
Discover the MITRE ATT&CK framework as a knowledge base of adversary tactics, techniques, and procedures, and learn how ICS tactics and mitigations support threat modeling and defense against cyber attacks.
Explore tactics, techniques, and procedures used against industrial control systems, including initial access, execution, persistence, privilege escalation, evasion, discovery, lateral movement, collection, command and control, and impact.
Understand drive-by compromise and watering hole attacks that infect visitors via compromised sites. Learn mitigations like browser sandboxing, exploit protection, network segmentation, and log-based detection.
Exploiting public facing applications enables initial access by targeting internet-exposed services; attackers use Shodan and Google dorking to identify vulnerabilities, while mitigations include sandboxing, least privilege, and monitoring.
Q: Why are ICS networks vulnerable?
A: Many ICS devices run legacy software and can’t be easily patched.
Q: How does MS17-010 work?
A: It lets attackers execute arbitrary code via SMB file-sharing protocol.
Q: What’s the difference between ransomware and Stuxnet?
A: Ransomware disrupts for profit; Stuxnet was a targeted attack to cause physical damage.
Exploit remote services like rdp, smb, ssh, and vnc to infiltrate OT networks. Segment networks, use mfa, restrict rdp/vnc to read-only on hmi, and monitor logon anomalies and traffic.
Replication through removable media lets attackers breach air gapped ICS environments via USB drives, compromising Mis, PLCs, and workstations; monitor drive creation, file access, and execution with defense in depth.
Supply chain compromise enables adversaries to tamper with products, software, or delivery mechanisms before end users, including counterfeit hardware and trojanized ICS software, in OT environments.
Explore how adversaries exploit wireless protocols like Wi-Fi, Bluetooth, and GPS to gain unauthorized access, and learn mitigations such as encryption, mutual authentication, and RF shielding in ICS.
The execution phase shows how attackers run malicious code on target systems via user actions, software exploits, remote code via APIs, and scripting tools.
defend against change operating mode by enforcing strict access control, authenticating users and devices, applying role-based permissions with physical key switches, and monitoring logs and traffic in segmented ot networks.
Attackers turn legitimate interfaces into weapons by abusing and reverse engineering API calls to command safety devices and PLCs; enforce RBAC, MFA, and protocol-aware firewalls to block unauthorized calls.
Hooking inserts a tollbooth into function calls via the import address table, redirecting Siemens functions and letting Stuxnet run first, while PLC projects trigger sensor spoofing.
Examine how attackers exploit the PLC scan cycle and startup blocks like OB1 and OB9999 with PLC blaster. Implement defenses with digital signatures, PKI, and strict change management.
Explore how native API exploitation grants direct access to the os kernel in industrial control systems, illustrate Triton's kernel-level abuse, and outline hardening steps to defend ICS.
Learn how scripting languages rely on interpreters, not compilers, enabling on-the-fly code execution and cross-system deployment. Adversaries weaponize scripts—from PowerShell to JavaScript and VBA macros—for execution and command and control.
Learn how user interaction enables malicious code execution, from opening attachments and enabling macros to granting permissions. The module covers spearphishing, installer delivery, and backdoor execution driven by users.
Examine ICS persistence and six techniques—project file infection, modify program, system firmware, module firmware, hard coded credentials, and stealing valid accounts—organized into infect, corrupt, and steal.
Hard coded credentials pose a systemic, unchangeable backdoor that enables lateral movement and persistence; strengthen access management and monitoring to defend critical industrial systems.
Explore how modify program attacks rewrite PLC and industrial controller logic, turning machinery into saboteurs. Learn prevention via code signing with cryptographic hashes and detection of online edit commands.
Project file infection hijacks industrial processes by embedding malicious code into PLC project files, creating long-term persistence; defend with auditing, code signing, restricting permissions, and encryption, as shown by Stuxnet.
Explore system firmware as the hidden brain powering devices, and learn how to defend it with three pillars: verify code, control access, and secure update networks.
Valid accounts let attackers bypass defenses with stolen or default credentials, enabling persistence and lateral movement into industrial control systems; MFA, least privilege, and threat hunting help detect impostors.
Explore privilege escalation in ot security, turning a guest pass into a master key to control physical systems. Mitre attack tracks many techniques for industrial control systems.
Explore how attackers escalate privileges in industrial control systems, using tools like in controller malware and Triton, and apply MITRE's four layered mitigations to defend OT core.
Explore evasion tactics in industrial control systems by adversaries who hide in plain sight, abusing trusted elements, spoofing communications, and removing indicators of compromise to defeat defenses.
Explain exploitation for evasion, where attackers bypass security to install malware, illustrated by the Triton case, and outline defenses—updates, sandboxing, exploit protection, and threat intelligence—in ongoing active defense.
