Supervisory
Human-Machine Interface (HMI)
The operator's window into the process — panel-mounted or PC-based graphics showing state and providing control actions.
What it does
Displays process values and alarms, and issues operator commands to controllers.
Typically locatedControl rooms and local panels near the process.
At a glance
Why should I care?
Human-Machine Interface sits at Level 2. Compromise here is not just a data problem — it changes what the physical process does or what operators can see and control.
Common security problems
- Shared operator accounts
- Unpatched Windows underneath
- USB ports enabled
- Auto-login with full control rights
If it is compromised
- Manipulation of the operator's view of the process
- Direct control commands with legitimate credentials
What to monitor
- Logon events and account use
- New software or process execution
- USB device insertion
- Screen/project file changes
How to defend it
- Application allow-listing where vendor-supported
- Remove general-purpose browsing and email
- Role-based operator accounts
- Control removable media
Hunting
Hunt ideas for this component
Intermediate
Abnormal HMI Communication
Detect HMIs communicating with unusual peers, services or destinations.
Foundational
Unapproved USB / Removable Media
Identify removable media use on OT hosts, especially engineering and operator systems.
Intermediate
Abnormal Authentication in OT
Identify authentication patterns in the OT environment that do not match normal operational behaviour.
Related
Protocols this component speaks
Open / standardized
Modbus TCP
502/TCP
Vendor-associated
S7 Communication (S7comm / S7comm-plus)
102/TCP
Industry consortium
EtherNet/IP
44818/TCP (explicit), 2222/UDP (implicit I/O)
Open / standardized
OPC UA
4840/TCP (default)
Vendor proprietary
UMAS
502/TCP (Modbus function code 90 / 0x5A)
Vendor proprietary
PCOM
20256/TCP (PCOM), 20257/TCP (secondary), 5900/TCP for embedded VNC