Cybersecurity 路 Free

OT Network Monitoring: Zeek, Suricata and Malcolm

Passive network security monitoring for industrial plants with free tools: where to tap, reading Modbus, S7comm, EtherNet/IP, DNP3 and BACnet in Wireshark, Zeek with the CISA ICSNPP parsers, Suricata rules for OT, Malcolm and Security Onion, asset inventory from traffic, baselines, MITRE ATT&CK for ICS detections and alert triage with plant operations.

15 modules 14h 28m of video English 路 self-paced

Inside the course

OT Network Monitoring: Zeek, Suricata and Malcolm: Syllabus at a glanceOT Network Monitoring: Zeek, Suricata and Malcolm: What you will be able to doOT Network Monitoring: Zeek, Suricata and Malcolm: Tools and credits

From the lessons

  • xOT Defense Lab Episode 1: How Passive Monitoring Works in OT Networks

    Why passive monitoring is the first OT security control

    Dragos: OT Cybersecurity

  • Learn Wireshark! Tutorial for BEGINNERS

    Wireshark for OT traffic: capture files, filters and conversations

    Chris Greer

  • ControlLogix, Stratix, Wireshark, Ethernet/IP, CIP

    EtherNet/IP and CIP, DNP3 and BACnet on the wire

    Turtle

  • ZeekWeek 2022 - Two Years of Developing Parsers for Industrial Control System Protocol - Seth Grover

    Zeek for ICS: the CISA ICSNPP parsers

    Zeek

  • Suricata + Zeek: How it Works

    Suricata for OT: rules, ICS keywords and tuning

    Corelight

  • Malcolm - Dashboards Overview

    Hunting in Malcolm and Security Onion: dashboards, Arkime and threat intelligence

    CISA

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Explain why passive monitoring is the safe first control in OT; place a sensor using SPAN or a TAP and size it; decode Modbus/TCP, S7comm, EtherNet/IP, DNP3 and BACnet in Wireshark; run Zeek with ICSNPP and answer questions from its logs; build an asset inventory from traffic; write and test Suricata rules for OT protocols; deploy Malcolm in a lab and hunt in its dashboards and Arkime; baseline normal traffic; map detections to MITRE ATT&CK for ICS; and triage an alert with operations and write the incident note.

  • Place a passive sensor by Purdue level and size a SPAN port, or choose a TAP
  • Read Modbus/TCP, S7comm, EtherNet/IP, DNP3 and BACnet traffic in Wireshark and spot writes and program transfers
  • Run Zeek with CISA's ICSNPP parsers and answer operational questions from its logs
  • Build an OT asset inventory from passive traffic, with evidence for every role
  • Write and test Suricata rules for OT protocols, and tune them without losing the alert
  • Deploy Malcolm in a lab and hunt with its ICS dashboards and Arkime
  • Baseline normal OT traffic and map detections to MITRE ATT&CK for ICS
  • Triage an OT alert with the control room and write a clear incident note

For you

Taking OT Network Monitoring: Zeek, Suricata and Malcolm from the United States

The course project 路 about 12 hours

Monitoring a water treatment plant's control network: sensor plan, passive inventory, OT detections and an incident note

Act as the OT security engineer for a water treatment plant that has never monitored its control network. Plan where the sensors go and size the SPAN ports, build an asset inventory and baseline from a public ICS capture with Zeek and ICSNPP, write and test Suricata detections mapped to MITRE ATT&CK for ICS, hunt in Malcolm, and write the incident note for a suspicious event, all in your own lab.

Sample document pack, 4 documents, filled in for the scenario

  • PlanPassive monitoring pilot: sensor placement plan
  • Asset inventoryControl network asset inventory from passive monitoring
  • RegisterDetection register mapped to ATT&CK for ICS
  • ReportIncident note: unexpected Modbus write to the dosing PLC

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

15 modules 路 48 lessons 路 14h 28m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01Why passive monitoring is the first OT security control31m
  2. 02Where to tap: Purdue levels, SPAN ports and network TAPs40m
  3. 03Wireshark for OT traffic: capture files, filters and conversations49m
  4. 04Modbus/TCP and S7comm on the wire37m
  5. 05EtherNet/IP and CIP, DNP3 and BACnet on the wire1h 41m
  6. 06Zeek fundamentals: logs, UIDs and reading a capture57m
  7. 07Zeek for ICS: the CISA ICSNPP parsers1h 25m
  8. 08Asset inventory from passive traffic1h 18m

Requirements

Who it is for
Intermediate. For control, automation and network engineers and SOC analysts moving into OT. You should know IP addressing and basic Linux commands and have met PLCs or SCADA; ICS Security Foundations covers the systems if they are new to you. No security tool experience is needed.
Software
All free: Wireshark 4.6, Zeek 9.0 with the CISA ICSNPP parsers, Suricata 8.0, Malcolm (CISA) and optionally Security Onion 3, on Linux virtual machines. Public ICS capture files stand in for a live plant. What to download, and how
Hardware
A computer able to run Linux virtual machines. The Wireshark, Zeek and Suricata modules run on a laptop with 8 GB of RAM; Malcolm's published minimum is a host with 8 CPU cores and 24 GB of RAM.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

Every lab runs in your own Linux virtual machines with public ICS capture files. Malcolm needs a host with at least 8 cores and 24 GB RAM, so it is optional on a laptop; Security Onion's import mode is a lighter alternative.

