Modbus/ICS Protocol Integration
Overview
Modbus is a serial communication protocol widely used in industrial control systems. KYRA MDR monitors Modbus traffic for detecting unauthorized access and anomalous commands. Supports Modbus TCP and Modbus RTU over TCP.
Prerequisites
- A KYRA MDR Collector installed and running
- Network tap or span port mirroring Modbus TCP traffic (port 502)
- Suricata or Zeek configured for Modbus protocol parsing
- Network segmentation between IT and OT networks
Configuration
Configure Modbus traffic monitoring:
- Deploy a network sensor on the OT network segment
- Configure Suricata with ICS rulesets:
app-layer: protocols: modbus: enabled: yes detection-ports: dp: 502- Configure Zeek for Modbus logging:
@load policy/protocols/modbus/known-masters-slaves@load policy/protocols/modbus/track-memmap- Forward ICS events to the collector via syslog
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Read Coils | Coil read operations | Process monitoring |
| Write Coils | Coil write operations | Unauthorized control detection |
| Read Registers | Register read operations | Data access monitoring |
| Write Registers | Register write operations | Process manipulation detection |
| Exceptions | Protocol exception events | Error and attack detection |
| Connection | TCP connection events | Network access monitoring |
Troubleshooting
No Modbus traffic: Verify the sensor is on the correct OT network segment. Port 502 by default.
ICS rules not triggering: Load ICS-specific rulesets in Suricata.
Safety warning: Use passive monitoring (IDS mode) only on OT networks. Never deploy inline IPS.
Contact kyra@seekerslab.com for support.