
Intro to OT ICS Penetration Testing (Part 5): Finding Exposed OT Assets Hidden on the Internet
Keywords
Summary
117 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable, practical information for OT/ICS penetration testers, with clear explanations and real-world examples. The argumentation is solid, emphasizing the importance of passive reconnaissance to avoid impacting critical systems. The instructor demonstrates tools and techniques effectively, making the content actionable.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates rigorous use of OSINT tools and techniques, with references to well-known resources like Shodan, DNSlytics, and DNSdumpster. The title accurately reflects the content. The instructor provides course materials and links to further training, but does not cite formal academic sources. The content is based on practical experience and industry best practices.
111 words
Title / Content Match
The title accurately reflects the content, which focuses on finding exposed OT assets via OSINT.
Quality & Reliability
8/10
The video provides a structured tutorial on OSINT techniques for OT/ICS asset discovery, with practical demonstrations and references to established tools and methodologies. The content is accurate and aligns with industry best practices, though it lacks formal citations and peer review.
Chapters
- Introduction
- OT Penetration Testing Methodology
- Finding OT/ICS/SCADA Assets Exposed to the Internet
- Reconnaissance: First Phase of OT Pentesting
- OSINT for Passive Reconnaissance in OT/ICS
- From IP Addresses & Open Ports to Services/Applications & Vulnerabilities
- Common OSINT Sources
- Tools for Finding Domain Names
- Starting with a Company's Website
- Searching by Copyright Statements
- Using DNSlytics for WHOIS, DNS & Other Records
- Working with DNSdumpter for Finding More Targets
- Lab 5.1: Domains, Sub-Domains & Fully Qualified Domain Names
- Finding IP Addresses & Subnets
- Using Shodan to Find IP Addresses
- Finding Open Ports
- Finding Services & Applications with OT/ICS Banner Grabbing
- Finding Vulnerabilities
- Shodan "Guessing" for Vulnerabilities
- Example of Internet-Exposed Control System with Vulnerability
- Lab 5.2: Digging Deeper with Shodan and the Shodan API
- Finding Control Systems with the NSA's EliteWolf Project (and Google)
- What's Exposed to the Internet? Bringing It All Together!
- Lab 5.3: Finding Exposed Assets with Google
- More Free OSINT Training for OT/ICS
- THANK YOU!!!
Cited Sources
- Course Materials Download — Downloadable course materials including scripts and resources.
- Newsletter Signup — Sign up for the instructor's newsletter for more OT/ICS cybersecurity content.
- Live Training Schedule — Schedule for live training sessions on OT/ICS cybersecurity.
Concurring Sources
- Shodan — Used in the video to find exposed OT assets.
- DNSlytics — Used for WHOIS and DNS lookups.
- DNSdumpster — Used for domain mapping.
Contribution & Novelties
The video provides a practical, step-by-step guide to OSINT for OT/ICS asset discovery, with a focus on passive techniques. It offers unique insights into using copyright statements and the NSA’s EliteWolf project for finding exposed assets. The inclusion of labs and real-world examples enhances its educational value.
Pour aller plus loin :
- Shodan — The primary tool for finding internet-exposed devices, including OT/ICS systems.
- DNSlytics — A domain and IP intelligence tool used for WHOIS and DNS lookups.
- DNSdumpster — A free domain research tool that maps DNS records and subdomains.
- Recon-ng — An open-source reconnaissance framework with modules for OSINT.
- NSA EliteWolf — A tool for identifying internet-exposed control systems.
111 words
Radar Profile
The radar profile shows high scores in information quantity and quality, with a slightly lower technical level, indicating a well-balanced tutorial suitable for intermediate learners. The reliability is high, reflecting the instructor's expertise.