
Explore the fundamentals of operational technology security and keystone actions to secure OT environments, using the cookie factory scenario and risk assessment, threat modeling, and system hardening techniques.
Contrast IT and OT by examining longer hardware lifespans and limited updates in OT, versus IT’s standard malware protection, firewalls, and backups; apply CIA triad—confidentiality, integrity, and availability.
Classify pen tests using six criteria: information base, aggressiveness, scope, approach, technique, and starting point, covering black box and white box methods from the inside or via the network.
Examine why ICS/OT devices are easy targets, with accessible design, weak passwords, legacy hardware, and missing encryption and logging, exposing systems to denial of service and social engineering.
Explore the industrial attack landscape, showing easy reconnaissance and manipulation of controllers with SNMP, Nmap, PLC scan, Metasploit, Modbus, and IEC 104, stressing security.
Discover OT osint techniques to uncover exposed industrial control systems using Google hacking and Shodan, including default credentials and port 102 probing.
Review basics of OT systems and their 30-year lifespan, contrasted with IT. Note OT penetration testing is forbidden; learn OT osint techniques like default credentials, Google docking PLCs, and Shodan.
Build a virtual ICS/OT lab by setting up virtualization principles, a virtual network, and Kali Linux on VirtualBox, then install and configure Ubuntu using the provided installation script.
Explore how virtual machines emulate PC hardware, run Ubuntu Server and Kali Linux, and use VirtualBox with host-only and bridged networking for an industrial control systems lab.
Download VirtualBox for Windows, run the installer, and complete the standard installation with suggested options. Enable the network interfaces and accept the optional usb driver to ensure VirtualBox starts correctly.
Install a Kali Linux VM in VirtualBox and configure a network bridge. Clone red point nmap scripts from GitHub, move to /usr/share/nmap/scripts, and probe industrial control systems.
Install Ubuntu Desktop in a virtual machine using VirtualBox, configure a bridge adapter and the shared clipboard, install Guest Additions, and export a backup for future restores.
Ensure internet access with a bridged adapter connected, then run the install script to download course materials from GitHub, taking about 4–5 minutes, then shut down for the practical part.
Configure a VirtualBox host-only network by setting the host-only ethernet adapter IP to 10.2.0.100 with a 255.255.255.0 subnet, and enable a DHCP server with addresses from 10.2.0.200 to 10.2.0.254.
Set up your ICS/OT lab with a ready virtual lab environment, including a penetration testing platform and a simulation platform for hands-on practice, and prepare to explore Kali Linux tools.
Explore essential penetration testing tools for an industrial control system network assessment, using Kali Linux to simulate a Siemens plc and test multiple tools, then report findings with ChatGPT.
Set up a dual-VM lab, emulate a Siemens S7 300 industrial controller, and perform ARP discovery with netdiscover and port probing with nmap, documenting findings.
Explore net discover for host discovery and use nmap with the scripting engine to fingerprint open ports and services, while practicing safe, adjustable scans on industrial networks.
Uncover an industrial control system via ARP discovery and Nmap reconnaissance, identifying Siemens S7-300 devices, open ports 80 and 102, and using S7 scripts for detailed findings.
Write a holistic pen test report with ChatGPT by feeding an Nmap scan, highlight the exposed web server, discuss information disclosure and possible unauthorized control, and include security recommendations.
Identify the control system with net discover, scan ports using nmap noting port 102 where a protocol runs, then use the nmap scripting engine to inspect device’s web server.
Prepare for the OT network assessment by gathering client information and processes, reviewing the penetration testing agreement, and building an asset inventory and network topology for a bird's eye view.
Assess the crumbs of joy cookie factory's OT security posture as the shop floor moves online, and inventory the networked devices using cautious ARP and ICMP reconnaissance.
Outline the penetration testing agreement and perform a black-box assessment of the cookie factory network on the 10.2.0.0/24 subnet, using netdiscover and nmap for reconnaissance and fingerprinting, with no exploitation.
Discover and document assets with the basic asset inventory template, detailing plcs, hmis, and ieds, vendor and device info, firmware, location, discovery results, and security considerations.
Merge the client's asset inventory into our template to form a bird's-eye view. Consolidate line names, device names, electrical tags, IP addresses, and identify PLC, intelligent embedded devices, and HMI.
Create a basic network topology using draw.io, building from a scratchpad XML with PLC, HMI, and IEDs, assign IPs, duplicate lines, and save the diagram.
Create an asset inventory from the bill of materials and map shop floor device topology to assess the OT cybersecurity posture under the exploitation prohibition in the testing agreement.
Conduct an OT network assessment using two scanning methods to map the client’s OT network, verify the asset inventory, and compare results with provided data, with options for extended assessment.
Execute a layer 2 asset discovery using netdiscover to map the production network, then compare ARP results with the asset inventory for an OT network assessment.
