Why Guardian AST matters
ATG systems are deployed at hundreds of thousands of locations globally. They monitor fuel inventory, detect leaks, and control dispensing equipment. Unlike many ICS protocols, ATG systems are frequently connected directly to the internet for remote monitoring by fuel suppliers and operators. Guardian AST devices listen on port 10001 by default. The protocol has no authentication. Anyone who can reach the device can read tank levels, temperatures, and alarm states — or send commands.Attack implications
Compromise of ATG systems can enable:- Intelligence gathering — fuel levels at military installations, airports, or critical facilities reveal operational patterns
- False alarms — triggering leak alarms causes facility shutdowns and emergency response
- Pump manipulation — some ATG systems control dispensing equipment directly
- Environmental sabotage — disabling leak detection systems
What Reyhford observes
Guardian AST is consistently the highest-volume ICS protocol by unique attacker IP count in our network — a finding that surprises most threat intelligence practitioners. This reflects the protocol’s unique exposure profile: ATG systems are frequently internet-connected for remote monitoring, poorly secured, and distributed across high-value locations that are interesting for intelligence collection. Our SEA sensor (edge-sgp-001, Singapore) observes Guardian AST scanning from geographically diverse sources, suggesting coordinated intelligence collection campaigns rather than opportunistic scanning.
The volume of Guardian AST targeting in our data is a unique finding not widely documented in public threat intelligence. This represents a meaningful signal for organizations managing fuel infrastructure.