
Intro to OT/ICS Penetration Testing (Part 6): What Happens After We Breach an OT Network
Keywords
Summary
147 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable, practical insights into OT/ICS penetration testing, particularly the discovery and collection phases. The instructor’s argumentation is solid, based on real-world experience and industry best practices. He clearly explains the importance of understanding the process and the relationships between OT assets, and provides concrete examples and lab exercises to reinforce the concepts. The content is well-structured and logically presented, making it useful for both beginners and experienced professionals.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates strong scientific rigor in its technical explanations, with accurate references to tools and protocols. The sources cited are primarily the instructor’s own course materials and website, which are relevant and credible. The title accurately reflects the content, focusing on post-breach activities. The video does not cite external academic sources, but the practical nature of the content justifies this approach.
148 words
Title / Content Match
The title accurately reflects the content, which focuses on post-breach activities in OT/ICS penetration testing, specifically discovery and collection.
Quality & Reliability
8/10
The content is a practical tutorial by an experienced OT/ICS penetration tester, providing detailed methodology and lab exercises. The information is technically accurate and aligns with industry best practices, though it is based on the author's expertise rather than peer-reviewed research.
Chapters
- Introduction
- OT Penetration Testing Methodology
- Discovery
- Collection
- Common Collection Targets
- Don't Just Ask "What is There?"
- How Do We Start to Understand the Process?
- What Are We Looking For to Start With?
- Step #1: Define the Process Purpose
- Step #2: Map the Network & Assets
- Discovery - Passive Techniques
- Using Wireshark in OT/ICS
- Wireshark Limitations
- What About Other OT/ICS Protocols?
- Lab 6.1: Examining Modbus Traffic
- Lab 6.2: Introducing Labshock
- Passive Discovery: Examining Network Equipment
- Wireshark OUI Lookup
- Lab 6.3: Reviewing Network Devices for Discovery
- Discovery - Active Techniques
- Using Nmap to Map OT/ICS Assets
- Nmap Course on YouTube
- Why Can Active Testing be a Bad Thing in OT?
- The Downside of Active Testing
- Living Off the Land - Port Scanners
- Creating a Port Scanner in Python with ChatGPT
- Converting Python to PowerShell with ChatGPT
- Other Discovery Tools
- Lab 6.4: Active Discovery with Labshock
- Identifying Common Control Relationships
- HMI Screenshots
- Lab 6.5: Performing Collection in Labshock
- Building a Process Model
- THANK YOU!!!
Cited Sources
- Course Materials Download — Provided in the video description for course materials.
- Newsletter Signup — Mentioned in the video description for additional resources.
- Live Training Schedule — Mentioned in the video description for live training sessions.
Concurring Sources
- MITRE ATT&CK for ICS — Provides a framework for adversary techniques in ICS, aligning with the video's discussion of discovery and collection.
Contribution & Novelties
This video provides a comprehensive, practical guide to the discovery and collection phases of OT/ICS penetration testing, which are often overlooked in favor of initial access. It offers a structured methodology, including specific techniques and tools, and emphasizes the importance of understanding the process and asset relationships. The inclusion of lab exercises using Labshock adds hands-on value.
Pour aller plus loin :
- MITRE ATT&CK for ICS — Relevant for understanding adversary techniques in OT environments.
- Nmap — Tool used for active discovery; official site provides documentation.
- Wireshark — Tool used for passive discovery; official site provides documentation.
97 words
Radar Profile
The radar profile shows high scores in quantity of information, quality, and technical level, indicating a comprehensive and detailed tutorial. The fiabilite_globale is also high, reflecting the instructor's expertise and practical approach.
💬 No comments were provided for analysis.