<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rethinking Threat ID: 31671 (SCADA ICCP Unauthorized COTP Connection) — Is This Really Malicious? in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/rethinking-threat-id-31671-scada-iccp-unauthorized-cotp/m-p/1262387#M2517</link>
    <description>&lt;P&gt;When reviewing security alerts, context is everything. Take Threat ID: 31671 ("SCADA ICCP Unauthorized COTP Connection Established"), for instance. The current description simply states: "This alert indicates that an ICCP client has successfully connected using OSI Connection Oriented Transport Protocol."&lt;/P&gt;
&lt;P&gt;While seeing a successful connection pop up in an alert is certainly helpful for asset visibility, the description leaves a massive gap: it fails to explain what actually makes the event malicious or risky. A successful COTP (Connection-Oriented Transport Protocol) handshake on its own is just a normal network event—it happens every time legitimate control systems communicate. Without additional context—such as whether the source IP address is unauthorized, if the connection violates segmentation policies, or if it deviates from established baseline behavior—this alert risks becoming just another piece of alert fatigue.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2026 05:13:17 GMT</pubDate>
    <dc:creator>rodney23koy</dc:creator>
    <dc:date>2026-08-20T05:13:17Z</dc:date>
    <item>
      <title>Rethinking Threat ID: 31671 (SCADA ICCP Unauthorized COTP Connection) — Is This Really Malicious?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/rethinking-threat-id-31671-scada-iccp-unauthorized-cotp/m-p/1262387#M2517</link>
      <description>&lt;P&gt;When reviewing security alerts, context is everything. Take Threat ID: 31671 ("SCADA ICCP Unauthorized COTP Connection Established"), for instance. The current description simply states: "This alert indicates that an ICCP client has successfully connected using OSI Connection Oriented Transport Protocol."&lt;/P&gt;
&lt;P&gt;While seeing a successful connection pop up in an alert is certainly helpful for asset visibility, the description leaves a massive gap: it fails to explain what actually makes the event malicious or risky. A successful COTP (Connection-Oriented Transport Protocol) handshake on its own is just a normal network event—it happens every time legitimate control systems communicate. Without additional context—such as whether the source IP address is unauthorized, if the connection violates segmentation policies, or if it deviates from established baseline behavior—this alert risks becoming just another piece of alert fatigue.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2026 05:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/rethinking-threat-id-31671-scada-iccp-unauthorized-cotp/m-p/1262387#M2517</guid>
      <dc:creator>rodney23koy</dc:creator>
      <dc:date>2026-08-20T05:13:17Z</dc:date>
    </item>
  </channel>
</rss>

