OT Threat Hunting: What Actually Works in ICS Environments with Joe Slowik

OT Threat Hunting: What Actually Works in ICS Environments with Joe Slowik

🎙 Joe Slowik 👥 2K 📅 June 15, 2026 ⏱ 54 min 👁 106 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

threat huntingOT securityICSvisibilityAI in cybersecurity

Summary

In this episode of OT Office Hours, Sam Becker interviews Joe Slowik, a seasoned OT security expert, about the realities of threat hunting in industrial control systems (ICS) and critical infrastructure. Slowik emphasizes that threat hunting is not primarily about finding adversaries but about translating threat intelligence into persistent detections. He stresses the importance of understanding one’s own environment and normal behavior before hunting. The conversation covers the myth of proactive hunting, the balance between indicator-based and behavior-based detection, the challenges of asset inventory and visibility, and the role of AI in both defense and offense. Slowik shares his experience using AI as a research assistant and warns about the risks of knowledge leakage and over-reliance on AI outputs, especially for less experienced professionals. He also discusses the need for human review in critical applications and the potential for AI to enable low-skilled threat actors. The episode provides practical insights for defenders in OT environments.

155 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high, offering practical insights from a seasoned practitioner. Slowik debunks common myths about threat hunting, such as the idea that it is purely proactive, and provides a nuanced view of behavior-based detection. His argumentation is solid, grounded in real-world experience and logical reasoning. He effectively explains the trade-offs between specificity and false positives, and the importance of understanding normal behavior. The discussion on AI is balanced, acknowledging both its utility and risks. The arguments are coherent and well-supported by examples from his career.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on expert opinion rather than formal research. No specific sources are cited, but Slowik references his experience and mentions organizations like Google Threat Intelligence Group and Microsoft. The title accurately reflects the content, focusing on practical threat hunting. The discussion is well-structured and avoids sensationalism. The lack of formal citations is typical for a webinar format, but the credibility of the speaker adds weight to the claims.

180 words

Title / Content Match

The title accurately reflects the content, which focuses on practical threat hunting in ICS/OT environments.

Quality & Reliability

8/10

High credibility due to Joe Slowik's extensive experience in OT security, including roles at Los Alamos National Laboratory, Dragos, and MITRE. The discussion is grounded in practical knowledge and avoids hype, but it is an opinion-based conversation without formal citations or peer-reviewed sources.

Key Moments

Cited Sources

  • Google Threat Intelligence Group — Mentioned as documenting adversary use of AI.
  • Microsoft Threat Intelligence — Mentioned as documenting adversary use of AI.

Concurring Sources

  • MITRE ATT&CK for ICS — Provides a framework for understanding adversary behavior in ICS, aligning with the discussion on behavior-based detection.
  • SANS ICS Security — Offers training that emphasizes the importance of visibility and understanding normal operations.

Dissenting Sources

  • No discordant sources found — The video does not contradict established knowledge; it aligns with common best practices in OT security.

Contribution & Novelties

The video provides a practical, experience-based perspective on OT threat hunting, emphasizing the importance of understanding normal behavior and the trade-offs in detection strategies. It offers a nuanced view on AI in OT security, highlighting both its potential and risks. The discussion is valuable for practitioners looking to improve their threat hunting programs.

Pour aller plus loin :

88 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates a well-rounded, credible discussion that is accessible to a broad audience while still providing valuable insights for practitioners.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.