Lab 01 - Basic OT-ICS Device Detection
Discovery of OT-ICS devices through network scanning, service enumeration, and industrial protocol analysis.
A progressive series to learn cybersecurity in OT/ICS industrial systems.
Recommendation: follow the numerical order. Each lab includes objective, steps, and expected outcome.
Discovery of OT-ICS devices through network scanning, service enumeration, and industrial protocol analysis.
Discovery and analysis of a Siemens S7 PLC through network scanning, service enumeration, and identification of vendor-specific protocols.
Discovery and analysis of a simulated service station control system through host identification, service enumeration, and ATG device analysis.
Configuration of a Modbus/TCP simulator and interaction with holding registers through network discovery and Modbus register access.
Discovery of subnet ranges, active OT-ICS hosts, TCP/UDP services, and intercepted Modbus/TCP communications.
Discovery of industrial devices through subnet enumeration, service analysis, web interface inspection, and SNMP information gathering.
Discovery of an OT-ICS host, identification of exposed services, and access to a management interface protected by default credentials.
Exploration of subnet masks, IP addressing, network segmentation, and routing behavior across multiple workstations.
Nmap scanning techniques in corporate subnets using ICMP, ARP, TCP and UDP analysis.
Introduction to TCP/IP communication, ARP discovery and TCP three-way handshake analysis.
Simulation of an adversary-in-the-middle attack to capture session cookies and bypass MFA in an OT-ICS environment.
Exploration of fundamental network topologies through ARP analysis, ICMP testing and Layer 3 path mapping.
Security assessment of an industrial network involving IT-to-OT pivoting, service discovery and enumeration.