIS: When Attackers Target Industrial Safety Systems

Triton/TRISIS is the first documented malware designed to disable Safety Instrumented Systems — the systems that prevent physical industrial accidents. Its impact goes beyond the targeted plant: it changes the perimeter of what must be monitored.

5 min read
Industrial control room with cybersecurity alarms and network anomaly indicators

Cybersecurity

Sandworm in Industrial Environments: What the Data Really Tells Us

An analysis of over 5 million alerts shows how Sandworm targets OT environments: weeks of ignored signals before the real impact lands.

2 min read
Screen showing malware code and AI symbols highlighting automated payload generation

Cybersecurity

AI in offensive cybersecurity: from payloads to APT operations

Artificial intelligence does not create autonomous threats, but it makes attacks faster and more variable. What changes for those defending OT environments.

2 min read
Stylized map of ransomware attacks focused on industrial plants and OT assets

Cybersecurity

Ransomware landscape, summer 2025: manufacturing in the crosshairs

In spring and summer 2025 ransomware mostly hit manufacturing. Data, active groups and what it means for industrial OT environments.

2 min read
MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna
© 2026 MON5 · All rights reserved