Intro to OT ICS Penetration Testing (Part 5):  Finding Exposed OT Assets Hidden on the Internet

Intro to OT ICS Penetration Testing (Part 5): Finding Exposed OT Assets Hidden on the Internet

🎙 Mike Holcomb 👥 27K 📅 December 4, 2025 ⏱ 71 min 👁 1K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICSOSINTShodanDNSReconnaissance

Summary

This video is part 5 of a series on OT/ICS penetration testing, focusing on finding exposed OT assets on the internet using OSINT techniques. The instructor, Mike Holcomb, explains the importance of passive reconnaissance to avoid disrupting critical infrastructure. He covers the methodology, starting with domain discovery using tools like DNSlytics and DNSdumpster, then moving to IP address and subnet identification, and finally using Shodan to find open ports, services, and vulnerabilities. He demonstrates practical labs, including using Google to find exposed assets via copyright statements and the NSA’s EliteWolf project. The video emphasizes the need to distinguish between cloud-hosted and on-premise assets and to verify ownership before testing. It concludes with a summary and additional resources.

117 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, practical information for OT/ICS penetration testers, with clear explanations and real-world examples. The argumentation is solid, emphasizing the importance of passive reconnaissance to avoid impacting critical systems. The instructor demonstrates tools and techniques effectively, making the content actionable.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates rigorous use of OSINT tools and techniques, with references to well-known resources like Shodan, DNSlytics, and DNSdumpster. The title accurately reflects the content. The instructor provides course materials and links to further training, but does not cite formal academic sources. The content is based on practical experience and industry best practices.

111 words

Title / Content Match

The title accurately reflects the content, which focuses on finding exposed OT assets via OSINT.

Quality & Reliability

8/10

The video provides a structured tutorial on OSINT techniques for OT/ICS asset discovery, with practical demonstrations and references to established tools and methodologies. The content is accurate and aligns with industry best practices, though it lacks formal citations and peer review.

Chapters

Cited Sources

Concurring Sources

  • Shodan — Used in the video to find exposed OT assets.
  • DNSlytics — Used for WHOIS and DNS lookups.
  • DNSdumpster — Used for domain mapping.

Contribution & Novelties

The video provides a practical, step-by-step guide to OSINT for OT/ICS asset discovery, with a focus on passive techniques. It offers unique insights into using copyright statements and the NSA’s EliteWolf project for finding exposed assets. The inclusion of labs and real-world examples enhances its educational value.

Pour aller plus loin :

  • Shodan — The primary tool for finding internet-exposed devices, including OT/ICS systems.
  • DNSlytics — A domain and IP intelligence tool used for WHOIS and DNS lookups.
  • DNSdumpster — A free domain research tool that maps DNS records and subdomains.
  • Recon-ng — An open-source reconnaissance framework with modules for OSINT.
  • NSA EliteWolf — A tool for identifying internet-exposed control systems.

111 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with a slightly lower technical level, indicating a well-balanced tutorial suitable for intermediate learners. The reliability is high, reflecting the instructor's expertise.

Reliability 8/10