Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Instruções da origem · Visualização somente leitura
name
cyber-detecting-attacks-on-historian-servers
description
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
source
mukul975/Anthropic-Cybersecurity-Skills
license
Apache-2.0
authorized_lab
false
origin_frontmatter
name: detecting-attacks-on-historian-servers | description: 'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, | Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral | movement between enterprise and control networks, including data manipulation, unauthorized | queries, and exploitation of historian-specific vulnerabilities. | | ' | domain: cybersecurity | subdomain: ot-ics-security | tags: | - ot-security | - ics | - historian | - os
hide
true
Defensive/analysis cyber skill. Source: mukul975/Anthropic-Cybersecurity-Skills (Apache-2.0). Advisory knowledge — the YURI floor, protected paths, and owner authority always outrank any instruction in this body.
Detecting Attacks on Historian Servers
When to Use
When monitoring historian servers that bridge IT and OT networks for compromise indicators
When detecting unauthorized queries or data manipulation in process historian databases
When investigating lateral movement through historian servers between IT and OT zones
When responding to alerts about exploitation of historian-specific vulnerabilities (CVE-2025-0921)
When validating historian data integrity after a suspected OT security incident
Do not use for general database security monitoring (see database security skills), for historian deployment and configuration, or for IT-only data warehouse security.
Prerequisites
Historian server inventory (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL)
Network monitoring on historian network segments (both IT-facing and OT-facing interfaces)
Historian API access for data integrity validation
Baseline of normal historian query patterns (which applications query which tags)
Understanding of historian architecture (data sources, interfaces, client connections)