# AN1924 — Detection of Rogue Master (ICS) ## Descrição Analítico para detecção de — na plataforma ICS. **Plataformas:** ICS --- ### Fontes de Log | Fonte | Detalhe | |-------|--------| | Asset Inventory (DC0110) | Asset | | Network Traffic Flow (DC0078) | Network Traffic | | Device Alarm (DC0108) | Operational Databases | | Network Traffic Content (DC0085) | Network Traffic | | Application Log Content (DC0038) | Application Log | ### Data Components Utilizados - [[dc0038-application-log-content|DC0038]] - [[dc0078-network-traffic-flow|DC0078]] - [[dc0085-network-traffic-content|DC0085]] - [[dc0108|DC0108]] - [[dc0110|DC0110]] --- *Fonte: [MITRE ATT&CK — AN1924](https://attack.mitre.org/detectionstrategies/DET0792#AN1924)*