Intro to OT/ICS Penetration Testing (Part 3):  How IT Pentesting Factors Into OT

Intro to OT/ICS Penetration Testing (Part 3): How IT Pentesting Factors Into OT

🎙 Mike Holcomb 👥 27K 📅 September 12, 2025 ⏱ 88 min 👁 2K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICSpenetration testingIT/OTMetasploitEternalBlue

Summary

This video is the third part of a course on OT/ICS penetration testing, focusing on how IT penetration testing techniques are relevant to OT environments. The instructor, Mike Holcomb, explains the IT penetration testing methodology and applies it to a common OT scenario: resetting a local administrator password on a Windows system in a plant. He covers the pre-engagement phase (scope, objectives, rules of engagement, authorization), the engagement phase (reconnaissance, scanning, exploitation, post-exploitation), and the post-engagement phase (reporting, remediation validation). The video includes practical labs using tools like Nmap and Metasploit, and emphasizes the importance of understanding IT attacks for OT security. The content is aimed at OT cybersecurity professionals and provides a solid foundation for conducting OT penetration tests.

120 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the intersection of IT and OT penetration testing, emphasizing the prevalence of Windows systems in OT environments and the relevance of IT attack techniques. The argumentation is solid, based on the author’s extensive experience and real-world examples, such as the case study of a vulnerable firewall. The step-by-step methodology is clear and practical, making it useful for practitioners. The author effectively argues that understanding IT penetration testing is essential for OT security, given that most attacks on OT networks originate from IT.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on practical experience rather than formal research, but it is well-structured and methodical. The sources cited are limited to the course materials and the author’s website, with no external references. The title accurately reflects the content, which is a tutorial on IT penetration testing from an OT perspective. The video does not include any public comments, so no analysis of audience feedback is possible.

176 words

Title / Content Match

The title accurately reflects the content, which focuses on how IT penetration testing techniques apply to OT/ICS environments.

Quality & Reliability

8/10

The content is based on the author's extensive practical experience in OT/ICS penetration testing, with clear methodology and real-world examples. The video is instructional and provides actionable steps, but lacks formal citations or references to external sources, relying on the author's expertise.

Chapters

Cited Sources

Concurring Sources

  • NIST SP 800-82 — Provides guidance on securing ICS, aligning with the video's emphasis on OT security.
  • MITRE ATT&CK for ICS — Offers a framework for understanding ICS-specific attack techniques, complementing the video's content.

Contribution & Novelties

This video contributes to the field by bridging the gap between IT and OT penetration testing, providing a practical guide for OT professionals to apply IT techniques in OT environments. It emphasizes the importance of understanding IT attacks for OT security and offers a structured methodology. The inclusion of labs and real-world examples enhances its educational value.

Pour aller plus loin :

119 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate technical level. The reliability is high, reflecting the author's expertise. The video is well-balanced, with strengths in providing practical knowledge and a clear methodology.

Reliability 8/10