
Pre-DEFCON Session: OSINT for OT/ICS
Keywords
Summary
193 words
Critical Evaluation
Value of the Information & Strength of the Argument
The session provides valuable, actionable information for both offensive and defensive security practitioners. The speaker demonstrates real-world techniques, such as using Google to find exposed PLCs and custom scripts for IP geolocation, which are immediately applicable. The argumentation is grounded in practical examples and the speaker’s extensive experience in OT security. However, the session lacks formal citations for some claims, and the effectiveness of the techniques may vary depending on the target environment. The speaker’s enthusiasm and clear explanations enhance the value, but the session is more of a practical tutorial than a rigorous scientific analysis.
Scientific Rigor, Source Quality, Title Accuracy
The speaker demonstrates a good understanding of the subject, but the session is not heavily sourced. He mentions the Elite Wolf Project, Shodan, Censys, and ZoomEye, but does not provide specific references or URLs. The title accurately reflects the content, and the session is well-structured. The speaker’s credibility is established through his experience and the practical demonstrations. However, the lack of formal citations and the reliance on anecdotal evidence reduce the scientific rigor. The session would benefit from referencing official documentation or research papers to support the claims.
199 words
Title / Content Match
The title accurately reflects the content: a pre-DEFCON session focused on OSINT techniques for OT/ICS environments.
Quality & Reliability
7/10
The session provides practical, hands-on demonstrations of OSINT techniques for OT/ICS, based on the speaker's extensive experience. Claims are generally supported by live examples, but some assertions lack formal citations. The speaker demonstrates a good understanding of the subject, but the content is largely anecdotal and not peer-reviewed.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and welcome, mention of DEFCON and ICS Village.
- Discussion of the Elite Wolf Project and its Snort signatures.
- Demonstration of using Google to find exposed Rockwell PLCs.
- Explanation of the custom script 'trace face' for IP geolocation.
- Introduction to Shodan and its history.
- Demonstration of Shodan search for Modbus devices.
- Discussion of alternative tools like Censys and ZoomEye.
- Tips for refining Shodan searches and using cheat sheets.
- Conclusion and final thoughts on OSINT for OT/ICS.
Cited Sources
- Elite Wolf Project — Mentioned as an NSA release of Snort signatures for OT.
- Shodan — Used for searching internet-connected devices, including ICS.
- Censys — Mentioned as an alternative to Shodan.
- ZoomEye — Mentioned as a Chinese alternative to Shodan.
Concurring Sources
Contribution & Novelties
The session provides a practical, hands-on approach to OSINT for OT/ICS, demonstrating techniques that are often overlooked. The speaker’s custom scripts and use of Google dorking offer novel ways to discover exposed industrial systems. The emphasis on using publicly available information for both attack and defense is a valuable contribution to the field.
Pour aller plus loin :
- Shodan — The primary tool for finding internet-connected devices, including ICS.
- Censys — An alternative search engine with full TCP port scanning.
- ZoomEye — A Chinese search engine for internet-connected devices.
- Elite Wolf Project — NSA’s Snort signatures for OT.
- Google Hacking Database — A collection of Google dorks for finding exposed systems.
111 words
Radar Profile
The radar profile shows high scores in quantity of information and technical level, indicating a content-rich session with practical depth. The quality and reliability scores are moderate, reflecting the anecdotal nature and lack of formal citations. The overall balance suggests a valuable but not rigorously sourced presentation.
💬 No comments were provided for analysis.