
Explore how critical infrastructure relies on industrial control systems and faces real attack surfaces. Red teams simulate attacks to uncover hidden vulnerabilities and teach offensive methodologies for securing critical infrastructure.
Explore OT network architecture with the Purdue model, IEC 62443 zones and conduits, and DMZ design to understand real-world misconfigurations for red team and defense.
Define explicit OT scope with multi-stakeholder sign-off and uphold safety as an operational constraint. Learn to balance realism with safety, regulatory compliance, and documented halt conditions.
Discover a disciplined five-phase OT red team methodology for ICS engagements, from intelligence and initial access to traversal, execution, and debrief.
Learn to manage risk in live OT engagements by applying four capabilities: understand risk, apply safe techniques, respond to impact, and document and review outcomes for safety and availability.
Discover how internet-exposed industrial control systems power critical processes and how to discover, fingerprint, and catalog exposed ICS assets using Shodan, Census, FOFA, and ZoomEye.
Case study of the Oldsmar water treatment attack shows how internet-exposed remote access with shared credentials and no MFA nearly caused mass harm, halted by a vigilant operator within seconds.
Explore ICS red team impact techniques across disruption, sabotage, and destruction, from objective tiers to safe, ethical testing and credible impact modeling for industrial control systems.
Explore data exfiltration from ot environments, prioritizing control logic, process telemetry, engineering files, and historian data; map exfiltration paths, maintain opsec, and model covert channels for realistic red team testing.
Study the Triton case of a purpose-built safety-instrumented system attack, detailing IT-OT lateral movement, Triconex protocol abuse, and a four-stage kill chain.
Industrial control systems are among the most critical and most vulnerable targets in the world, especially in 2026 — yet offensive security training for ICS/OT environments remains rare, expensive, and largely inaccessible.
This course changes that.
ICS/OT Offensive Security: Red Team Methodology is a structured, practitioner-focused course that teaches you how to think, plan, and operate as a red teamer inside industrial environments. You will learn how attackers approach ICS/OT targets from initial reconnaissance all the way through to physical impact — and how to conduct engagements safely, professionally, and with the depth that critical infrastructure demands.
You will build a complete understanding of OT architecture, industrial protocols, and adversary tradecraft before moving into offensive techniques covering initial access, IT-to-OT pivoting, lateral movement across Purdue model levels, protocol exploitation, and device attacks against PLCs, RTUs, and HMIs.
Every major phase is grounded in real-world adversary behavior mapped to MITRE ATT&CK for ICS, and reinforced through four in-depth case studies covering Stuxnet, Industroyer, Triton, and the Oldsmar water treatment attack.
The course closes with a full red team reporting framework designed specifically for OT engagements, including how to communicate physical risk to both technical teams and executive stakeholders.
Whether you are a penetration tester expanding into ICS, an IT security professional transitioning into OT, or a consultant supporting critical infrastructure clients — this course gives you the methodology, the knowledge, and the professional foundation to operate in one of the most demanding and highest-impact specializations in cybersecurity.