Detect Operating Mode

Detect Operating Mode
ID T868
Tactic Collection
Data Sources Network protocol analysis, Packet capture
Asset Field Controller/RTU/PLC/IED


Adversaries may gather information about the current operating state of a PLC. CPU operating modes are often controlled by a key switch on the PLC. Example states may be run, prog, stop, remote, and invalid. Knowledge of these states may be valuable to an adversary to determine if they are able to reprogram the PLC.

Procedure Examples

  • Triton contains a file named which contains default definitions for key state (TS_keystate). Key state is referenced in