Cybersecurity 路 Free
OT Network Monitoring: Zeek, Suricata and Malcolm
Passive network security monitoring for industrial plants with free tools: where to tap, reading Modbus, S7comm, EtherNet/IP, DNP3 and BACnet in Wireshark, Zeek with the CISA ICSNPP parsers, Suricata rules for OT, Malcolm and Security Onion, asset inventory from traffic, baselines, MITRE ATT&CK for ICS detections and alert triage with plant operations.
Inside the course



From the lessons

Why passive monitoring is the first OT security control
Dragos: OT Cybersecurity

Wireshark for OT traffic: capture files, filters and conversations
Chris Greer

EtherNet/IP and CIP, DNP3 and BACnet on the wire
Turtle

Zeek for ICS: the CISA ICSNPP parsers
Zeek

Suricata for OT: rules, ICS keywords and tuning
Corelight

Hunting in Malcolm and Security Onion: dashboards, Arkime and threat intelligence
CISA
Lesson frames belong to the creators named in the Credits below and are shown from YouTube.
What you will learn
Explain why passive monitoring is the safe first control in OT; place a sensor using SPAN or a TAP and size it; decode Modbus/TCP, S7comm, EtherNet/IP, DNP3 and BACnet in Wireshark; run Zeek with ICSNPP and answer questions from its logs; build an asset inventory from traffic; write and test Suricata rules for OT protocols; deploy Malcolm in a lab and hunt in its dashboards and Arkime; baseline normal traffic; map detections to MITRE ATT&CK for ICS; and triage an alert with operations and write the incident note.
- Place a passive sensor by Purdue level and size a SPAN port, or choose a TAP
- Read Modbus/TCP, S7comm, EtherNet/IP, DNP3 and BACnet traffic in Wireshark and spot writes and program transfers
- Run Zeek with CISA's ICSNPP parsers and answer operational questions from its logs
- Build an OT asset inventory from passive traffic, with evidence for every role
- Write and test Suricata rules for OT protocols, and tune them without losing the alert
- Deploy Malcolm in a lab and hunt with its ICS dashboards and Arkime
- Baseline normal OT traffic and map detections to MITRE ATT&CK for ICS
- Triage an OT alert with the control room and write a clear incident note
For you
Taking OT Network Monitoring: Zeek, Suricata and Malcolm from the United States
- Free in the United States, as everywhere, and self-paced: lessons, notes and the final assessment are open at any hour, so your time zone and shift pattern do not matter.
- The optional certificate for learners in the United States is a one-off US$28.99. What you get for it
- Plants across the Americas most often run Allen-Bradley, Siemens and Inductive Automation; each has its own free course to take next.
- See automation and engineering jobs in the United States, and what the industry looks like in Houston, Detroit and Chicago.
- EDWartens also has a regional site for the United States, for classroom training and local support: edwartens.com/us.
The course project 路 about 12 hours
Monitoring a water treatment plant's control network: sensor plan, passive inventory, OT detections and an incident note
Act as the OT security engineer for a water treatment plant that has never monitored its control network. Plan where the sensors go and size the SPAN ports, build an asset inventory and baseline from a public ICS capture with Zeek and ICSNPP, write and test Suricata detections mapped to MITRE ATT&CK for ICS, hunt in Malcolm, and write the incident note for a suspicious event, all in your own lab.
Sample document pack, 4 documents, filled in for the scenario
- PlanPassive monitoring pilot: sensor placement plan
- Asset inventoryControl network asset inventory from passive monitoring
- RegisterDetection register mapped to ATT&CK for ICS
- ReportIncident note: unexpected Modbus write to the dosing PLC
Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.
Course content
15 modules 路 48 lessons 路 14h 28m
In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.
- 01Why passive monitoring is the first OT security control3 lessons31m
- 02Where to tap: Purdue levels, SPAN ports and network TAPs3 lessons40m
- 03Wireshark for OT traffic: capture files, filters and conversations3 lessons49m
- 04Modbus/TCP and S7comm on the wire4 lessons37m
- 05EtherNet/IP and CIP, DNP3 and BACnet on the wire3 lessons1h 41m
- 06Zeek fundamentals: logs, UIDs and reading a capture3 lessons57m
- 07Zeek for ICS: the CISA ICSNPP parsers3 lessons1h 25m
- 08Asset inventory from passive traffic2 lessons1h 18m
Requirements
- Who it is for
- Intermediate. For control, automation and network engineers and SOC analysts moving into OT. You should know IP addressing and basic Linux commands and have met PLCs or SCADA; ICS Security Foundations covers the systems if they are new to you. No security tool experience is needed.
- Software