Disguising a file or service as a legitimate vendor or system component, masquerading enables attackers to bypass detection by renaming files or altering extensions.
Explore discovery tactics where adversaries survey your environment to identify targets, learn network architecture and communications, and plan lateral movement, using techniques like network enumeration and sniffing.
Learn how attackers perform network connection enumeration to gather information from active connections and map device roles. Explore DNS, LDAP, SNMP, and netstat-based techniques to identify shares, subnets, and patterns.
Learn how network sniffing monitors and captures traffic via interfaces, taps, or span on switches, uses wireshark for analysis, and how plaintext credentials and DNS poisoning affect exposure and defenses.
Explore remote system discovery as a lateral movement technique, showing how attackers enumerate devices by ip address, hostname, or other identifiers using built-in tools or windows networking (wnet).
Learn how adversaries perform remote system information discovery to collect hardware, software, OS details, and system roles for planning and targeting subsequent attacks.
Examine wireless sniffing across Bluetooth, Wi-Fi, infrared, and RF links, including industrial and enterprise contexts, and learn practical defenses like encrypted protocols, WPA, two-factor, and radius authentication.
Study lateral movement as adversaries pivot through networks by abusing default credentials, known accounts, and vulnerable services, leveraging dual home devices and pivot points like OPC servers and IP cameras.
Examine how default credentials enable lateral movement in control systems, stressing changing admin passwords after first boot to prevent exploitation, with Stuxnet's use of hardcoded defaults as context.
Explains lateral transfer of tools and files between endpoints using smb, vbscript, and sql statements, with Stuxnet as an example.
Illustrates how attackers leverage existing remote services, such as RDP and SMB, to move laterally across network segments, gain remote access, and execute attacks or download programs using valid accounts.
Explore automated data collection tactics in industrial environments, using native protocols like OPC to gather device details, process value, and network metadata from connected systems.
Attackers excavate data from information repositories across plant databases, harvesting specifications, schematics, diagrams, and control system layouts for campaigns by Chinese state-sponsored actors against oil and natural gas organizations.
Detect operating mode explains how attackers observe whether a controller is in program, run, remote, stop, reset, or test mode to plan actions and program downloads.
Examine man in the middle attacks in the MITRE framework, where privileged adversaries intercept, block, log, modify, or inject traffic and redirect it to a local service.
Monitor the process state and gather information from OPC data, historian records, PLC blocks, and valve status to inform attacks and potentially alter process parameters.
Explore point and tag identification in Mitre's framework, showing how adversaries collect inputs, memory, locations, and tag names to map industrial processes and enumerate OPC tags.
Explain how adversaries may upload a PLC program to read and study the running logic using vendor software, and stress securing backups and controlling uploads.
Screen capture techniques collect screenshots from HMI or workstation displays to reveal operator behavior and typical commands. Adversaries may use this to mimic operations and remain undetected on the network.
Explore commonly used ports and protocols, how attackers bypass firewalls by blending with normal traffic, and how deep packet inspection and application layer firewalls help detect Stuxnet's UDP 1502 usage.
Explore connection proxy techniques that use relay proxies to establish trusted network relationships and route communications from a DMZ to enterprise network, enabling adversaries to manage command and control communications.
Adversaries exploit the standard application layer protocol to establish command and control using public protocols like HTTP, sometimes on nonstandard ports, including vendor proprietary and industrial protocols.
CAUTION: "DO NOT BUY IF YOU DON'T LIKE THEORETICAL COURSE"
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.
In this course, you will learn about all the tactics for ICS/OT as per the framework. This is not a practical course, this is solely for learning the concepts. Also, we will learn about all the techniques in detail for each tactic. And for mitigation, there could be the same mitigation to be applied for multiple techniques so we will cover mitigations as a whole. We will cover all the below-mentioned tactics:
ICS Attack tactics:
Initial Access
Execution
Persistence
Privilege Escalation
Evasion
Discovery
Lateral Movement
Collection
Command and Control
Inhibit Response Function
Impair Process Control
Impact
After completing this course you will have a good understanding of the techniques to be implemented and executed by adversaries. That will help you to answer clients, customers, and in meetings and discussions. Also whenever you are designing some solution you will keep these in mind and set proper mitigation to make the environment more secure and comprehensive.
* Connect to me on Linkedin/ or visit cyberotsecure{dot}com website to get discounts.
For understanding this course you should have a basic understanding of the Industrial control system and technical terms which are commonly used in cybersecurity so that you can understand the concepts. This is a theoretical course but in the future, I will keep on adding practical examples as well.
* Most affordable course on ICS MITRE