Inferring Attacks on a Distributed Honeyfarm Using Adversary Emulation and Centralized Threat Detection

Sergio Fadanelli, Thuy Nguyen, Neil C. Rowe · Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences · 2026

Securing industrial control systems (ICSs) is difficult. This research aims to improve ICS security with data collected by a distributed honeyfarm (a network of honeypots). We deployed cloud-based honeypots in Europe and North America to monitor and analyze real-world attacks on simulated power grids and ICS devices. Our honeyfarm included a centralized enterprise-grade Security Information and Event Management (SIEM) system for real-time threat detection. We used MITRE Caldera adversary emulation, MITRE ATT&CK, system logs, and network-intrusion alerts to create SIEM queries. This approach distinguishes our honeyfarm from other research. We observed exploits of network protocols and legitimate services, remote code execution, brute-force credential cracking, denial of service, and botnet activity. RDP activity indicated possible human involvement. Our results showed that a SIEM system trained with adversary-emulation results and intrusion-detection alerts collected data on 16 times more suspicious intruders and improved detection of their threats, enabling better defenses.

Read the paper · More papers on PaperTik