Intro to OT/ICS Penetration Testing (Part 7): Attacking Wireless, PLCs and the Process in OT

Intro to OT/ICS Penetration Testing (Part 7): Attacking Wireless, PLCs and the Process in OT

🎙 Mike Holcomb 👥 27K 📅 December 29, 2025 ⏱ 102 min 👁 946 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICSpenetration testingwirelessPLC

Summary

This video is the seventh part of a course on OT/ICS penetration testing, continuing the discussion on discovery and collection. The instructor, Mike Holcomb, emphasizes the importance of understanding OT environments to defend them, and explains how attackers can exploit wireless communication and PLCs. He reviews key concepts from previous parts, including the OT pen testing methodology and the use of coils and registers in PLCs. The main focus is on wireless attacks, covering various wireless protocols like Wi-Fi, Bluetooth, and WirelessHART, and their associated risks. He discusses real-world examples, such as the Maroochy Shire incident, and tools like Wigle.net for reconnaissance. The video also touches on attacking PLCs directly, including manipulating data values and understanding the I/O image. The instructor stresses that many OT networks contain Windows systems, making them vulnerable to common IT attacks. He concludes by highlighting the need for specialized knowledge in OT security and the importance of hands-on labs for learning.

156 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into OT/ICS penetration testing, particularly focusing on wireless attacks and PLC manipulation. The instructor’s extensive experience is evident, and he offers practical advice and real-world examples that enhance the learning value. The argumentation is solid, as he logically explains the attack surface and the importance of understanding the process. He effectively communicates the risks associated with wireless in OT environments and the need for specialized security measures. The content is well-structured and builds on previous parts, making it a coherent part of the course.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates a high level of scientific rigor in the sense that the information is based on practical experience and industry knowledge. However, it lacks formal citations or references to external sources, which limits its academic rigor. The title accurately reflects the content, which is focused on attacking wireless, PLCs, and the process in OT. The content is well-organized and the instructor clearly explains complex concepts. The absence of formal sources is a minor weakness, but the practical nature of the content compensates for it.

190 words

Title / Content Match

The title accurately reflects the content, which focuses on attacking wireless, PLCs, and the process in OT environments.

Quality & Reliability

8/10

The content is based on the author's extensive experience in OT/ICS penetration testing, providing practical insights and real-world examples. The information is technically accurate and aligns with industry knowledge, though it lacks formal citations and peer review.

Key Moments

Cited Sources

  • Wigle.net — Mentioned as a tool for mapping wireless networks, useful for reconnaissance.

Concurring Sources

  • IEC 62443 — Standards for OT security that align with the video's emphasis on securing industrial environments.

Contribution & Novelties

This video provides a practical, hands-on approach to OT/ICS penetration testing, specifically focusing on wireless attacks and PLC manipulation. It offers unique insights from real-world experience, such as the Maroochy Shire incident and the use of Wigle.net for reconnaissance. The content is valuable for both attackers and defenders, emphasizing the importance of understanding the process to secure OT environments.

Pour aller plus loin :

  • IEC 62443 — International standards for industrial automation and control systems security.
  • PLC — Overview of programmable logic controllers.
  • WirelessHART — Wireless communication protocol for process automation.

91 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower score in technical level, indicating that the content is comprehensive and trustworthy but may not delve into extremely advanced technical details.

Reliability 8/10

💬 No comments were provided for analysis.