Automation Glossary • OT Threat Hunting

What Is Threat Hunting in OT Networks?

Merobix Engineering • • 8 min read

Detection tools catch what they were built to catch, but an attacker who stays quiet and uses techniques no rule anticipated can sit inside a network for weeks without tripping a single alert. Threat hunting is the deliberate, proactive search for exactly that kind of intruder: a human hunter forming a hypothesis about how an adversary might be hiding and then digging through the data to prove or disprove it. In OT this discipline has an unusual advantage, because control networks are far more predictable than office ones, and in a place where almost nothing should change, the thing that changed stands out.

Back to Blog

OT Threat Hunting in one line: Threat hunting in OT networks is a proactive, hypothesis-driven search for attackers that automated detection has missed. Instead of waiting for an alert, a hunter starts from an idea about how an adversary might be operating - for example, a technique from a known playbook - and then examines network traffic, host data, and historian records to confirm or rule it out. Its purpose is to find hidden intrusions early and shrink dwell time, and it is especially effective in OT because the deterministic, repetitive nature of control traffic makes genuine anomalies conspicuous.

Hunting Starts With a Hypothesis

The defining feature of threat hunting is that it is not driven by alerts. An alert says a specific known-bad thing happened; a hunt asks whether something bad that no rule would catch might be happening right now. That question has to be made concrete before it is useful, which is why hunting is hypothesis-driven. A hunter picks a plausible adversary behavior - perhaps an attacker using a legitimate engineering tool to move laterally, or beaconing to a command-and-control server hidden in otherwise normal traffic - and turns it into a testable statement: if this were happening, the data would show this specific footprint.

With a hypothesis in hand, the hunt becomes a focused investigation rather than an aimless trawl. The hunter goes to the data sources where that footprint would appear and looks for it directly: network captures for the traffic pattern, host artifacts for the tool's traces, logs for the access sequence. The result of a hunt is either evidence of a real intrusion, which becomes an incident, or a confidence that this particular technique is not present, which is itself valuable because it narrows where an undetected attacker could be. Either way the hunt often exposes a gap in detection that can be closed with a new rule so the next occurrence trips an alert automatically.

Good hypotheses come from knowing the adversary. Hunters draw on structured catalogs of adversary tactics and techniques, on threat intelligence about who targets their sector and how, and on their own understanding of where their environment is weak. A hunt for a technique known to be used against industrial targets is far more productive than a random look, because it aims the search at behavior a real attacker of this kind would actually exhibit. This is what makes hunting a skilled human activity rather than something a tool does on its own: the value is in choosing the right question.

Why OT Determinism Helps the Hunter

An office network is a poor place to spot subtle anomalies because it is chaotic by nature. People install software, visit new sites, connect personal devices, and generate a constantly shifting baseline in which one more unusual thing hides easily. An OT network is the opposite. The same controllers poll the same registers at the same intervals, the same HMIs talk to the same PLCs, and the traffic follows a rhythm that barely changes from day to day. This determinism is the hunter's greatest ally, because against a stable, repetitive baseline, a new connection, an unfamiliar protocol, or a device reaching somewhere it never has before is genuinely conspicuous.

That predictability lets a hunter frame powerful, simple hypotheses. In an OT segment, a controller should almost never initiate an outbound connection to the internet, so a hunt for any such connection is both easy to run and highly revealing, because there is essentially no legitimate reason for it and any hit is worth investigating. Similarly, a device speaking a protocol that has no business on its segment, or an engineering workstation active at an hour no engineer works, jumps out against a baseline that is otherwise almost boringly consistent. The hunter can exploit the fact that the environment is supposed to be static.

The flip side is that OT hunting demands care for the environment itself. Aggressive scanning that an IT hunter might run freely can disturb fragile devices, so OT hunting leans heavily on passive observation of traffic that is already flowing and on data already collected, rather than on active probing. The hunter works from what the network reveals about itself, which suits a domain where the priority is to watch the process without perturbing it. That constraint, far from weakening the hunt, aligns it with how the network already behaves and keeps the search from becoming a source of the very disruption it aims to prevent.

Pivoting Through the Historian and SCADA Data

Network traffic is not the only place an OT intrusion leaves marks. The historian, the database that records every process value over time, is a rich and often overlooked hunting ground, because an attacker who manipulates a process has to change values that the historian faithfully records. A hunter can pivot into historian data to test hypotheses that network data alone cannot answer: did a setpoint change at a time no operator was logged in, did a reading move in a way the physics of the process cannot explain, did a value freeze at exactly the moment an attacker might have wanted operators blinded. These are questions about the process itself, and only the process record can answer them.

This is where the operational and security views converge. A cloud SCADA platform such as Merobix continuously historizes what every asset is doing across a fleet of sites, which gives a hunter a long, queryable record of normal behavior to hunt against and a single place to correlate a suspicious network event with what the process was actually doing at that instant. A network alert about an unexpected write becomes far more decisive when the hunter can immediately see whether that write moved a real setpoint on a running unit, and the historian is what makes that pivot possible.

Bringing network, host, and historian data into one hunt is what lets a hunter reconstruct an attacker's path through an industrial environment. A hypothesis about lateral movement, tested against network flows, might point at a controller; the historian then shows whether that controller's process values were tampered with; the SCADA logs show who was connected when. Following the evidence across these sources is how hunting shrinks dwell time, catching an intruder in the weeks between a quiet initial foothold and the moment they would have acted, which in a physical process is precisely the window in which finding them still prevents harm.

Frequently Asked Questions

How is threat hunting different from monitoring or alerting?

Monitoring and alerting are reactive: a tool watches for known-bad patterns and raises an alert when one appears. Threat hunting is proactive and human-led: a hunter assumes an attacker may already be present and undetected, forms a hypothesis about how they might be hiding, and searches the data to confirm or rule it out. Hunting deliberately looks for what the alerts would miss, and when it finds a gap it often produces a new detection rule so the same behavior triggers an alert next time.

Why is OT easier to hunt in than IT?

Because OT networks are deterministic. The same controllers poll the same registers at the same intervals, and the traffic barely changes day to day, so a stable baseline exists to hunt against. In that quiet, repetitive environment, a new connection, an unexpected protocol, or a controller reaching out to the internet stands out sharply, whereas the same anomaly would hide in the constant churn of an office network. Hunters exploit that predictability to frame simple, high-signal hypotheses like looking for any outbound connection from a segment that should have none.

What is the role of the historian in OT threat hunting?

The historian records every process value over time, so it captures the physical evidence of tampering that network traffic alone cannot show. A hunter can pivot into historian data to test whether a setpoint changed when no operator was present, whether a reading moved in a physically impossible way, or whether a value was frozen to blind operators. Because manipulating a process forces an attacker to change values the historian is recording, it is one of the most revealing places to hunt in an OT environment.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
MITRE ATT&CK for ICS  •  Indicator of Compromise (IOC)  •  Protocol Whitelisting  •  DNS Tunneling Detection  •  Secure Protocol Tunneling  •  Transmitter Terminal Wiring  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →