SCADA Systems Integration
Overview
SCADA systems monitor and control industrial processes. KYRA MDR collects SCADA system logs and network traffic for detecting cyber threats targeting critical infrastructure.
Prerequisites
- A KYRA MDR Collector installed and running
- Network access to the SCADA/OT network (read-only)
- SCADA server with audit logging enabled
- Network IDS sensor on the OT network segment
Configuration
Configure SCADA security monitoring:
- Enable SCADA server audit logging and export to syslog
- Deploy a passive network sensor:
sources: - type: scada protocols: [modbus, dnp3, s7comm, opc-ua] listen_interface: eth1 mode: passive- Configure ICS-specific detection rules
- Ensure all monitoring is passive (read-only)
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Process Events | Control system state changes | Process integrity monitoring |
| Alarms | SCADA alarm and notification events | Operational safety |
| Authentication | Operator login events | Access control |
| Configuration | System configuration changes | Change management |
| Network | ICS protocol communications | Network anomaly detection |
| Historian | Historical data access events | Data integrity auditing |
Troubleshooting
Passive mode only: Never deploy active scanning or inline tools on OT networks.
Protocol support: Verify the collector supports the protocols in use (Modbus, DNP3, S7comm, OPC-UA).
Air-gapped networks: Deploy a local collector with periodic secure data export.
Contact kyra@seekerslab.com for support.