
This lecture provides an overview of the course. I've also attached a text file which contains various links which are used throughout the course!
Preview course prerequisites and the role of security onion on a linux vm. Explore open-source tools like snort, cabana, and wire shark for network monitoring and Triton SRS malware detection.
Discover how Kibana-backed Cabana visualizes ics/scada logs—from modbus and tri station protocols to Bro and Snort alerts—enabling port-based filtering, interface-driven insights, and customizable dashboards for nsm.
Explore how the tri station protocol powers Schneider Electric safety systems. See the four BSI detection methods for Triton activity and thresholds.
Explore German BSI TriStation snort rules for safety instrumented systems, including alerting, logging, threshold, and exploit rules, and how they detect unauthorized hosts and Triton malware activity.
Explore Nozomi Networks trictools for Triton ISIS malware, using Wireshark and Security Onion to test German BSI Snort rules, analyze the tri station protocol, and deploy the tri connects honeypot.
Update snort rules for German BSI Tri station in a Security Onion NSM setup by configuring local rules, editing snort config with correct IP variables, and applying tri station rules.
Learn how to view ICS/SCADA snort rule alerts in SGUIL with Squeal on Security Onion. Troubleshoot pickup file checksums, inspect alerts, and fine-tune tri-station rules for a clear Squeal dashboard.
Celebrate completing the network security monitoring course. Commit to ongoing practice by building a home lab, mastering tradecraft, and continuously improving to stay sharp in cybersecurity.
Our world is growing more and more dependent upon technology and systems that monitor and control industrial processes. The electric power grid, water and sewage systems, oil and natural gas pipelines, and many more critical infrastructure utilize Industrial Control Systems/Supervisory Control and Data Acquisition (ICS/SCADA) systems. ICS/SCADA is used to monitor and control these infrastructure processes. One way we can defend these systems is by implementing Network Security Monitoring (NSM) within ICS/SCADA environments. This ICS/SCADA Network Security Monitoring (NSM) course will provide you with a strong foundation in some of the open source tools that are available to implement ICS/SCADA NSM within your ICS/SCADA environments! You will learn about various topics such as: What is Security Onion, and how can it be used for ICS/SCADA NSM? What open source tools and resources are available to implement ICS/SCADA NSM? How do I update my Snort rules to implement ICS/SCADA NSM? What are some Snort rules that can be used to detect the TRITON SIS Malware? What other TRITON SIS Malware resources are out there? etc...