- Add validated mitre_attack frontmatter to all 754 skills (286 distinct
techniques), verified against MITRE ATT&CK v19.1 via the official
mitreattack-python library: 0 revoked, deprecated, or invalid IDs
- Curate precise per-skill technique IDs for forensics, malware-analysis,
threat-intel, and red-team skills (e.g. DCSync -> T1003.006,
Kerberoasting -> T1558.003, Pass-the-Ticket -> T1550.003)
- Reconcile v19.1 tactic restructuring: Defense Evasion split into
Stealth (TA0005) and Defense Impairment (TA0112); revoked T1562.*
family and T1070.001/.002 remapped to active equivalents (T1685.*)
- Normalize word-split tags across 35 skills (remove filename-derived
stopword tags, add semantic cybersecurity tags)
- Add api-reference.md for 3 skills that were missing it
- Update README ATT&CK section with accurate v19.1 tactic distribution
Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like VOLTZITE, GRAPHITE, and BAUXITE.
cybersecurity
ot-ics-security
ot-security
ics
dragos
threat-detection
ot-monitoring
scada
threat-intelligence
ndr
1.0
mahipal
Apache-2.0
MEASURE-2.7
MAP-5.1
MANAGE-2.4
AML.T0070
AML.T0066
AML.T0082
PR.IR-01
DE.CM-01
ID.AM-05
GV.OC-02
T1078
T1190
T1059
T0816
T0836
Implementing Dragos Platform for OT Monitoring
When to Use
When deploying an OT-specific network detection and response (NDR) solution for industrial environments
When needing threat intelligence-driven detection against known ICS threat groups (VOLTZITE, CHERNOVITE, KAMACITE)
When building an OT SOC capability with purpose-built industrial security tooling
When requiring asset discovery and vulnerability management alongside threat detection in a single platform
When integrating OT security monitoring with an enterprise SIEM (Splunk, Sentinel, QRadar)
Do not use for IT-only network monitoring without ICS components, for endpoint detection and response (EDR) on OT workstations, or for environments standardized on Claroty or Nozomi (see respective skills).
Prerequisites
Dragos Platform license and deployment package
Network TAP or SPAN port at OT network boundaries (one sensor per monitored segment)
Firewall rules allowing sensor-to-Dragos-SiteStore communication (encrypted, outbound only from OT)
Dragos Knowledge Pack subscription for threat intelligence updates
Workflow
Step 1: Deploy Dragos Sensors and Configure Monitoring
#!/usr/bin/env python3"""Dragos Platform Deployment Validator and Integration Tool.
Validates Dragos sensor deployment, checks connectivity, and
configures integration with enterprise SIEM for OT alert forwarding.
"""importjsonimportsysimportcsvfromdatetimeimportdatetimefromtypingimportOptional,List,Dicttry:importrequestsexceptImportError:print("Install requests: pip install requests")sys.exit(1)classDragosPlatformManager:"""Interface with Dragos Platform API for OT monitoring management."""def__init__(self,base_url:str,api_key:str,api_secret:str,verify_ssl:bool=True):self.base_url=base_url.rstrip("/")self.session=requests.Session()self.session.headers.update({"API-Key":api_key,"API-Secret":api_secret,"Content-Type":"application/json",})self.session.verify=verify_ssldefget_sensors(self)->List[Dict]:"""Retrieve all deployed Dragos sensors and their status."""resp=self.session.get(f"{self.base_url}/api/v1/sensors")resp.raise_for_status()returnresp.json().get("sensors",[])defget_assets(self,asset_type:Optional[str]=None)->List[Dict]:"""Retrieve OT assets discovered by Dragos."""params={}ifasset_type:params["type"]=asset_typeresp=self.session.get(f"{self.base_url}/api/v1/assets",params=params)resp.raise_for_status()returnresp.json().get("assets",[])defget_notifications(self,severity:str="high",limit:int=50)->List[Dict]:"""Retrieve threat detection notifications."""params={"min_severity":severity,"limit":limit}resp=self.session.get(f"{self.base_url}/api/v1/notifications",params=params)resp.raise_for_status()returnresp.json().get("notifications",[])defget_vulnerabilities(self,severity:str="critical")->List[Dict]:"""Retrieve