[OOTB] KICS for Networks package - ENG
<html lang="en">
<body>
  
	<p>
	The KICS for Networks rules package is designed for monitoring industrial cybersecurity based on telemetry from the Kaspersky Industrial CyberSecurity for Networks system, as well as for identifying potentially dangerous actions.<br>
	The package enables the detection of attempts to interfere with the technological process, as well as anomalies in the composition of industrial network assets, including the appearance of unknown devices and addresses and the possible impersonation of a legitimate asset by an attacker. It detects unauthorized operations on industrial equipment and control system components, such as modification of PLC projects, modification of user accounts, modification of device configurations, and other actions that may lead to equipment compromise. The package monitors the integrity of the industrial network and detects loss of visibility of the technological process, as well as unauthorized network interactions that may indicate data exfiltration or the presence of a command server. In addition, the package identifies situations indicating a weakening of protection or attempts to access the system, including loss of connection to Kaspersky Security Center, update installation errors, failed login attempts to the KICS for Networks system, and other similar events.<br>
	<br>
	Covered event sources: events from the KICS for Networks system (asset management, network integrity monitoring, intrusion detection, endpoint device protection, external systems), system messages, and application audit messages of KICS for Networks. Asset management data is collected from OVAL scans, Endpoint Agent telemetry, network traffic analysis, and external sources.

</body>
</html>