Required

  1. 01

    Wireshark

    Wireshark Foundation

    Free
    Runs on
    Windows 11 or 10 64-bit (x64 or Arm64), Windows Server 2016 or later, macOS (Universal disk image), Linux
    Account
    None needed

    Free, open source software. No licence fee for any use.

  2. 02

    Zeek

    The Zeek Project

    Free
    Runs on
    Linux (binary packages for common distributions), FreeBSD, macOS through Homebrew or MacPorts; on Windows use a Linux virtual machine
    Account
    None needed

    Free, open source software under a BSD licence. No licence fee for any use.

  3. 03

    Suricata

    Open Information Security Foundation (OISF)

    Free
    Runs on
    Linux (Ubuntu PPA and distribution packages), Windows 64-bit installer, macOS and FreeBSD from source or package managers
    Account
    None needed

    Free, open source software under GPL version 2. No licence fee for any use.

  4. 04

    Oracle VirtualBox

    Oracle

    Free
    Runs on
    Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
    Account
    None needed

    The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.

  5. 05

    Ubuntu Desktop

    Canonical

    Free
    Runs on
    64-bit PC (Intel or AMD) or ARM 64-bit. Recommended: 2 GHz dual-core processor, 6 GB RAM, 25 GB free disk space.
    Account
    None needed
    Size
    About 5.9 GB ISO (Intel or AMD 64-bit, current LTS)

    Free to download and use. LTS releases get five years of free security updates, which Ubuntu Pro can extend.

    Alternatives

Optional

Useful, not needed to finish the course.

  1. 06

    Malcolm

    CISA

    Free
    Runs on
    Linux host with Docker or Podman (an installer ISO is also offered); minimum 8 CPU cores and 24 GB RAM, 16 cores and 32 GB recommended
    Account
    None needed

    Free, open source software under the Apache License 2.0, published by CISA and developed by Idaho National Laboratory.

    Official download pagecisagov.github.io
  2. 07

    Security Onion

    Security Onion Solutions

    Free
    Runs on
    Installs from its own ISO image onto a dedicated machine or virtual machine; import mode needs at least 2 cores, 4 GB RAM and 100 GB storage
    Account
    None needed

    Free and open platform; it bundles Zeek, Suricata and Elastic components, each under its own licence. Paid Pro features and support are optional.

    Official download pagesecurityonion.net

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

OT Network Monitoring: Zeek, Suricata and Malcolm at a glance

OT Network Monitoring: Zeek, Suricata and Malcolm is a free, self-paced online course from EDWartens for control, automation and network engineers who run plant networks, and SOC analysts taking on OT monitoring in utilities, water, oil and gas, manufacturing and buildings. It has 15 modules and 14h 28m of video lessons by CISA, Zeek, OISF-Suricata and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
Control, automation and network engineers who run plant networks, and SOC analysts taking on OT monitoring in utilities, water, oil and gas, manufacturing and buildings
Format
15 self-paced modules, 14h 28m of video, written notes, a practice task per module and one final assessment.
Level
Intermediate. Intermediate. For control, automation and network engineers and SOC analysts moving into OT. You should know IP addressing and basic Linux commands and have met PLCs or SCADA; ICS Security Foundations covers the systems if they are new to you. No security tool experience is needed.
Brand
Vendor-neutral
Software
All free: Wireshark 4.6, Zeek 9.0 with the CISA ICSNPP parsers, Suricata 8.0, Malcolm (CISA) and optionally Security Onion 3, on Linux virtual machines. Public ICS capture files stand in for a live plant.
Hardware
A computer able to run Linux virtual machines. The Wireshark, Zeek and Suricata modules run on a laptop with 8 GB of RAM; Malcolm's published minimum is a host with 8 CPU cores and 24 GB of RAM.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
CISA, Zeek, OISF-Suricata, Security Onion, Malcolm Network Traffic Analysis Tool Suite, Dragos: OT Cybersecurity, SANS ICS Security, S4 Events, Chris Greer, Mike Holcomb, Insane Cyber, Keith Jones, Corelight, HackerSploit, Antisyphon Training, MyDFIR, Threat Hunter's Daily, DEFCONConference, ITFreeTraining, Xploit Cyber Security, Yasin Najib, Markus864, Turtle, BrodersenSystems, Horner APG (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

More free courses: Free cyber security courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of OT Network Monitoring: Zeek, Suricata and Malcolm, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

What is OT network monitoring?

