
Critical Infrastructure:
Electric Grid
AI doesn’t just analyze evidence—it decides how to analyze it. RemiFetch adapts forensic methodology in real time based on detected patterns, automatically applying the right techniques—correlation, artifact extraction, behavioral analysis, and timeline reconstruction—to match the investigation.
By linking signals across systems and evolving its approach as new evidence emerges, AI reveals relationships and attack paths that static workflows cannot. This enables deeper insight, faster investigations, and defensible, evidence-driven conclusions.
- Not dependent on known malware signatures or predefined rules
- ✓ Detects patterns, behaviors, and relationships across systems and time
- ✓ Adapts forensic methods dynamically based on the evidence and context
- ✓ Correlates activity across accounts, devices, networks, and platforms automatically
- ✓ Identifies multi-stage and coordinated attacks traditional tools often miss
- ✓ Surfaces hidden relationships and attack paths without manual stitching
- ✓ Produces evidence-backed findings with defensible, audit-ready timelines

Supported Platforms
- Siemens Energy – grid automation, protection relays, substation control systems
- Schneider Electric – SCADA platforms, energy management systems, grid control
- GE Vernova – grid control systems, protection relays, EMS/SCADA platforms
- ABB – substation automation, protection relays, grid control technologies
- Hitachi Energy – grid automation, protection systems, substation control
- SEL (Schweitzer Engineering Laboratories) – protective relays, grid monitoring, automation
- Emerson – power plant and grid control systems (Ovation DCS)
- Rockwell Automation – PLCs and industrial control platforms used in grid facilities
- Honeywell – industrial control systems and plant automation
- Mitsubishi Electric – protection relays and substation automation systems
Reconstruct Electric Grid Disruption Tradecraft
Remi analyzes offline electric grid OT/IT event logs to surface insider behavior, grid disruption tradecraft, and coordinated activity across substations, SCADA systems, protection relays, and dispatch operations. By correlating events across control networks, engineering workstations, and grid telemetry, Remi helps investigators identify unauthorized commands, protection system tampering, abnormal load or frequency events, and multi-site coordination that may indicate adversarial attempts to disrupt electric infrastructure.
Critical Infrastructure: Electric Grid — Detection Catalog
Scrollable list (click a detection to expand)
AI-Assisted Tradecraft Indicators
AI API Usage from ICS Environment AI
Automation Agent Framework Indicators AI
Local LLM Tooling Present on ICS Asset AI
Prompt / LLM Artifact Indicators in Logs AI
Access & Authentication
Unauthorized SCADA Login Access
Unauthorized Substation Operator Logins at Odd Hours Identity
Compromise of Dispatch Center Operator Account Identity
Remote VPN Access Without Authorization Remote
Process & Command Integrity
Breaker Trip Injection Control
Unauthorized Substation Command Injection Control
SCADA Command Replay Attack Replay
Substation Switchgear Forced Open / Close Switching
Unauthorized Control of Automatic Load Balancer Balancer
Unauthorized Remote Disconnect of Substations Remote
Malicious Command Flooding to SCADA Bus Flooding
Grid Stability & Operations
Load Shedding Frequency Instability Attacks Operations
Generator Manipulation (Frequency / Voltage) Generation
Frequency Oscillation Anomalies Anomaly
Grid-Wide Oscillation Detection Cross-Substation Anomaly Telemetry
Emergency Load Shedding Disabled Safety
Protection, Device, & Firmware Tampering
Protection Relay Setting Change Protection
GOOSE or SV Spoof / Replay IEC 61850
Malware in Substation RTUs or IEDs Malware
Unauthorized Firmware Change in IEDs Firmware
Unexpected Firmware Downgrade on RTUs Firmware
Tampering with Protection Relays Tamper
Network, Multi-Site Coordination, & Evidence
DoS on SCADA Network Network
Communication Loss Between Substations Network
Coordinated Attack Across Multiple Substations Multi-Site
Coordinated Fault Injection Across Substations Multi-Site
False Telemetry Data Integrity Attack Integrity
Unauthorized Access to Grid State Estimation Logs Logs
Insider Data Historian Tampering Historian
Suspicious Parallel Operator Sessions at Dispatch Dispatch
Reconstruct Electric Grid Disruption Tradecraft
Remi analyzes offline electric grid OT/IT event logs to surface insider behavior, grid disruption tradecraft, and coordinated activity across substations, SCADA systems, protection relays, and dispatch operations. By correlating events across control networks, engineering workstations, and grid telemetry, Remi helps investigators identify unauthorized commands, protection system tampering, abnormal load or frequency events, and multi-site coordination that may indicate adversarial attempts to disrupt electric infrastructure.
- Executive_Summary.txt ✓
- Operational_Narrative.txt ✓
- System_State_Timeline.txt ✓
- Device_Activity_Report.txt ✓
- Control_Action_Summary.txt ✓
- Anomaly_Report.txt ✓
- Artifact_Inventory.txt ✓
- Artifact_Origin_Report.txt ✓
- Evidence_Excerpts.txt ✓
- Thread_Index.txt ✓