OT Cyber Tuesday (Ep. 9) - OSINT for OT/ICS - Finding Assets on the Internet

OT Cyber Tuesday (Ep. 9) - OSINT for OT/ICS - Finding Assets on the Internet

🎙 Mike Holcomb 👥 27K 📅 December 10, 2025 ⏱ 60 min 👁 427 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

ShodanZoomEyePLCHMIOSINTOT/ICSexposed assetsModbuscybersecurity

Summary

In this episode of OT Cyber Tuesday, Mike Holcomb provides a hands-on tutorial on using OSINT tools to find OT/ICS assets exposed to the internet. He begins by emphasizing the importance of backup and recovery in OT security, sponsored by Macrium. The main focus is on using Shodan and ZoomEye to locate devices like PLCs and HMIs. He explains that while Shodan scans a limited set of ports, it can identify services and provide vendor information. He demonstrates how to refine searches using vendor names and specific protocols like Modbus, and shows examples of exposed Rockwell and Allen-Bradley devices. He also discusses the prevalence of unauthenticated protocols and the ease of identifying device types. He mentions the use of GenAI for finding assets and provides resources like cheat sheets on his website. The session includes Q&A on topics such as hiding ports and using VMs for privacy. He concludes by highlighting the importance of understanding these tools for defensive purposes.

160 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable practical knowledge for OT/ICS security professionals, demonstrating real-world techniques for discovering exposed assets. The argumentation is based on direct experience and clear explanations of the tools’ capabilities and limitations. The author effectively communicates the importance of using vendor-specific queries and understanding that open ports do not necessarily indicate real control systems. The demonstration of Shodan’s interface and search results adds credibility. However, the video lacks a structured methodology and does not delve into the ethical or legal considerations of scanning for exposed assets, which could be a limitation for some viewers.

Scientific Rigor, Source Quality, Title Accuracy

The video is scientifically rigorous in its practical approach, but it does not cite formal sources or academic references. The author relies on his expertise and demonstrates real tools, which is appropriate for a tutorial. The title accurately reflects the content, and the video stays on topic. The description provides links to the author’s newsletter and free resources, which are relevant but not formal citations. The video does not include any external sources beyond the tools themselves. The lack of formal citations is a minor weakness, but the practical demonstrations and clear explanations compensate for this.

206 words

Title / Content Match

The title accurately reflects the content: a practical session on OSINT for OT/ICS, focusing on finding exposed assets using Shodan and ZoomEye.

Quality & Reliability

8/10

The video provides a practical, hands-on tutorial on using OSINT tools (Shodan, ZoomEye) to find exposed OT/ICS assets. The author demonstrates real queries and explains the context, including the limitations of port-based searches and the importance of vendor-specific queries. While the content is largely based on personal experience and demonstration, it is accurate and aligns with known practices in OT security. The author also mentions the use of GenAI, but does not provide detailed methodology. Overall, the information is reliable for educational purposes, with minor caveats regarding the lack of formal citations.

Key Moments

Cited Sources

  • Newsletter signup — Author's newsletter for OT/ICS cybersecurity content.
  • Free videos for learning OT/ICS cyber — Free educational resources on OT/ICS security.

Concurring Sources

  • Shodan — The tool used in the video for finding exposed devices.
  • ZoomEye — The alternative tool demonstrated in the video.

Contribution & Novelties

The video offers a practical, hands-on approach to using OSINT tools specifically for OT/ICS asset discovery, which is often overlooked in general cybersecurity training. It provides real-world examples and tips for refining searches to find exposed PLCs and HMIs. The author’s experience and clear explanations add value for both beginners and experienced professionals. The video also highlights the importance of understanding the limitations of these tools, such as false positives and the need for vendor-specific queries.

Pour aller plus loin :

  • Shodan — The primary tool demonstrated, with extensive documentation and search capabilities.
  • ZoomEye — A Chinese-based search engine for internet-connected devices, offering similar functionality to Shodan.
  • Modbus Protocol — The protocol discussed in the video, widely used in industrial control systems.
  • PLC (Programmable Logic Controller) — The type of device targeted in the searches, with details on its role in industrial automation.

143 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-rounded tutorial that is both informative and trustworthy, but may not delve deeply into advanced technical details.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.