HoneypotsICS/OTThreat Intel

What a Modbus and IEC-104 Honeypot Fleet Actually Teaches You

Jason Faulhefer July 24, 2026 7 min read

Share this post

Deploying vendor-authentic Modbus/TCP and IEC 60870-5-104 decoys is only the start. The real value comes from what the traffic tells you about scanning campaigns, targeted operators, and pre-attack reconnaissance against grid and manufacturing assets.

Every serious ICS/OT program eventually asks the same question: who is actually poking at protocols like Modbus/TCP and IEC 60870-5-104 on the public internet, and does any of it target us?

A well built honeypot fleet answers that question with data instead of vendor threat reports.

What a good OT decoy looks like

A credible Modbus or IEC-104 sensor is more than an open port. It mimics a specific vendor stack, exposes realistic register maps, and responds to function codes the way a Schneider Modicon or Siemens SIPROTEC would. Attackers who script generic scanners get filtered out quickly. The interesting sessions are the ones that speak the protocol correctly and probe for identity, firmware, or engineering access.

What the traffic actually shows

  1. Broad internet scanning for TCP/502 and TCP/2404 is constant and mostly automated.
  2. A much smaller slice of sessions issues valid function codes (read holding registers, read device identification, general interrogation).
  3. A still smaller slice enumerates points, walks address ranges, or attempts writes.

That last group is what a CTI team should care about. Those sessions map cleanly to MITRE ATT&CK for ICS techniques such as T0846 Remote System Discovery and T0888 Remote System Information Discovery.

Turning sensor data into intelligence

Raw hits are noise. Intelligence is context: source ASN, geolocation, session fingerprint, protocol depth, and whether the same actor has touched other sensors in the fleet. ThreatSpire correlates these signals across the sensor grid so that a single write attempt on a substation decoy becomes a tracked actor profile rather than a forgotten log line.

Feeding it back to defense

The honeypot output is only useful if it changes something. Practical uses:

  • Block or tarpit source ranges that repeatedly speak ICS protocols to nothing they should be talking to.
  • Prioritize detections in the SOC for the specific function codes attackers use in the wild.
  • Feed PIRs and collection plans with real observed adversary behavior instead of vendor conjecture.

Honeypots are not a defense. They are a collection asset. Treated that way, an OT sensor fleet becomes one of the highest signal intelligence sources a utility or manufacturer can run.

Share this post

See it in action

Want intelligence that drives decisions, not noise?