Intro to OT/ICS Penetration Testing (Part 6): What Happens After We Breach an OT Network

Intro to OT/ICS Penetration Testing (Part 6): What Happens After We Breach an OT Network

🎙 Mike Holcomb 👥 27K 📅 December 26, 2025 ⏱ 115 min 👁 834 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICSpenetration testingdiscoverycollectionPLC

Summary

This video is the sixth part of a course on OT/ICS penetration testing, focusing on what happens after gaining initial access to an OT network. The instructor, Mike Holcomb, explains the importance of discovery and collection phases in understanding the OT environment. He covers passive and active discovery techniques, including using Wireshark and Nmap, and emphasizes the need to map network assets and understand their relationships. The video discusses common collection targets such as engineering workstations, data historians, HMI screenshots, and GIS data. Holcomb also highlights the significance of understanding the process being controlled, including defining process purpose and mapping the network. He provides practical lab exercises using Labshock to demonstrate discovery and collection. The video concludes with building a process model to understand how to impact the real-world process. Throughout, Holcomb stresses the importance of safety and availability in OT environments, advising caution with active testing.

147 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, practical insights into OT/ICS penetration testing, particularly the discovery and collection phases. The instructor’s argumentation is solid, based on real-world experience and industry best practices. He clearly explains the importance of understanding the process and the relationships between OT assets, and provides concrete examples and lab exercises to reinforce the concepts. The content is well-structured and logically presented, making it useful for both beginners and experienced professionals.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates strong scientific rigor in its technical explanations, with accurate references to tools and protocols. The sources cited are primarily the instructor’s own course materials and website, which are relevant and credible. The title accurately reflects the content, focusing on post-breach activities. The video does not cite external academic sources, but the practical nature of the content justifies this approach.

148 words

Title / Content Match

The title accurately reflects the content, which focuses on post-breach activities in OT/ICS penetration testing, specifically discovery and collection.

Quality & Reliability

8/10

The content is a practical tutorial by an experienced OT/ICS penetration tester, providing detailed methodology and lab exercises. The information is technically accurate and aligns with industry best practices, though it is based on the author's expertise rather than peer-reviewed research.

Chapters

Cited Sources

Concurring Sources

  • MITRE ATT&CK for ICS — Provides a framework for adversary techniques in ICS, aligning with the video's discussion of discovery and collection.

Contribution & Novelties

This video provides a comprehensive, practical guide to the discovery and collection phases of OT/ICS penetration testing, which are often overlooked in favor of initial access. It offers a structured methodology, including specific techniques and tools, and emphasizes the importance of understanding the process and asset relationships. The inclusion of lab exercises using Labshock adds hands-on value.

Pour aller plus loin :

  • MITRE ATT&CK for ICS — Relevant for understanding adversary techniques in OT environments.
  • Nmap — Tool used for active discovery; official site provides documentation.
  • Wireshark — Tool used for passive discovery; official site provides documentation.

97 words

Radar Profile

The radar profile shows high scores in quantity of information, quality, and technical level, indicating a comprehensive and detailed tutorial. The fiabilite_globale is also high, reflecting the instructor's expertise and practical approach.

Reliability 8/10

💬 No comments were provided for analysis.