Active incident INC-0042 — Ransomware precursor activity, Substation 7 zone
Encryption-rate file writes from HMI-04 to the ops file server, preceded by SMB admin-share access from ENG-WS-02 and an out-of-window Modbus write to PLC-SUB7-01. Recommended action: isolate ENG-WS-02 and HMI-04 at the L2/L3 boundary; PLC last-known-good config snapshot is available (taken 02:00).
Assets monitored
214
+3 discovered this week
Active alerts
7
▲ +4 vs yesterday · 2 critical
OT traffic
12.4K msgs/min
NERC CIP readiness
78%
▲ +2.1 pts this quarter
Protocol traffic — last 24 hours
Messages per minute by control protocol. The 13:40 Modbus spike is INC-0042's unauthorized write burst.
Live sensor feed
Streaming from sub7-span-01
OT network topology — Purdue model view
Passively mapped from mirrored traffic. The dashed red path is INC-0042's observed lateral movement.
Observed attack path (INC-0042)
✕ Compromised
⚠ Suspicious activity
Baseline conversation
Asset inventory
Passively fingerprinted — showing 12 of 214 assets. No device was scanned or touched.
Alerts
Ranked by severity. Each alert carries the protocol evidence and the mapped ATT&CK for ICS technique.
Overall NERC CIP readiness
78%
▲ +2.1 pts this quarter
Evidence items auto-collected
1,847
Asset lists, config snapshots, ESP flow logs
Next audit window
Oct 2026
Regional entity: MRO
Readiness by standard
Continuously assessed from live telemetry and collected evidence. Lowest first-priority gaps: CIP-010 config baselines, CIP-007 patch currency.