
OT Security Assessment: Testing a Plant Without Stopping It
The assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.
- Write rules of engagement with a window, a named owner and an abort condition, for a plant that cannot stop
- Draw the zones yourself and test each conduit from the side it is meant to protect
- Capture and read ICS traffic in Wireshark, tshark and Zeek before sending a single packet











