Detecting Anomalies in Industrial Control Systems When to Use - When deploying continuous monitoring for OT environments that lack intrusion detection - When building behavior-based detection to complement signature-based IDS in OT networks - When establishing baselines for deterministic SCADA communications to detect deviations - When integrating machine learning anomaly detection with OT security monitoring platforms - When investigating alerts from Nozomi Guardian or Dragos Platform that require deeper analysis Do not use for signature-based detection of known exploits (see detecting-attac…