Uploaded May 2025 | Updated September 2026, 1 week ago
IDS rules for ICS are no longer bleeding edge. They are common. Unfortunately many are also quite bad. Bad because evasion techniques can bypass a lot of the published rules.
Preprocessors can sometimes 'fix' these failings, and they also can introduce new failings.
Reid helps you evaluate the rules your using, and more importantly provide you with some tips on how to use advanced features to deal with the problems seen regularly in ICS rules for IDS.
Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x26. Feb 23 - 26 in Miami South Beach:
s4xevents.com
IDS rules for ICS are no longer bleeding edge. They are common. Unfortunately many are also quite bad. Bad because evasion techniques can bypass a lot of the published rules.
Preprocessors can sometimes 'fix' these failings, and they also can introduce new failings.
Reid helps you evaluate the rules your using, and more importantly provide you with some tips on how to use advanced features to deal with the problems seen regularly in ICS rules for IDS.
Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x26. Feb 23 - 26 in Miami South Beach:
s4xevents.com










