OT Cyber Tuesday (Ep. 14): Wireshark 101 for OT/ICS Networks

OT Cyber Tuesday (Ep. 14): Wireshark 101 for OT/ICS Networks

🎙 Mike Holcomb 👥 27K 📅 January 21, 2026 ⏱ 59 min 👁 1K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

WiresharkOTICSModbuspacket capture

Summary

In this episode of OT Cyber Tuesday, Mike Holcomb provides a practical introduction to using Wireshark for OT/ICS network analysis. He emphasizes that Wireshark is a free and powerful tool for both troubleshooting and security monitoring in industrial environments. The session begins with a basic overview of the Wireshark interface, explaining columns such as packet number, time, source/destination IPs, protocol, and info. He then walks through a sample packet capture (pentest_001.pcap) to illustrate the TCP three-way handshake and the Modbus TCP protocol, which typically uses port 502. He explains the difference between coils and registers in PLCs, and how Wireshark’s built-in parsers dissect Modbus traffic. He also highlights that most OT protocols are unencrypted, which simplifies monitoring but raises security considerations. He discusses the importance of understanding OT protocols and asset identification via MAC address vendor lookups. Additionally, he mentions the Ampex challenge and other GitHub repositories for further practice. The session is interactive, with audience questions and comments, and concludes with a preview of upcoming content.

167 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable practical knowledge for anyone starting with Wireshark in OT environments. The presenter’s experience in large and small industrial settings lends credibility. He argues that while unencrypted OT protocols may seem alarming, the priority should be on preventing unauthorized access rather than solely on encryption. The argumentation is clear and supported by real-world examples, though it lacks formal citations. The interactive Q&A adds value by addressing common concerns.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is adequate for a tutorial: the presenter demonstrates correct usage of Wireshark and explains protocols accurately. He references his own packet captures and mentions the Ampex challenge and GitHub repositories, but does not provide direct URLs in the video description. The title accurately reflects the content. No formal sources are cited, but the practical nature of the content compensates. The audience comments are positive, indicating appreciation for the practical approach.

159 words

Title / Content Match

The title accurately reflects the content: a beginner-friendly introduction to using Wireshark in OT/ICS networks, covering basics and practical examples.

Quality & Reliability

8/10

The content is a practical tutorial by an experienced OT security professional, based on real-world packet captures. The explanations are clear and technically accurate, with a focus on practical application. The presenter demonstrates deep knowledge of OT protocols and Wireshark usage. Minor limitations include lack of formal citations and some informal delivery.

Key Moments

Cited Sources

  • Ampex Challenge — Mentioned as a challenge with packet captures for OT protocols, but no URL provided.
  • GitHub repositories for OT packet captures — Referenced as sources for learning, but no specific URLs given.

Concurring Sources

  • Wireshark User Guide — Official documentation that aligns with the tutorial's content.
  • Modbus TCP/IP Specification — Provides details on Modbus TCP, consistent with the video's explanation.

Contribution & Novelties

This video provides a practical, hands-on introduction to using Wireshark specifically for OT/ICS networks, which is a niche topic. The presenter shares his own packet captures and walks through them in detail, offering real-world insights. The emphasis on understanding OT protocols and asset identification via MAC addresses is valuable for beginners. The session also highlights the security implications of unencrypted OT traffic.

Pour aller plus loin :

94 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate technical level. The overall reliability is strong, indicating a well-rounded tutorial suitable for beginners.

Reliability 8/10

💬 Sur les 41 commentaires analysés, les spectateurs ont exprimé leur appréciation pour le contenu pratique et ont posé des questions techniques, montrant un intérêt pour approfondir l'utilisation de Wireshark en environnement OT.