# AN1916 — Detection of Block Command Message (ICS) ## Descrição Analítico para detecção de — na plataforma ICS. **Plataformas:** ICS --- ### Fontes de Log | Fonte | Detalhe | |-------|--------| | Process Termination (DC0033) | Process | | Process History/Live Data (DC0107) | Operational Databases | | Application Log Content (DC0038) | Application Log | | Network Traffic Flow (DC0078) | Network Traffic | | Process/Event Alarm (DC0109) | Operational Databases | ### Data Components Utilizados - [[dc0033-process-termination|DC0033]] - [[dc0038-application-log-content|DC0038]] - [[dc0078-network-traffic-flow|DC0078]] - [[dc0107|DC0107]] - [[dc0109|DC0109]] --- *Fonte: [MITRE ATT&CK — AN1916](https://attack.mitre.org/detectionstrategies/DET0784#AN1916)*