Stuxnet
Associated with: Natanz centrifuge sabotage
Target: Siemens PLC environments
Why it matters: Demonstrated that cyber operations can manipulate physical industrial processes while hiding operator-visible effects.
Operator Notes
- • Stuxnet is the classic example of process-aware malware.
- • It highlights the importance of engineering workstation security and project-file integrity.
- • It also shows that attacker goals may be physical process manipulation, not data theft.
Lessons
- • Protect engineering workflows.
- • Monitor logic changes.
- • Validate controller integrity.
- • Do not assume HMI visibility reflects ground truth.
TRITON / TRISIS
Associated with: XENOTIME
Target: Schneider Triconex safety systems
Why it matters: Targeted safety instrumented systems, making it one of the most serious ICS malware cases.
Operator Notes
- • TRITON is a safety conversation, not just a malware conversation.
- • It shows why SIS networks and SIS engineering stations require special protection.
- • Any pentest near SIS assets needs strict scope and operational control.
Lessons
- • Separate SIS from basic process control.
- • Monitor SIS engineering activity.
- • Limit and review vendor access.
- • Treat safety networks as high-consequence environments.
Industroyer / CRASHOVERRIDE
Associated with: ELECTRUM / Sandworm-linked operations
Target: Electric utility operations
Why it matters: Showed protocol-aware disruptive capability against electric grid environments.
Operator Notes
- • Industroyer is important because it used ICS protocol knowledge.
- • It reinforces the importance of control-center-to-substation communication monitoring.
- • It helps explain why industrial protocol paths need strict allowlisting.
Lessons
- • Monitor telecontrol protocols.
- • Restrict masters and outstations.
- • Prepare manual operation procedures.
- • Detect abnormal command patterns.
PIPEDREAM / INCONTROLLER
Associated with: CHERNOVITE
Target: Multiple industrial vendors and protocols
Why it matters: Represents modular OT capability designed around industrial devices and protocols.
Operator Notes
- • PIPEDREAM is a modern example of reusable OT attack tooling.
- • It makes vendor inventory and protocol exposure extremely important.
- • It validates why engineering workstations and controller access paths are crown jewels.
Lessons
- • Inventory industrial assets.
- • Detect protocol discovery.
- • Restrict engineering access.
- • Monitor controller interaction from unexpected hosts.