Perform a layer 2 asset discovery by documenting devices found via app discovery, add undocumented IPs to inventory, and note Siemens, Yaskawa, CW, while excluding virtual machine addresses.
Mark ot devices that respond to icmp requests as safe for port scanning using a layer 3 icmp nmap ping sweep, and update the asset inventory.
Mark OT devices that replied to the layer three ICMP scan as safe to scan, update the asset inventory, and prepare the client-approved port scan of the marked devices.
Identify open ports on safe OT hosts using a simplified Nmap scan from a prepared host list, then update the asset inventory.
Scan the OT network with Nmap to identify open ports on eight devices, save and clean the report, and update the asset inventory, noting Siemens PLCs and HMIs.
Perform an OT network assessment using layer two asset discovery to uncover undocumented assets, update the inventory, and identify PLC and HMI for port scanning.
Set up the PLC emulation in the Kali Linux and Ubuntu ICS VM, then use nmap to confirm open ports 80 and 102 and probe the industrial protocol.
Scan 10.2.0.204 with nmap for ports 80 and 102, probe 102 with info.nc to reveal CPU type, model, firmware, save results to a file named nmap 8102 and include screenshot.
Investigate the open http service on port 80 to reveal an exposed, badly configured web server that could halt the industrial process; deactivate or harden it and document findings.
Assess and protect industrial control systems by using nmap to identify open ports and analyze misconfigured plc web servers. Learn how such misconfigurations threaten manufacturing operations.
Assess an open port on an emulated Siemens TP 1200 comfort HMI panel, verify the open ports, and inspect the services running to understand human-machine interface security.
Boot ubuntu ICS and Kali Linux to assess the 2200 hmi panel for the three ovens, examining open ports 5001, 5002, 5900 and TCP 102 for remote access, using nmap.
Run an nmap port scan, skip host discovery, and specify ports 102, 5001, 5002, and 5900 with the -p flag; the scan reveals a VNC service on port 5900.
Assess the HMI's remote access by exposing oven controls through the smart server, highlighting the lack of access control or authentication and the risk of anyone manipulating oven settings.
Assess the security of an HMI panel, revealing an insecure remote control service accessible over the network with no access controls and implications for industrial control system protection.
Consolidate misconfigurations and vulnerabilities from the shop floor assessment, present a client-ready dashboard, and draft the penetration testing report with ChatGPT.
Update the network topology by preparing the draft alongside the asset inventory, deactivating filters, hiding unused columns, and uploading the draft, then switch sheets to landscape and a4.
Update the network topology to reflect undocumented hosts, move production lines, and document the mixer plc S7 300 with ip 50 and the net dot mini MD 862 behind 54.
Identify four undocumented OT network hosts, including PLCs, an internet access router, and a shift supervisor PC, and update the asset inventory and network topology to reflect them.
Four critical findings reveal a flat OT network with an undocumented remote access router, and insecure PLC and oven control HMI configurations with unauthenticated web access in Siemens Smart Server.
Present findings from the asset inventory and network topology in a concise dashboard, highlighting critical findings, new devices, and key open ports and unprotected services in the operational technology network.
Draft OT assessment findings with ChatGPT, highlighting the flat OT network architecture, undocumented remote access router, and misconfigured PLC and HMI services using nmap and Net Discover.
Summarize findings from the industrial control system penetration test by updating the network diagram, noting undocumented network hosts, and presenting a management dashboard with thorough, accessible documentation.
Perform risk assessment and threat modeling for OT network, addressing flat OT architecture and VPN router, using 62, 443 and mitral ICS framework to craft PLC and Hmmis threat scenarios.
Assess the risks of a flat OT network where devices share a single segment, lacking segmentation and creating a single point of failure that could disrupt operations and revenue.
The lecture examines cybersecurity risks of VPN remote access to industrial control systems, highlighting trusted device and cloud portal vulnerabilities, misconfigurations, weak access control, and unreliable MFA.
Assess the cybersecurity maturity of an OT system using the IEC Isa 62 443 standard, applying security levels 1–4 and SLT, SLC, SLA to gauge attacker-resilience.
Explore Mitra's ICS attack framework, the attackers playbook for industrial control systems, and learn how it uses 12 tactics and techniques to assess secondary attacks and guide mitigations.
Create a heat map of attack techniques in the ICS attack framework using the Attack Navigator to visualize frequent techniques across campaigns, highlighting initial access, discovery, and persistence.
Develop a threat scenario for the PLC and HMI using ATT&CK Attack Navigator, focusing on initial access, execution, process control, and impact, with technique selection and scoring.
Develop a threat scenario on the PLC and HMI using ATT&CK to show how an attacker gains remote access, stops the CPU, and manipulates setpoints, compromising availability and control.
