OT Security Expert
Three days at the plant: read industrial protocols byte by byte, run attacks under control, and write the detection rule on the capture you made yourself.
Malware that speaks control systems itself
In 2016 Industroyer spoke the control protocols directly: IEC 101, IEC 104, IEC 61850 and OPC, with no detour through an operator station. A year later TRITON went for the safety system of a plant, the last protective layer. PIPEDREAM became known in 2022 and is not a tool for one target but a kit for a class of device: switch the operating mode, read and write programs, speak OPC UA and Modbus, all of it prepared.
Malware of that kind is not recognised by a file name. It shows up when somebody reads the protocol it speaks, can name its capabilities in the code, and writes a rule that catches its traffic. A sandbox is of little help: without the target device the sample does not show its behaviour.
That is hand work, and it is the subject of this training.
Three days at the device
The Professional lays the foundation: how a plant is built, its protocols, its architecture, its detection. The Expert builds the skills on top of that, over three days with around 80 per cent exercises.
The three days build on each other. Having read a protocol yourself, you can attack with it. Having attacked yourself, you know what is in your own capture, and you notice at once what your detection rule misses. So on day three every team writes rules against the traffic it produced on day two.
Protocols
Each team works against its own instance of the course plant. It serves the same process values over several protocols at the same time. There is a reason for that. Where a register carries no name, a second protocol reveals which quantity sits behind it. So nothing is guessed. Every protocol is worked in the same four steps. Read it with the standard tool, build your own request, walk the undocumented address space, then take a frame apart by hand.
- Zones and test planning. Derive a test plan from a plant's zone concept, recording what may be tested and who approves it
- Modbus TCP and RTU. Build your own requests. On RTU only a short pause separates one frame from the next, there is no length field. You recalculate the checksum yourself
- S7comm and S7comm-plus. Tell the two Siemens protocols apart. The classic one transmits unprotected, the newer one protects integrity
- Profinet DCP. Find devices at the Ethernet layer, with no IP address
- OPC UA. Browse the address space and judge which security policy a server really offers, and whether anonymous login is open
- BACnet/IP. The building automation protocol that often shares the same network. A single broadcast is enough to list every device on a site
- An unknown protocol. Derive its structure with no specification and no dissector
- Real captures. Check your own results against curated recordings from field devices
Offensive OT security
First known attacks on control systems are taken apart, then the same techniques are run under control against the course plant. Every team records as it goes; those captures are the material for day three.
- Case analysis. We take Industroyer, Industroyer2, TRITON and PIPEDREAM apart. For each case we record which protocol was attacked, which capability the malware carried and where it sat in the ICS kill chain
- MITRE ATT&CK for ICS. Every step you take in the lab is mapped onto a technique, not only the steps from the case studies
- Reconnaissance and the traces it leaves. We measure how much traffic each method generates and how much of it becomes visible in the control room
- Process manipulation. Change setpoints and registers. Force outputs to a fixed value the control program can no longer overwrite. Each of these interventions is noticed to a very different degree
- Attacks on the controller. Switch the operating mode, read and write programs, judge protection levels on Siemens and Codesys
- Identity manipulation. Change device identifiers over Profinet DCP, and see why that is harder to unpick forensically
- The way from IT into OT. Reconstruct a real attack path and pick the most effective countermeasure
- Classes of intervention. Before every command, record what it triggers, who approves it and how it is undone
Defensive OT security
Analyse malware and build detection, on the traffic from the day before. No endpoint agent runs on a controller, so the usual source is gone. We build three others in its place. Detection from signatures, detection from deviation against a baseline, and checks on device and process integrity.
- ICS malware triage. Place an unknown sample statically and name its capabilities from the protocol code, with no target device and no usable sandbox
- YARA. Derive a rule from the sample that holds, and check it against false positives
- Intrusion detection for OT. Turn industrial protocols such as Modbus, S7comm, IEC 104 and Profinet into events you can work with
- Rules and signatures. Write your own detection rules for those protocols and judge whether existing rulesets are fit for purpose
- Baselining and whitelisting. Define which devices may talk to each other and which function codes are permitted. Everything else stands out, with no signature needed
- Process-aware detection. Check setpoints and readings for physical plausibility rather than only looking at packets
- Device integrity. Compare program states and checksums on a controller where no agent is available
- SIEM and use cases. Feed OT sources into the SIEM, write use cases along MITRE ATT&CK for ICS, and keep the alert volume down
- Detection engineering. Test every rule against your own capture replayed, before it counts as finished
- Final exercise and report. You work an incident where the material is incomplete, and write a technical report covering the reporting duties under NIS2
Who the training is aimed at
- OT security leads who have to judge test reports and vendor statements on their merits
- SOC and control room staff running or introducing detection for industrial protocols
- Automation engineers with security responsibility
- Auditors, consultants and assessors who want to substantiate their own findings
Assumed are the Professional or comparable practice, confidence with Wireshark and the command line, and Python at reading level. Scripts get adapted, not written from scratch. For beginners the pace is too dense.
What participants can do afterwards
- Take a capture apart field by field, even where the analysis tool does not resolve it
- Open up an address space with no project file
- Proceed methodically on an unknown protocol
- Say in advance what a test action triggers, who approves it and how it is undone
- State a finding at a defensible level of evidence and name what was left untested
- Change process values and device identities and judge the consequences for plant and control room
- Write detection rules and YARA signatures, and judge another author's
- Connect OT sources to a SIEM and write use cases for them
- Build a baseline and find deviations that have no signature
- Write a technical incident report, including the reporting duties under NIS2
Format, length, assessment
Format
On site, in-house or as an open course.
Length
Three days, 24 teaching units.
Hands-on
Around 80 per cent, each team on a plant of its own.
Group size
Eight to twelve people, in teams of two or three.
Prerequisites
The Professional or comparable practice, Wireshark, the command line, Python at reading level.
Assessment
An exam of 25 questions, a final exercise, an incident report.
Common questions about the Expert
The Expert runs with groups of eight to twelve. Price and dates depend on whether you book in-house or places on an open course. Ask us and you get both, with a named contact.
Not necessarily, but comparable practice is assumed. If you are unsure, talk to us and we will settle it in five minutes.
A laptop with administrator rights, Docker working and Wireshark installed. Lab access, materials and all captures and scripts come from us.
The exercises run on the team instances of the simulated plant, alongside curated captures from real field devices. The laboratory rack with its Siemens controllers is there for demonstration and comparison.
Ask for dates and terms.
The Expert runs with groups of eight to twelve. Tell us how many places you need and whether in-house or open, and you get dates and a price.