Kaspersky KICS for Networks 4.2 CEF
Kaspersky Industrial CyberSecurity for Networks 4.2 Asset Management events for new devices and address changes, and Intrusion Detection events for ARP spoofing signs, in an industrial (OT) plant network. Each record follows the EventMessage structure KICS sends to a SIEM in CEF; Eventum writes ECS JSON with the CEF line in event.original. About 690 records a day from 60 known devices and 54 transient laptops follow the plant's working day in UTC. For SIEM detection engineering and parser testing. Recurring episodes show a commissioning laptop taking over the address of an existing device.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-kaspersky-kics4net/generator.yml \
--id kics4net \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 4000005007 | New device IP address detected | 39.5% of records | host |
| 4000005003 | New device detected on network | 26.0% of records | host |
| 4000005009 | IP address added to the device | 24.8% of records | host |
| 4000005008 | MAC address added to the device | 2.9% of records | host |
| 4000005005 | IP address conflict detected | 2.0% of records | network |
| 4000005010 | New device MAC address detected | 1.9% of records | host |
| 4000004001 | Symptoms of ARP spoofing detected in ARP replies | 1.8% of records | intrusion_detection, network |
| 4000004002 | Symptoms of ARP spoofing detected in ARP requests | 1.0% of records | intrusion_detection, network |
Realism Features
- Three subnets, each seen by one monitoring point: two production cells (10.20.30.0/24, 10.20.31.0/24) with PLCs, HMIs and switches and a SCADA subnet (10.20.40.0/24) with SCADA and historian servers, engineering workstations and gateways. 60 known devices, nine of them redundant pairs with a backup MAC, each polled by a peer HMI or server; 54 transient engineering, contractor and diagnostic laptops, three of them commissioning laptops with the IPs of the devices they service. RFC 1918 addresses, MACs random within vendor prefixes, synthetic names.
- About 690 records a day (+/- 3% from day to day) follow the plant's working day in UTC: about 13 an hour from 19:00 to 04:00, about 19 at 04:00 and 17:00-19:00, about 33 at 05:00 and 15:00-17:00 and about 45 from 06:00 to 15:00. Laptops make about 90% of records: new or additional DHCP addresses and re-detection as a new device after removal from the devices table, each laptop with its own activity level. Known devices occasionally gain an IP or MAC address or get a new IP; redundant pairs fail over about twice a day around the clock, mostly three flaky pairs, and the primary takes the shared IP back tens of minutes later.
- In about one of five appearances a commissioning laptop comes up with the IP of the device it services. While that device is disconnected, the laptop is only registered with the IP; while it is online, the laptop is either detected as a new device with the IP and then conflicts with the device one to three times within minutes, or, as a known laptop, conflicts and/or shows ARP spoofing signs for the IP towards the device's peer. Other laptops do this rarely, with the IP of some device.
- Detections are a small part of the data: about 10 ARP spoofing bursts (20 records) and 9 IP conflict incidents (14 records) a day, two thirds of them from the three commissioning laptops and a fifth from the redundant pairs. A burst shares one attackStartTimestamp and targets the claimed device's peer, otherwise another HMI, server, workstation or gateway of its subnet. The score adds device importance (PLCs highest) to a synthetic per-type base score, and severity follows the documented 3, 6, 9 bands. KICS registers no event when a conflict or ARP spoofing ends.
- Records that KICS registers seconds apart are further apart here: records of one ARP spoofing burst are a median 100 seconds apart (90% within 6 minutes) and repeated conflicts a median 3 minutes. Laptops change addresses more often than a quiet plant would show (commissioning laptops about 23 to 30 records a day each). Rates, shares, device pools, peers, service IPs and the UTC working day are scenario assumptions, not Kaspersky measurements.
- Kaspersky publishes the EventMessage field table but no complete raw record: the CEF header follows the table, and dateTime, hostname, messageType and score are the first extension keys. Key order, value formats of technology, MAC addresses and start, and the absence of a syslog header are assumptions; byte parity with a live KICS installation and compatibility with the KUMA 4.2 syslog normalizer are not established. Event titles are the event type names; installations may show other titles.
- Only Asset Management address events and ARP spoofing signs: no Process Control, Intrusion Detection rules, Command Control, PLC project, application or audit messages, and no optional common fields such as cnt, end, ports, vlanId, triggeredRule, industrial addresses, device network name or model.
- An ordinary ARP spoofing burst that would complete the anomaly sequence claims another IP of the same subnet, so a few times a week a conflict on one IP is followed within the hour by ARP spoofing signs from the same laptop for a neighbouring IP. With anomaly_mode on, each episode adds about one new-device, conflict and ARP spoofing record for a commissioning laptop and its main service IP; at intervals shorter than a day, a larger share of episodes falls at night than of ordinary activity.
Sample Output
{
"@timestamp": "2026-09-21T13:21:12.824+00:00",
"destination": {
"ip": "10.20.40.10",
"mac": "18-66-DA-E1-D7-BD"
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "Symptoms of ARP spoofing detected in ARP requests",
"category": [
"intrusion_detection",
"network"
],
"code": "4000004002",
"dataset": "kaspersky.kics_networks",
"kind": "alert",
"original": "CEF:0|Kaspersky Lab|Kaspersky Industrial CyberSecurity for Networks|4.2.0.335|4000004002|Symptoms of ARP spoofing detected in ARP requests|6|dateTime=2026-09-21T13:21:12.824Z hostname=10.20.40.5 messageType=Event score=7.6 dmac=18:66:da:e1:d7:bd dst=10.20.40.10 smac=f8:bc:12:48:ef:ed src=10.20.40.18 start=2026-09-21T13:21:15.491Z technology=Intrusion Detection protocol=ARP monitoringPoint=MP-SCADA-SPAN eventIdentifier=2353604 substitutedIpAddress=10.20.40.18 targetIpAddress=10.20.40.10 attackStartTimestamp=2026-09-21T13:21:12.824Z srcAssetName=ENG-LT06 srcVendor=Dell srcOS=Windows 10 Enterprise dstAssetName=SCADA-SRV01 dstVendor=Dell dstOS=Windows Server 2019",
"risk_score": 7.6,
"severity": 6,
"type": [
"indicator"
]
},
"kaspersky": {
"kics_networks": {
"event_identifier": 2353604,
"message_type": "Event",
"monitoring_point": "MP-SCADA-SPAN",
"score": 7.6,
"substituted_ip": "10.20.40.18",
"target_ip": "10.20.40.10",
"technology": "Intrusion Detection"
}
},
"observer": {
"hostname": "10.20.40.5",
"product": "Kaspersky Industrial CyberSecurity for Networks",
"vendor": "Kaspersky Lab",
"version": "4.2.0.335"
},
"related": {
"ip": [
"10.20.40.18",
"10.20.40.10"
]
},
"source": {
"ip": "10.20.40.18",
"mac": "F8-BC-12-48-EF-ED"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring new device, IP conflict, ARP spoofing episode; false produces background only |
| anomaly_interval_hours | 24 | Hours from the start of one episode to the time the next is due, range 3-8760 |
| server_host | 10.20.40.5 | KICS for Networks Server address (hostname) |
| device_version | 4.2.0.335 | KICS for Networks version in the CEF header |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.