ICS Anomaly Detection — ML monitoring for OT/ICS environments (Modbus/DNP3/OPC UA)
Defensive security: detect anomalies in industrial control systems with machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis — flag deviations, rogue devices, and historian mismatches for OT security teams
- What
- Defensive security: detect anomalies in industrial control systems with machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis — flag deviations, rogue devices, and historian mismatches for OT security teams
- Cost
- Free
- Needs
- passive network monitoring sensors on OT network SPAN/TAP ports; 2–4 weeks of baseline traffic capture during normal operations; Python 3.9+ with scikit-learn, numpy, pandas; process historian access; understanding of normal operational patterns (shift changes, batch processes, maintenance windows)
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @mukul975's detecting-anomalies-in-industrial-control-systems skill, listed here with credit to its creator (authored by mahipal, purely defensive OT/ICS security): deploy anomaly detection for operational-technology environments using machine learning on OT network baselines. It walks the agent through building multi-dimensional baseline models of deterministic SCADA communications (timing, protocol behavior, network topology), combining them with physics-based process models and Modbus/DNP3/OPC UA traffic analysis, to flag deviations, rogue devices, and mismatches against historian data — with use cases like baselining deterministic SCADA polling, complementing signature-based IDS in OT, and investigating alerts from platforms like Nozomi Guardian or Dragos that need deeper protocol analysis. Mapped to MITRE ATT&CK, NIST CSF, and NIST AI RMF frameworks. Honest caveats: a SPECIALIZED skill — it assumes OT network access (SPAN/TAP on OT segments, 2–4 weeks of baseline capture, historian access) and process knowledge; it explicitly does not replace process safety systems (SIS); the ML models detect deviations, they don't identify exploits. Apache-2.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: passive network monitoring sensors on OT network SPAN/TAP ports; 2–4 weeks of baseline traffic capture during normal operations; Python 3.9+ with scikit-learn, numpy, pandas; process historian access; understanding of normal operational patterns (shift changes, batch processes, maintenance windows) Install "ICS Anomaly Detection — ML monitoring for OT/ICS environments (Modbus/DNP3/OPC UA)" for me. It gives my agent @mukul975's defensive OT anomaly-detection workflow: build multi-dimensional baselines of deterministic SCADA communications (timing, protocol behavior, topology), combine them with physics-based process models and Modbus/DNP3/OPC UA traffic analysis, and flag deviations, rogue devices, and historian mismatches — with mappings to MITRE ATT&CK, NIST CSF, and NIST AI RMF. Apache-2.0 licensed. Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-anomalies-in-industrial-control-systems/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "detecting-anomalies-in-industrial-control-systems". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm SPAN/TAP coverage of my OT segments; arrange 2–4 weeks of baseline capture; get process historian access; do NOT use this as a replacement for safety instrumented systems). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.