OT network monitoring is the passive collection and analysis of traffic on industrial control networks to see every device, every conversation and every change to a controller, without sending anything to the process. This course teaches it with free tools: Wireshark, Zeek with CISA's ICSNPP parsers, Suricata and Malcolm.

Who is this OT security monitoring course for?

It is for control, automation and network engineers who look after plant networks, and for SOC analysts who now have to watch OT. It suits utilities, water, oil and gas, manufacturing, building and data-centre teams, and is a natural next step after ICS Security Foundations or OT and ICS Cybersecurity with ISA/IEC 62443.

Is the course free to learn, and is the software free?

Yes. Every module, the notes, the worked problems, the project and the final assessment are free to learn, and every tool used (Wireshark, Zeek, the ICSNPP parsers, Suricata, Malcolm and Security Onion) is free and open source. The certificate is optional.

Do I need a real plant or PLC to do the labs?

No. All labs run in your own Linux virtual machines with public ICS capture files, so you never touch a live control network. The course is defensive throughout: it never asks you to scan or send commands to equipment you do not own.

What hardware do I need for Zeek, Suricata and Malcolm?

A laptop with 8 GB of RAM runs Wireshark, Zeek and Suricata for the early modules. Malcolm's published minimum is a dedicated host with 8 CPU cores and 24 GB of RAM, so use a lab server or a larger virtual machine for those two modules.

How long does the OT Network Monitoring: Zeek, Suricata and Malcolm course take?

About 21 hours at your own pace: 14.5 hours of video plus notes, worked problems and practice tasks. The optional project, a monitoring pilot for a water treatment plant, takes about 12 hours more.

Which standards and frameworks does it use?

It uses MITRE ATT&CK for ICS to name and map detections, and the Purdue model and the IEC 62443 idea of zones and conduits to decide where sensors go and which conversations should exist. The 62443 programme itself is taught in the neighbouring OT and ICS Cybersecurity with ISA/IEC 62443 course.

What certificate do I get, and how is it verified?

You receive a verifiable certificate of completion from EDWartens when you finish the modules and pass the 15-question final at 60 percent. It carries a unique certificate number and a QR code that open a public verification page showing the course, the modules covered and your final score. It is not a certification from CISA, MITRE, the Zeek project or OISF.

What you walk away with

Your certificate for OT Network Monitoring: Zeek, Suricata and Malcolm

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for OT Network Monitoring: Zeek, Suricata and Malcolm
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • CISAthe Malcolm overviews (software, platform, configuring Malcolm and Hedgehog, live capture, dashboards, Arkime) and the webinar on foundational steps for an OT asset inventory
  • ZeekZeek in Action lessons on the four types of monitoring data, sensor placement and new devices, Seth Grover's ZeekWeek talk on the ICS parsers, and the webinar on visualising OT networks
  • OISF-Suricatathe talk on practical ICS threat hunting with Suricata
  • Security OnionSecurity Onion Essentials 2026 introduction and Robert Lee's talk on ICS/SCADA network security monitoring
  • Malcolm Network Traffic Analysis Tool Suitethe lessons on Arkime sessions and threat intelligence feeds in Malcolm
  • Dragos: OT Cybersecuritythe xOT Defense Lab episodes on passive monitoring, the do-no-harm monitoring talk and the ATT&CK for ICS webinar
  • SANS ICS Securitythe ICS/OT incident response lessons on detection, time-critical analysis, containment considering safety and the tabletop walkthrough
  • S4 Eventsthe ICS ATT&CK framework talk and the panel on whether OT anomaly detection is worth it
  • Chris GreerWireshark for beginners, filtering traffic and simple packet capture hardware
  • Mike HolcombICS/OT packet analysis tools
  • Insane Cyberwriting Suricata rules and the basic rule format
  • Keith Jonespublic ICS captures for Zeek and Wireshark
  • Corelighthow Suricata and Zeek work together
  • HackerSploitthe introduction to Suricata IDS
  • Antisyphon TrainingChris Brenton's getting started with Zeek and pcaps
  • MyDFIRa short introduction to Zeek for network analysis
  • Threat Hunter's DailyZeek conn.log and pivoting with connection UIDs
  • DEFCONConferenceNorman Lundt's talk on extending Zeek for ICS defence
  • ITFreeTrainingTAP and SPAN explained
  • Xploit Cyber SecurityModbus packet analysis in Wireshark
  • Yasin NajibModbus/TCP troubleshooting with Wireshark
  • Markus864setting up Wireshark to monitor PLC network traffic
  • TurtleControlLogix EtherNet/IP and CIP traffic in Wireshark
  • BrodersenSystemsDNP3 theory and a hands-on example
  • Horner APGhands-on BACnet/IP

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.