
OT Cyber Weekly: Finding & Attacking OT/ICS Assets on the Internet
Keywords
Summary
215 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable, actionable information for anyone interested in OT/ICS security. It offers a practical methodology for discovering exposed industrial control systems using publicly available tools like Shodan and Google. The presenter demonstrates real-world examples, including live PLCs and ENCO controllers, and explains the implications of their exposure. The argumentation is solid, based on the presenter’s extensive experience and the demonstration of actual techniques. The video also highlights the ease with which attackers can exploit these exposures, reinforcing the need for better security practices. The use of a simulator for ethical testing is a responsible approach, and the presenter clearly advises against attacking live systems.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates a high level of scientific rigor in its methodology, showing step-by-step how to use Shodan and other tools to identify exposed OT assets. The presenter references the NSA’s Elite Wolf project and provides links to his own GitHub repositories and a TryHackMe room, which serve as sources for further learning. The title accurately reflects the content, as the video indeed covers finding and attacking OT/ICS assets. The presentation is well-structured and technically accurate, though it lacks formal citations to academic or industry publications. The presenter’s practical experience adds credibility, but the video is more of a tutorial than a peer-reviewed analysis.
225 words
Title / Content Match
The title accurately reflects the content, which focuses on discovering and attacking OT/ICS assets exposed to the internet.
Quality & Reliability
8/10
The video is a practical tutorial by an experienced OT/ICS security professional, demonstrating real-world techniques for finding and attacking exposed industrial control systems. The methods are well-established and the presenter provides concrete examples and tools. The content is technically accurate and aligns with known security practices, though it lacks formal citations and peer review.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction to the topic and recent attacks on OT assets.
- Overview of Shodan and its history with ICS.
- Demonstration of searching Shodan for Modbus port 502.
- Using Google to find exposed PLCs via URLs from NSA's Elite Wolf project.
- Example of a live Rockwell PLC with web interface and Ethernet/IP exposed.
- Discussion on using Shodan to gather device details and internal IP addresses.
- Introduction to the ENCO Controller Simulator and Modbus Swiss Army Knife.
- Searching Shodan for ENCO controllers exposed in Ukraine.
- Demonstration of connecting to an exposed ENCO controller via Telnet and Modbus.
- Mention of alternative search engines like Censys and ZoomEye.
Cited Sources
- Shodan — Used to search for exposed OT/ICS devices.
- Censys — Alternative search engine for internet-connected devices.
- ZoomEye — Another search engine for internet-connected devices.
- TryHackMe OT/ICS Room — Hands-on room for learning OT/ICS security.
- ENCO Controller Simulator — Simulator used to practice attacking ENCO controllers.
- Modbus Swiss Army Knife — Tool for interacting with Modbus devices.
- NSA Elite Wolf Project — Source of snort signatures used to find exposed PLCs.
Concurring Sources
Contribution & Novelties
This video provides a practical, hands-on approach to discovering and attacking exposed OT/ICS assets, which is highly relevant given recent geopolitical tensions. It offers a unique perspective by combining Shodan searches with Google dorking and the NSA’s Elite Wolf project, and introduces custom tools for simulation. The presenter’s emphasis on using simulators for ethical testing is a valuable contribution to the community.
Pour aller plus loin :
- Shodan — The primary tool demonstrated for finding exposed devices.
- Censys — An alternative search engine with similar capabilities.
- ZoomEye — A Chinese-based search engine with unique coverage.
- TryHackMe — Platform offering hands-on cybersecurity training, including OT/ICS rooms.
- Modbus Protocol — The industrial protocol discussed, known for its lack of authentication.
- EtherNet/IP — Another industrial protocol used in Rockwell devices.
- FrostyGoop Attack — The attack on ENCO controllers referenced in the video.
139 words
Radar Profile
The radar chart shows high scores in quantity of information, quality of information, and reliability, with a slightly lower but still solid score in technical level. This indicates a well-balanced, informative, and credible tutorial.
💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.