iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

Arp Poisoning

Multiple changes of the MAC address for a specific IP were detected in a short period of time - this pattern is typical for ARP poisioning attack attempt

Device re-detected

The system detected traffic on an inactive asset

ABB, Start

An ABB operation was performed - Start action

PCCC, Download request

A Download of the configuration was performed on the PLC

UMAS, Stop the PLC

A UMAS operation was performed - Stop PLC action