OT vulnerabilities with Dragos-specific context."""params={"min_severity":severity}resp=self.session.get(f"{self.base_url}/api/v1/vulnerabilities",params=params)resp.raise_for_status()returnresp.json().get("vulnerabilities",[])defget_threat_groups(self)->List[Dict]:"""Retrieve tracked ICS threat group activity relevant to the environment."""resp=self.session.get(f"{self.base_url}/api/v1/threat-groups")resp.raise_for_status()returnresp.json().get("threat_groups",[])defvalidate_deployment(self):"""Validate sensor deployment health and coverage."""sensors=self.get_sensors()assets=self.get_assets()print(f"\n{'='*65}")print("DRAGOS PLATFORM DEPLOYMENT VALIDATION")print(f"{'='*65}")print(f"Validation Time: {datetime.now().isoformat()}")print(f"\n--- SENSOR STATUS ---")healthy_sensors=0forsensorinsensors:status=sensor.get("status","unknown")icon="[OK]"ifstatus=="connected"else"[!!]"print(f" {icon}{sensor.get('name','Unknown')} | Status: {status}")print(f" IP: {sensor.get('ip_address')} | Segment: {sensor.get('monitored_segment')}")print(f" Last Seen: {sensor.get('last_seen')} | Packets/sec: {sensor.get('pps',0)}")print(f" Knowledge Pack: {sensor.get('knowledge_pack_version','N/A')}")ifstatus=="connected":healthy_sensors+=1print(f"\n Sensor Health: {healthy_sensors}/{len(sensors)} operational")print(f"\n--- ASSET VISIBILITY ---")print(f" Total Assets Discovered: {len(assets)}")asset_types={}forassetinassets:atype=asset.get("type","Unknown")asset_types[atype]=asset_types.get(atype,0)+1foratype,countinsorted(asset_types.items(),key=lambdax:-x[1]):print(f" {atype}: {count}")protocols=set()forassetinassets:protocols.update(asset.get("protocols",[]))print(f" Protocols Observed: {', '.join(sorted(protocols))}")print(f"\n--- THREAT INTELLIGENCE ---")groups=self.get_threat_groups()print(f" Relevant Threat Groups: {len(groups)}")forgroupingroups:print(f" - {group.get('name')}: {group.get('description','')[:80]}")print(f" Targets: {', '.join(group.get('target_sectors',[]))}")print(f" Activity Level: {group.get('activity_level','Unknown')}")defgenerate_siem_integration_config(self,siem_type:str="splunk"):"""Generate SIEM integration configuration for Dragos alerts."""configs={"splunk":{"syslog_format":"CEF","syslog_port":514,"severity_mapping":{"critical":10,"high":7,"medium":5,"low":3,"info":1,},"index":"ot_security","sourcetype":"dragos:notification","fields":["notification_id","severity","category","source_ip","destination_ip","asset_name","protocol","description","mitre_ics_technique","threat_group",],},"sentinel":{"connector_type":"Syslog-CEF","workspace_id":"<workspace-id>","log_analytics_table":"DragosOTAlerts_CL","severity_mapping":{"critical":"High","high":"High","medium":"Medium","low":"Low","info":"Informational",},},}config=configs.get(siem_type,configs["splunk"])print(f"\n--- {siem_type.upper()} INTEGRATION CONFIG ---")print(json.dumps(config,indent=2))returnconfigif__name__=="__main__":manager=DragosPlatformManager(base_url="https://dragos-sitestore.plant.local",api_key="your-api-key",api_secret="your-api-secret",verify_ssl=True,)manager.validate_deployment()manager.generate_siem_integration_config("splunk")print(f"\n--- RECENT HIGH-SEVERITY NOTIFICATIONS ---")notifications=manager.get_notifications(severity="high",limit=10)forninnotifications:print(f" [{n.get('severity','').upper()}] {n.get('title','No title')}")print(f" Category: {n.get('category')} | Time: {n.get('timestamp')}")print(f" Assets: {', '.join(n.get('affected_assets',[]))}")print(f" MITRE ICS: {n.get('mitre_technique','N/A')}")
Step 2: Configure Detection Analytics and Knowledge Packs
