
This lecture provides an overview of the course. I've also attached a text file which contains various links which are used throughout the course!
Explore how the tri station protocol powers Schneider Electric safety systems. See the four BSI detection methods for Triton activity and thresholds.
Explore German BSI TriStation snort rules for safety instrumented systems, including alerting, logging, threshold, and exploit rules, and how they detect unauthorized hosts and Triton malware activity.
Explore Nozomi Networks trictools for Triton ISIS malware, using Wireshark and Security Onion to test German BSI Snort rules, analyze the tri station protocol, and deploy the tri connects honeypot.
Learn how to view ICS/SCADA snort rule alerts in SGUIL with Squeal on Security Onion. Troubleshoot pickup file checksums, inspect alerts, and fine-tune tri-station rules for a clear Squeal dashboard.
Our world is growing more and more dependent upon technology and systems that monitor and control industrial processes. The electric power grid, water and sewage systems, oil and natural gas pipelines, and many more critical infrastructure utilize Industrial Control Systems/Supervisory Control and Data Acquisition (ICS/SCADA) systems. ICS/SCADA is used to monitor and control these infrastructure processes. One way we can defend these systems is by implementing Network Security Monitoring (NSM) within ICS/SCADA environments. This ICS/SCADA Network Security Monitoring (NSM) course will provide you with a strong foundation in some of the open source tools that are available to implement ICS/SCADA NSM within your ICS/SCADA environments! You will learn about various topics such as: What is Security Onion, and how can it be used for ICS/SCADA NSM? What open source tools and resources are available to implement ICS/SCADA NSM? How do I update my Snort rules to implement ICS/SCADA NSM? What are some Snort rules that can be used to detect the TRITON SIS Malware? What other TRITON SIS Malware resources are out there? etc...