Apply the ICS attack framework and ATT&CK mitigation recommendations to a cookie factory, evaluating mitigations for PLC and HMI vulnerabilities and defense in depth, including system hardening and network security.
Explore how dynamical systems theory and hazop reveal attacker perspectives on industrial control vulnerabilities, defining potential values and flow values to craft abuse scenarios and protect processes.
Develop vulnerability insights for cyber-physical processes by applying the use case abuse model to actuators and sensors, highlighting misuse scenarios, false alarms, and data manipulation.
Identify three risks in a penetration testing report for an ot network: flat ot network, undocumented vpn router, and exposed remote control functions, using ChatGPT to draft the report.
Explore risks in flat OT networks, apply the Matrix Attack framework to model threats using hazop and dynamical systems, and derive PLC and HMI mitigations.
Introduce the Pojo reference model and defense in depth for securing industrial control systems, then apply system hardening, network segmentation, and secure PLC coding to reduce the attack surface.
Compare the Pojo reference model with the automation pyramid to understand OT network structure, from field devices to the enterprise, and the role of a DMZ.
Apply a defense in depth approach to industrial control systems, layering system hardening, network and perimeter security plus security management to protect a vulnerable PLC from intrusion.
Harden the PLC by restricting IP changes, enforcing HTTPS, and limiting admin access. Enable panel passwords, restrict web server privileges to maintenance, and replace legacy put/get with secure data exchange.
Harden the HMI through the Siemens tia portal by deactivating unused runtime services and enforcing password, IP change, and user segmentation, with screens segregated for information and privileged control.
Assess how PLC and HMI hardening fares against an ICS ATT&CK threat scenario using the Attack navigator, with mitigations like access management and password policies.
Apply network segmentation to reduce OT risks by creating five zones for each cookie line, plus a shared zone and a DMZ, secured by a next-gen firewall.
Strengthen OT security by implementing network segmentation and a dmz-hosted remote access point to control firewall-driven data flows, allow lists, and VLAN-bound connections.
Compare remote access methods for industrial control systems, showing how a jump host with a protocol break in the dmz enhances cybersecurity, access control, and logging over traditional vpn.
Reduce the ICS attack surface with secure coding practices and protective controls. Learn timeouts, interlocks, plausibility checks, and input validation across HMI and PLC to detect manipulation and false alarms.
Learn to craft mitigation recommendations for industrial control systems by restricting PLC web server access, hardening HMI remote services, and applying DMZ-based segmentation with a next generation firewall and VLANs.
Apply the Pojo reference model to bridge IT and OT, implement PLC/HMI hardening, and use network segmentation with VLANs and a DMZ to enforce least privilege and zero trust.
Gain practical, hands-on experience in securing OT environments through simulated exercises and real-world scenarios. Learn from an expert with extensive experience, providing valuable insights and guidance throughout the course. Elevate your defensive OT skills to the next level.
Join now and step into the exciting world of OT security! In this comprehensive course, you will embark on a mission to assess and protect the infrastructure of Joy Cookie Factory as it prepares to transition its entire shop floor online. Unlike previous courses, we prioritize understanding the environment in which OT devices operate, recognizing threats, and implementing effective onboard protection techniques to fortify these devices against cyber threats.
In this course, you'll dive into the essentials of OT security, focusing on practical skills and actionable strategies. Whether you're a newcomer to the field or a seasoned professional, this course will empower you to safeguard OT environments effectively.
Gain a comprehensive understanding of the ecosystem in which OT devices operate, enabling you to identify potential vulnerabilities and threats. Learn how to create a thorough OT asset inventory and assess devices for common vulnerabilities, laying the groundwork for robust security measures. Acquire essential skills and techniques to fortify your OT environment against attacks, utilizing onboard resources and a firewall without relying on expensive detection and response tools.
While participation in the predecessor course, Practical Industrial Control System Penetration Testing, is optional, it is highly recommended. Both courses together provide a holistic understanding of OT device vulnerabilities and their operating environments, setting you up for success in securing OT systems effectively.
The core exercise of this course revolves around a simulated OT network of a cookie factory, offering hands-on experience in creating an OT asset inventory and assessing devices for vulnerabilities. Through practical exercises and real-world scenarios, you'll develop the skills needed to defend OT environments effectively.
Enroll today and take the first step towards mastering the art of defending industrial control systems. Equip yourself with the knowledge and skills needed to safeguard critical infrastructure and protect against evolving cyber threats. Don't miss out on this opportunity to advance your career and make a tangible impact in the world of OT security. Join us now and embark on a journey towards a more secure future!
Curious about penetration testing of ICS/OT devices? Join my course Practical Industrial Control System Penetration Testing.
Please note that the software used is not mine. I can only offer limited assistance in case of problems. Please contact the publisher of the software for help. The installation instructions were created to the best of my knowledge, but the responsibility for the installation lies with the participants.