# Dragos Platform Detection Configuration# Tuned for manufacturing/energy environmentdetection_configuration:knowledge_pack:auto_update:trueupdate_schedule:"weekly"include_threat_groups:- "VOLTZITE"# Targets energy sector, exfiltrates OT diagrams- "GRAPHITE"# New 2025 threat group targeting ICS- "BAUXITE"# New 2025 threat group targeting ICS- "CHERNOVITE"# Developed PIPEDREAM/INCONTROLLER framework- "ELECTRUM"# Linked to Industroyer/CrashOverride- "KAMACITE"# Targets energy sector initial accessdetection_categories:network_baseline:enabled:truelearning_period_days:30alert_on:- "new_communication_pair"- "new_protocol_detected"- "new_device_on_network"- "protocol_anomaly"threat_detection:enabled:truealert_on:- "known_malware_ioc"- "threat_group_ttp"- "lateral_movement"- "command_and_control"- "data_exfiltration"vulnerability_correlation:enabled:truealert_on:- "active_exploitation_attempt"- "vulnerability_with_public_exploit"protocol_monitoring:modbus:monitor_writes:truebaseline_function_codes:truebaseline_register_ranges:truednp3:monitor_control_commands:truedetect_firmware_updates:trues7comm:detect_cpu_stop:truedetect_program_download:trueopc_ua:monitor_method_calls:truedetect_browsing:trueethernet_ip:monitor_cip_services:truedetect_firmware_flash:truealert_routing:critical:notify:["ot_soc_team","plant_manager"]siem_forward:trueauto_ticket:truehigh:notify:["ot_soc_team"]siem_forward:trueauto_ticket:truemedium:siem_forward:truelow:siem_forward:true
Key Concepts
Term
Definition
Dragos Platform
Purpose-built OT cybersecurity platform with asset visibility, threat detection, and vulnerability management for ICS environments
Knowledge Pack
Dragos threat intelligence update containing detection analytics for new threats, malware, and vulnerability exploits specific to ICS
SiteStore
Dragos central management server aggregating data from all deployed sensors across a site
VOLTZITE
Dragos-tracked threat group targeting energy sector OT environments, exfiltrating GIS data and ICS network diagrams
PIPEDREAM/INCONTROLLER
Modular ICS attack framework developed by CHERNOVITE, targeting Schneider/OMRON PLCs and OPC UA servers
Neighborhood Keeper
Dragos community defense program sharing anonymized threat data across participating OT environments
Common Scenarios
Scenario: Detecting VOLTZITE Reconnaissance in Energy Utility
Context: A Dragos sensor deployed at an electric utility detects unusual OPC UA browsing activity and exfiltration of device configuration data from an engineering workstation.
Approach:
Review the Dragos notification for MITRE ATT&CK ICS technique mapping
Identify the source host performing OPC UA browsing (check if it is an authorized engineering workstation)
Check Dragos threat intelligence correlation for VOLTZITE TTPs
Examine the scope of data accessed (GIS data, network diagrams, ICS configuration files)
Isolate the compromised workstation from the OT network
Check for lateral movement indicators to other OT systems
Engage Dragos Professional Services if threat group attribution is confirmed
Report to CISA as a critical infrastructure cyber incident
Pitfalls: Do not ignore OPC UA browsing alerts as false positives -- VOLTZITE specifically uses this technique for pre-positioning. Ensure Dragos Knowledge Packs are current to detect the latest VOLTZITE indicators. Do not reimage the compromised workstation before collecting forensic evidence.
Output Format
DRAGOS OT MONITORING DEPLOYMENT REPORT
==========================================
Site: [Site Name]
Date: YYYY-MM-DD
SENSOR DEPLOYMENT:
Total Sensors: [count]
Operational: [count]
Coverage: [percentage of OT segments monitored]
ASSET VISIBILITY:
Total OT Assets: [count]
PLCs: [count] | HMIs: [count] | Network Devices: [count]
Protocols: [list]
THREAT DETECTION:
Active Threat Groups Relevant: [count]
Detection Analytics Loaded: [count]
Alerts (Last 30 Days): [count by severity]
SIEM INTEGRATION:
Status: [Connected/Disconnected]
Events Forwarded (Last 24h): [count]