OT Cyber Weekly: Finding & Attacking OT/ICS Assets on the Internet

OT Cyber Weekly: Finding & Attacking OT/ICS Assets on the Internet

🎙 Mike Holcomb 👥 27K 📅 April 29, 2026 ⏱ 61 min 👁 324 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICSShodanPLCModbusEtherNet/IP

Summary

This video, part of the ‘OT Cyber Weekly’ series, focuses on finding and attacking OT/ICS assets exposed to the internet. The presenter, Mike Holcomb, begins by discussing recent geopolitical tensions and the increased attention on exposed PLCs and HMIs. He emphasizes that this is not a new issue, as Shodan was originally created to find such systems. The tutorial demonstrates how to use Shodan to search for devices by port (e.g., TCP 502 for Modbus) and by banner content (e.g., ‘Rockwell Automation’). He highlights that simply having port 502 open does not guarantee Modbus is running, and shows how to use Google to find PLCs via URLs from NSA’s Elite Wolf project. The video also covers how to identify exposed devices via their web interfaces and Ethernet/IP, and how to use Shodan to gather detailed device information. He introduces his own tools, the ENCO Controller Simulator and Modbus Swiss Army Knife, which are used in a TryHackMe room to simulate attacks. The presentation includes real examples of exposed ENCO controllers in Ukraine, related to the FrostyGoat attack. The presenter stresses the ease of finding and attacking these systems, and the importance of securing them. He also mentions alternative search engines like Censys and ZoomEye. The video is a practical guide for security professionals and enthusiasts.

215 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, actionable information for anyone interested in OT/ICS security. It offers a practical methodology for discovering exposed industrial control systems using publicly available tools like Shodan and Google. The presenter demonstrates real-world examples, including live PLCs and ENCO controllers, and explains the implications of their exposure. The argumentation is solid, based on the presenter’s extensive experience and the demonstration of actual techniques. The video also highlights the ease with which attackers can exploit these exposures, reinforcing the need for better security practices. The use of a simulator for ethical testing is a responsible approach, and the presenter clearly advises against attacking live systems.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates a high level of scientific rigor in its methodology, showing step-by-step how to use Shodan and other tools to identify exposed OT assets. The presenter references the NSA’s Elite Wolf project and provides links to his own GitHub repositories and a TryHackMe room, which serve as sources for further learning. The title accurately reflects the content, as the video indeed covers finding and attacking OT/ICS assets. The presentation is well-structured and technically accurate, though it lacks formal citations to academic or industry publications. The presenter’s practical experience adds credibility, but the video is more of a tutorial than a peer-reviewed analysis.

225 words

Title / Content Match

The title accurately reflects the content, which focuses on discovering and attacking OT/ICS assets exposed to the internet.

Quality & Reliability

8/10

The video is a practical tutorial by an experienced OT/ICS security professional, demonstrating real-world techniques for finding and attacking exposed industrial control systems. The methods are well-established and the presenter provides concrete examples and tools. The content is technically accurate and aligns with known security practices, though it lacks formal citations and peer review.

Key Moments

Cited Sources

  • Shodan — Used to search for exposed OT/ICS devices.
  • Censys — Alternative search engine for internet-connected devices.
  • ZoomEye — Another search engine for internet-connected devices.
  • TryHackMe OT/ICS Room — Hands-on room for learning OT/ICS security.
  • ENCO Controller Simulator — Simulator used to practice attacking ENCO controllers.
  • Modbus Swiss Army Knife — Tool for interacting with Modbus devices.
  • NSA Elite Wolf Project — Source of snort signatures used to find exposed PLCs.

Concurring Sources

  • Shodan — The main tool used for finding exposed devices.
  • Censys — Similar to Shodan, used for internet-wide scanning.

Contribution & Novelties

This video provides a practical, hands-on approach to discovering and attacking exposed OT/ICS assets, which is highly relevant given recent geopolitical tensions. It offers a unique perspective by combining Shodan searches with Google dorking and the NSA’s Elite Wolf project, and introduces custom tools for simulation. The presenter’s emphasis on using simulators for ethical testing is a valuable contribution to the community.

Pour aller plus loin :

  • Shodan — The primary tool demonstrated for finding exposed devices.
  • Censys — An alternative search engine with similar capabilities.
  • ZoomEye — A Chinese-based search engine with unique coverage.
  • TryHackMe — Platform offering hands-on cybersecurity training, including OT/ICS rooms.
  • Modbus Protocol — The industrial protocol discussed, known for its lack of authentication.
  • EtherNet/IP — Another industrial protocol used in Rockwell devices.
  • FrostyGoop Attack — The attack on ENCO controllers referenced in the video.

139 words

Radar Profile

The radar chart shows high scores in quantity of information, quality of information, and reliability, with a slightly lower but still solid score in technical level. This indicates a well-balanced, informative, and credible tutorial.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.