Pre-DEFCON Session: Hacking Your First OT System

Pre-DEFCON Session: Hacking Your First OT System

🎙 Mike Holcomb 👥 27K 📅 August 1, 2026 ⏱ 35 min 👁 420 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICSModbusPLCHacking

Summary

In this pre-DEFCON session, Mike Holcomb demonstrates how to hack an OT (Operational Technology) system using a simulated conveyor belt controlled by a PLC. He explains that Modbus, the most common industrial protocol, is unauthenticated, allowing anyone with network access to read and write to the PLC’s memory. Using his custom ‘Modbus Swiss Army Knife’ tool, he shows how to read and write coils (binary values) and registers (numeric values) to control the conveyor belt’s speed and direction. He also demonstrates scanning for all coils and registers, flooding values to override sensor inputs, and using functions to zero out or flip all coils, which can cause physical effects like reversing the belt. He emphasizes that these techniques apply to real-world critical infrastructure, such as power plants, water treatment, and transportation, and that even simple actions can have serious consequences. The session concludes with a Q&A where he explains that mapping coil addresses to physical meanings often requires access to the HMI, which acts as a ‘Rosetta Stone’.

167 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, hands-on insight into OT hacking, demonstrating the ease of exploiting unauthenticated protocols like Modbus. The argumentation is solid, based on practical demonstration and real-world experience. The presenter effectively shows that even simple tools can have significant impact, and he contextualizes the risks with examples of real-world consequences. The session is well-structured, starting with basics and progressing to more advanced techniques, making it accessible for beginners while still offering depth for those with some knowledge.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the presenter is an experienced professional, and the technical explanations are accurate, but he does not cite external sources or provide formal references. The tools and simulations are his own, and he mentions his GitHub and website for resources. The title accurately reflects the content, and the session is a practical tutorial rather than a formal study. The lack of citations is typical for such practical sessions, but it limits the ability to verify claims independently.

174 words

Title / Content Match

The title accurately reflects the content: a hands-on session on hacking OT systems, specifically targeting a PLC via Modbus.

Quality & Reliability

7/10

The video is a practical tutorial by an experienced OT security professional. It demonstrates real attack techniques on a simulated PLC using Modbus, and provides accurate technical explanations. However, it lacks formal citations and relies on anecdotal evidence. The content is reproducible and aligns with known OT security practices.

Key Moments

Cited Sources

  • Mike Holcomb's GitHub — Mentioned as the source for the tools and simulators used in the session.
  • Mike Holcomb's Website — Mentioned as a hub for resources, including links to GitHub, infographics, ebooks, and TryHackMe rooms.

Concurring Sources

  • Modbus Protocol Specification — Official Modbus specification confirming the protocol's structure and unauthenticated nature.
  • CISA ICS Advisories — CISA advisories on vulnerabilities in ICS, supporting the claim that many systems are exposed.

Contribution & Novelties

The video provides a practical, hands-on introduction to OT hacking, specifically focusing on Modbus and PLCs. It demystifies the process and shows that even simple tools can have significant impact. The presenter’s approach of using a simulated conveyor belt makes the concepts tangible and accessible. The session also highlights the importance of understanding the physical consequences of cyber attacks on OT systems.

Pour aller plus loin :

  • Modbus Protocol — Overview of the Modbus protocol, its history, and its use in industrial control systems.
  • Programmable Logic Controller — Explanation of PLCs, their role in automation, and their vulnerabilities.
  • ICS-CERT — Official resources on industrial control systems security from CISA.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, providing best practices and recommendations.

125 words

Radar Profile

The radar profile shows high scores in quality of information and technical level, reflecting the practical and accurate content. The moderate scores in quantity and reliability are due to the lack of formal citations and the limited scope of the demonstration. Overall, the video is a valuable resource for those interested in OT security.

Reliability 7/10

💬 No comments were provided for analysis.