> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reyhford.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ICS/OT Threat Intelligence

> Context around the data — landscape, protocols, MITRE ATT&CK for ICS, STIX/TAXII, and regional intelligence for SOC, CISO, and National CERT teams.

Reyhford does not only ship indicators. We publish the **context SOC analysts, CISOs, and National CERTs need** to interpret ICS/OT telemetry: who attacks industrial networks, which protocols are abused, how techniques map to MITRE ATT\&CK for ICS, and how STIX/TAXII deliver that intelligence.

## What you will learn

<CardGroup cols={2}>
  <Card title="Threat Landscape" icon="globe" href="/threat-landscape/why-ics-ot">
    Why ICS/OT is under threat, who attacks, and landmark incidents.
  </Card>

  <Card title="Industrial Protocols" icon="network-wired" href="/protocols/modbus">
    Modbus, S7, BACnet, IEC 104, EtherNet/IP, Guardian AST — how they work and how they are attacked.
  </Card>

  <Card title="MITRE ATT&CK for ICS" icon="crosshairs" href="/mitre/t0855">
    Techniques we observe most often on the sensor fleet.
  </Card>

  <Card title="TI Fundamentals" icon="book" href="/fundamentals/stix-21">
    STIX 2.1, TAXII 2.1, IoCs, and confidence scoring.
  </Card>

  <Card title="Regional Intelligence" icon="map" href="/regional/southeast-asia">
    Southeast Asia focus, critical infrastructure, actor profiles.
  </Card>
</CardGroup>

## How this connects to the product

Indicators in the [TAXII 2.1 feed](/api-reference/taxii/discovery) and [Indicators API](/api-reference/indicators/search) are enriched with protocol, MITRE technique, and confidence context described in these pages. Use these pages for interpretation; use the API Reference to pull the data into your SOC stack.
