SCADA Logging: See Every Change, Stop Insider Threats!

SCADA Logging: See Every Change, Stop Insider Threats!

?? Labshock 1.4.1 – SCADA Logging Update

Labshock 1.4.1 introduces SCADA logging, making it easier to collect and analyze events from FUXA SCADA. With this update, you can track user actions, system changes, and project modifications in real time. Logs are sent via Syslog to Tidal Collector, where they can be viewed through a simple and powerful web interface.

Why is SCADA Logging Important?

Insider threats are one of the biggest risks in OT environments. Many issues don’t come from external hackers but from operators/engineers/vendors/contractors - whether by accident or on purpose.

Unlike external attacks, insider threats don’t require phishing, malware, or lateral movement. They already have direct access.

The best protection? Centralized monitoring. If changes, logins, and system edits are tracked, people think twice before attempting to hide actions. SCADA logging helps you see what’s changing, correlate events and stop problems before they escalate.

This guide walks you through SCADA logging Demo:

  • enabling logging
  • collecting key events
  • using Tidal Collector to monitor activity.


Let’s get started! ??


?? Update Labshock

enable SCADA logging

Getting Labshock up and running is simple. You only need Docker, Docker Compose, and optional Git installed on your system. No extra libraries or tools are required.

Check GitHub for update process -> Labshock repo

And put Star ?? your feedback helps a lot, thanks!

Update process Simple as possible:



?? Collecting Logs from SCADA

what's new in Labshock

I developed Syslog logging for FUXA SCADA, allowing it to send logs to external systems. I also updated the web interface to include logging settings, making it easier to enable and configure log collection. This update integrates with Tidal Collector, providing a user-friendly way to view and analyze SCADA logs in real time.

And thanks a lot Frangoteam team for such cool tool!

FUXA GitHub

FUXA Website


1. Login to SCADA

  • let's open the FUXA SCADA web interface
  • enter admin credentials if needed and log in
  • go to Editor


2. Enable Logging

  • go to the SCADA settings
  • now there is new security Feature: Syslog Logging ??
  • fill Syslog Host and Port


3. Check Logs in Tidal Collector

  • open the Tidal Collector Web UI
  • navigate to the Messages section
  • you can see SCADA logs appear in real time



?? Tracking User Creation Logs

let's check user creation example

I added logging for user creation events in FUXA SCADA, ensuring that every new account creation is recorded and sent via Syslog. With integration into Tidal Collector, users can easily track and review account creation events through a web interface, improving visibility and security monitoring.


1. Creating a New User in SCADA

  • let's log in to the FUXA SCADA web interface as an admin
  • navigate to the User Management section
  • add a new user 123

2. Logging User Creation Events

  • logging is enabled in the SCADA settings
  • when a new user is created, an event log is generated and sent via Syslog


3. Viewing Logs in Tidal Collector

  • open the Tidal Collector Web UI
  • navigate to the Messages section
  • you can see the new user creation event appears in the logs



?? Tracking Project Changes

now they know that you know

I added logging for project changes in FUXA SCADA, capturing edits, device updates, and configuration changes. Logs with user details and timestamps are sent via Syslog to Tidal Collector, allowing real-time tracking through its web interface.

1. Making Changes to a SCADA Project

  • let's modify key settings, add/remove devices, or update logic
  • save and apply the changes

2. Logging Project Modifications

  • the logs are sent via Syslog to Tidal Collector
  • ensures traceability of critical SCADA modifications


3. Viewing Logs in Tidal Collector

  • open the Tidal Collector Web UI
  • navigate to the Logs section and filter by Project Changes events
  • you can see modifications are logged and tracked



?? Conclusion

Labshock makes it easy to practice and understand SCADA logging

SCADA logging is a simple but powerful way to improve visibility and security in OT environments. By enabling logging in SCADA and integrating it with Tidal Collector, you can track user actions, detect unauthorized changes and respond to insider threats before they cause harm.

? Monitor logins, project edits and user management events

? Correlate actions across SCADA, PLCs, and other OT systems

? Ensure accountability by making changes traceable

The same principles apply to all SCADA and HMI systems, not just Oilsprings. Logging user actions, tracking configuration changes, and integrating with a central collector enhance security and visibility across any industrial environment.



Try it out, and let me know your thoughts!

put Like ?? put Star ?? and Coffee ??


AIT ICHOU MUSTAPHA ??

+17K Followers ?? | Cybersecurity Analyst | Blue Team Specialist | Threat Hunting | Malware Researcher and Analyst ?? | ML, DL, AI | Community Manager @SOC4M

5 天前

Useful tips Zakhar Bernhardt thank you for sharing

要查看或添加评论,请登录

Zakhar Bernhardt的更多文章

社区洞察

其他会员也浏览了