
Intro to OT/ICS Penetration Testing (Part 4): OT/ICS Penetration Test Walkthrough
Keywords
Summary
136 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable, practical insights into OT/ICS penetration testing, bridging the gap between IT and OT security. The argumentation is solid, grounded in real-world examples like the Unitronics attack and the use of established frameworks. The instructor clearly explains the methodology and emphasizes safety and authorization. The content is well-structured, with a logical flow from reconnaissance to impact, and includes hands-on labs to reinforce learning. The discussion of passive vs. active reconnaissance and the importance of understanding the physical process adds depth. The video is particularly useful for those new to OT security, offering a comprehensive overview without oversimplifying.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates scientific rigor by referencing MITRE ATT&CK for ICS and using industry-standard tools. The sources cited are primarily the course materials and the instructor’s own resources, which are appropriate for a tutorial. The title accurately reflects the content, and the video stays on topic. The instructor’s expertise is evident, and the content is technically accurate. However, as a tutorial, it does not provide formal citations or peer-reviewed references, which is typical for this format. The inclusion of labs and practical examples enhances credibility. Overall, the video is a reliable educational resource for OT/ICS penetration testing.
212 words
Title / Content Match
The title accurately reflects the content: a walkthrough of OT/ICS penetration testing, consistent with the series.
Quality & Reliability
8/10
The video is a practical tutorial by an experienced professional, covering OT/ICS penetration testing methodology with real-world examples and labs. It references established frameworks like MITRE ATT&CK for ICS and uses tools like Shodan, Wireshark, and Nmap. The content is well-structured and technically accurate, though it is not peer-reviewed and relies on the author's expertise.
Chapters
- Introduction
- The OT Penetration Testing Methodology
- Case Study: Unitronics, Water Treatment & Breweries
- What Does a Hacked OT/ICS System Look Like?
- IT Penetration Testing Methodology
- MITRE ATT&CK for ICS
- Reconnaissance & OSINT
- Active Recon vs Passive Recon
- Using Shodan to Find Exposed OT Assets like PLCs and HMIs
- Lab 4.1: Using Shodan to Find Externally Exposed Assets
- How do attackers and hackers gain Initial Access?
- The Purdue Model for Understanding OT/ICS Cyber Attacks
- Discovery & Collection
- Using Wireshark to Find Active Hosts
- Lab 4.2: Using Wireshark to Examine Modbus Traffic
- Using Nmap to Enumerate Assets with Modbus
- Finding a Human Machine Interface (HMI)
- Using Programmable Logic Controller (PLC) Development Tools for Gathering
- Lab 4.3: What Does an OT/ICs Attacker See?
- Execution
- Living Off the Land, PowerShell, Malicious Firmware, SCADA Manager
- Execution Example
- Using the Modbus Swiss Army Knife
- Lab 4.4: Manipulating Industrial Processes
- Lateral Movement
- Persistence
- Creating Malicious Scheduled Tasks in Windows
- Scheduling Evil Tasks
- Evasion
- Using Modbus for Command & Control
- Lab 4.6: Command & Control Over Modbus
- Inhibit Response Function
- Impair Process Control
- Fuzzing Tags & Data Points in Memory
- Impact
- THANK YOU!!!
Cited Sources
- Course Materials Download — Provided in the video description for accessing lab manuals and associated files.
- Newsletter Signup — Mentioned in the video description for additional OT/ICS cybersecurity content.
- Live Training Schedule — Mentioned in the video description for upcoming training sessions.
Concurring Sources
- MITRE ATT&CK for ICS — The video references this framework for structuring the methodology.
- Shodan — Used in the video for reconnaissance of exposed OT assets.
- Wireshark — Used in the video for network traffic analysis.
Contribution & Novelties
This video provides a structured walkthrough of OT/ICS penetration testing, emphasizing the differences from IT pen testing. It offers practical labs and real-world case studies, making it accessible for beginners. The focus on understanding the physical process and using tools like Shodan and Modbus is particularly valuable.
Pour aller plus loin :
- MITRE ATT&CK for ICS — Official framework for ICS attack techniques.
- Shodan — Search engine for internet-connected devices, used in the video.
- Wireshark — Network protocol analyzer used in the labs.
- Modbus Protocol — Official Modbus protocol specification.
- Purdue Model — Reference model for industrial control system architecture.
100 words
Radar Profile
The radar profile shows high scores in quantity and quality of information, and moderate technical level, indicating a well-balanced tutorial. The reliability score is also high, reflecting the instructor's expertise and use of established frameworks.