Intro to OT/ICS Penetration Testing (Part 4): OT/ICS Penetration Test Walkthrough

Intro to OT/ICS Penetration Testing (Part 4): OT/ICS Penetration Test Walkthrough

🎙 Mike Holcomb 👥 27K 📅 October 17, 2025 ⏱ 86 min 👁 2K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICSpenetration testingreconnaissanceinitial accessdiscoveryexploitationimpactModbusShodanMITRE ATT&CK

Summary

This video is the fourth part of a course on OT/ICS penetration testing, focusing on a walkthrough of the entire process. The instructor, Mike Holcomb, outlines a five-phase methodology derived from MITRE ATT&CK for ICS: reconnaissance, initial access, discovery, exploitation, and impact. He uses the Unitronics attack as a case study to illustrate real-world vulnerabilities. The video covers passive and active reconnaissance, using Shodan to find exposed PLCs, and emphasizes the importance of understanding the physical process. It demonstrates network analysis with Wireshark and Nmap, and discusses execution techniques like living off the land and using Modbus for command and control. The instructor also covers lateral movement, persistence, evasion, and impact, including inhibiting response functions and impairing process control. The video includes several labs for hands-on practice, and the instructor provides course materials and encourages questions.

136 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, practical insights into OT/ICS penetration testing, bridging the gap between IT and OT security. The argumentation is solid, grounded in real-world examples like the Unitronics attack and the use of established frameworks. The instructor clearly explains the methodology and emphasizes safety and authorization. The content is well-structured, with a logical flow from reconnaissance to impact, and includes hands-on labs to reinforce learning. The discussion of passive vs. active reconnaissance and the importance of understanding the physical process adds depth. The video is particularly useful for those new to OT security, offering a comprehensive overview without oversimplifying.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by referencing MITRE ATT&CK for ICS and using industry-standard tools. The sources cited are primarily the course materials and the instructor’s own resources, which are appropriate for a tutorial. The title accurately reflects the content, and the video stays on topic. The instructor’s expertise is evident, and the content is technically accurate. However, as a tutorial, it does not provide formal citations or peer-reviewed references, which is typical for this format. The inclusion of labs and practical examples enhances credibility. Overall, the video is a reliable educational resource for OT/ICS penetration testing.

212 words

Title / Content Match

The title accurately reflects the content: a walkthrough of OT/ICS penetration testing, consistent with the series.

Quality & Reliability

8/10

The video is a practical tutorial by an experienced professional, covering OT/ICS penetration testing methodology with real-world examples and labs. It references established frameworks like MITRE ATT&CK for ICS and uses tools like Shodan, Wireshark, and Nmap. The content is well-structured and technically accurate, though it is not peer-reviewed and relies on the author's expertise.

Chapters

Cited Sources

Concurring Sources

  • MITRE ATT&CK for ICS — The video references this framework for structuring the methodology.
  • Shodan — Used in the video for reconnaissance of exposed OT assets.
  • Wireshark — Used in the video for network traffic analysis.

Contribution & Novelties

This video provides a structured walkthrough of OT/ICS penetration testing, emphasizing the differences from IT pen testing. It offers practical labs and real-world case studies, making it accessible for beginners. The focus on understanding the physical process and using tools like Shodan and Modbus is particularly valuable.

Pour aller plus loin :

  • MITRE ATT&CK for ICS — Official framework for ICS attack techniques.
  • Shodan — Search engine for internet-connected devices, used in the video.
  • Wireshark — Network protocol analyzer used in the labs.
  • Modbus Protocol — Official Modbus protocol specification.
  • Purdue Model — Reference model for industrial control system architecture.

100 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, and moderate technical level, indicating a well-balanced tutorial. The reliability score is also high, reflecting the instructor's expertise and use of established frameworks.

Reliability 8/10