Pre-DEFCON Session: OSINT for OT/ICS

Pre-DEFCON Session: OSINT for OT/ICS

🎙 Mike Holcomb 👥 27K 📅 August 2, 2026 ⏱ 48 min 👁 539 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OSINTOT/ICSShodanGoogle DorkingPLC

Summary

In this pre-DEFCON session, Mike Holcomb provides an overview of Open Source Intelligence (OSINT) techniques for Operational Technology (OT) and Industrial Control Systems (ICS). He emphasizes that a wealth of information about industrial systems is publicly available and can be leveraged by both attackers and defenders. The session begins with a discussion of the Elite Wolf Project, an NSA release of Snort signatures for OT, and demonstrates how to use Google to find exposed Rockwell PLCs by searching for specific URL patterns. He then shows a custom script that scrapes IP addresses from a PLC’s web interface and maps them geographically, revealing connections from various locations. The talk covers Shodan, a popular search engine for internet-connected devices, and explains how to refine searches to find actual control systems, such as using the term ‘slave’ in Modbus searches. He also mentions alternative tools like Censys and ZoomEye. The session includes practical tips, such as using Shodan’s explore feature and cheat sheets, and highlights the importance of understanding OT-specific protocols and devices. The overall message is that OSINT is a powerful and accessible method for identifying exposed OT assets, which is crucial for improving security.

193 words

Critical Evaluation

Value of the Information & Strength of the Argument

The session provides valuable, actionable information for both offensive and defensive security practitioners. The speaker demonstrates real-world techniques, such as using Google to find exposed PLCs and custom scripts for IP geolocation, which are immediately applicable. The argumentation is grounded in practical examples and the speaker’s extensive experience in OT security. However, the session lacks formal citations for some claims, and the effectiveness of the techniques may vary depending on the target environment. The speaker’s enthusiasm and clear explanations enhance the value, but the session is more of a practical tutorial than a rigorous scientific analysis.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates a good understanding of the subject, but the session is not heavily sourced. He mentions the Elite Wolf Project, Shodan, Censys, and ZoomEye, but does not provide specific references or URLs. The title accurately reflects the content, and the session is well-structured. The speaker’s credibility is established through his experience and the practical demonstrations. However, the lack of formal citations and the reliance on anecdotal evidence reduce the scientific rigor. The session would benefit from referencing official documentation or research papers to support the claims.

199 words

Title / Content Match

The title accurately reflects the content: a pre-DEFCON session focused on OSINT techniques for OT/ICS environments.

Quality & Reliability

7/10

The session provides practical, hands-on demonstrations of OSINT techniques for OT/ICS, based on the speaker's extensive experience. Claims are generally supported by live examples, but some assertions lack formal citations. The speaker demonstrates a good understanding of the subject, but the content is largely anecdotal and not peer-reviewed.

Key Moments

Cited Sources

  • Elite Wolf Project — Mentioned as an NSA release of Snort signatures for OT.
  • Shodan — Used for searching internet-connected devices, including ICS.
  • Censys — Mentioned as an alternative to Shodan.
  • ZoomEye — Mentioned as a Chinese alternative to Shodan.

Concurring Sources

  • Shodan — The speaker's demonstration aligns with Shodan's capabilities.
  • Censys — Mentioned as an alternative, consistent with its scanning capabilities.

Contribution & Novelties

The session provides a practical, hands-on approach to OSINT for OT/ICS, demonstrating techniques that are often overlooked. The speaker’s custom scripts and use of Google dorking offer novel ways to discover exposed industrial systems. The emphasis on using publicly available information for both attack and defense is a valuable contribution to the field.

Pour aller plus loin :

  • Shodan — The primary tool for finding internet-connected devices, including ICS.
  • Censys — An alternative search engine with full TCP port scanning.
  • ZoomEye — A Chinese search engine for internet-connected devices.
  • Elite Wolf Project — NSA’s Snort signatures for OT.
  • Google Hacking Database — A collection of Google dorks for finding exposed systems.

111 words

Radar Profile

The radar profile shows high scores in quantity of information and technical level, indicating a content-rich session with practical depth. The quality and reliability scores are moderate, reflecting the anecdotal nature and lack of formal citations. The overall balance suggests a valuable but not rigorously sourced presentation.

Reliability 7/10

💬 No comments were provided for analysis.