- All free: Wireshark 4.6, Zeek 9.0 with the CISA ICSNPP parsers, Suricata 8.0, Malcolm (CISA) and optionally Security Onion 3, on Linux virtual machines. Public ICS capture files stand in for a live plant. What to download, and how
- Hardware
- A computer able to run Linux virtual machines. The Wireshark, Zeek and Suricata modules run on a laptop with 8 GB of RAM; Malcolm's published minimum is a host with 8 CPU cores and 24 GB of RAM.
Software you need
What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.
Every lab runs in your own Linux virtual machines with public ICS capture files. Malcolm needs a host with at least 8 cores and 24 GB RAM, so it is optional on a laptop; Security Onion's import mode is a lighter alternative.
Required
- 01Free
Wireshark
Wireshark Foundation
- Runs on
- Windows 11 or 10 64-bit (x64 or Arm64), Windows Server 2016 or later, macOS (Universal disk image), Linux
- Account
- None needed
Free, open source software. No licence fee for any use.
Steps
- 1.Open wireshark.org/download.html.
- 2.Download the Windows x64 Installer (or Arm64, or the macOS Universal Disk Image).
- 3.Run the installer and keep the Npcap option ticked on Windows.
- 4.Open Wireshark, pick your network interface and click the blue fin to start capturing.
- Npcap is needed for live capture on Windows. The Windows installer includes it.
- Only capture traffic on networks you own or have written permission to monitor.
Official download pagewireshark.org - 02Free
Zeek
The Zeek Project
- Runs on
- Linux (binary packages for common distributions), FreeBSD, macOS through Homebrew or MacPorts; on Windows use a Linux virtual machine
- Account
- None needed
Free, open source software under a BSD licence. No licence fee for any use.
Steps
- 1.Open zeek.org/get-zeek and note the current release (9.0.0 in October 2026) and the LTS release.
- 2.On an Ubuntu virtual machine, follow the Zeek manual's binary package instructions for your distribution.
- 3.Add Zeek's bin directory to your PATH and check the version with zeek --version.
- 4.Install the CISA ICS parsers with zkg, for example zkg install icsnpp-modbus icsnpp-s7comm.
- 5.Run zeek -C -r on a public capture file and list the .log files it writes.
- Use the LTS release on a production sensor and the current release in the lab.
- Only monitor networks you own or have written permission to monitor.
Official download pagezeek.org - 03Free
Suricata
Open Information Security Foundation (OISF)
- Runs on
- Linux (Ubuntu PPA and distribution packages), Windows 64-bit installer, macOS and FreeBSD from source or package managers
- Account
- None needed
Free, open source software under GPL version 2. No licence fee for any use.
Steps
- 1.Open suricata.io/download and note the stable release (8.0.7 in October 2026).
- 2.On Ubuntu, add the Suricata 8 PPA named on the page and install the suricata package.
- 3.In suricata.yaml, set enabled: yes for the modbus, dnp3 and enip app-layer protocols.
- 4.Test rules offline with suricata -r capture.pcap -S local.rules -l ./out and read out/eve.json.
- On an OT network run Suricata in IDS mode from a SPAN or TAP copy, never inline.
- The Modbus, DNP3 and ENIP parsers ship disabled; rules for them stay silent until enabled.
Official download pagesuricata.io - 04Free
Oracle VirtualBox
Oracle
- Runs on
- Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
- Account
- None needed
The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.
Steps
- 1.Open virtualbox.org/wiki/Downloads.
- 2.Click the package for your host system (for example, Windows hosts).
- 3.Run the installer and accept the network driver prompts.
- 4.Open VirtualBox, click New, choose your ISO file (for example Ubuntu or Windows) and follow the wizard.
- Turn on hardware virtualisation (Intel VT-x or AMD-V) in your PC's BIOS or UEFI if VirtualBox says it is not available.
- You do not need the Extension Pack for normal lab work. Install it only if you need its extra features and your use is personal or educational.
Official download pagevirtualbox.org - 05Free
Ubuntu Desktop
Canonical
- Runs on
- 64-bit PC (Intel or AMD) or ARM 64-bit. Recommended: 2 GHz dual-core processor, 6 GB RAM, 25 GB free disk space.
- Account
- None needed
- Size
- About 5.9 GB ISO (Intel or AMD 64-bit, current LTS)
Free to download and use. LTS releases get five years of free security updates, which Ubuntu Pro can extend.
Steps
- 1.Open ubuntu.com/download/desktop and download the LTS ISO. For ROS 2 courses, get 24.04 LTS or 22.04 LTS from releases.ubuntu.com instead.
- 2.To try it safely, create a new virtual machine in VirtualBox and attach the ISO.
- 3.To install on a real PC, write the ISO to a USB stick (8 GB or more) and boot from it.
- 4.Follow the installer, then run Software Updater when it finishes.
- Your course may name a specific release. ROS 2 Humble needs Ubuntu 22.04 and ROS 2 Jazzy needs Ubuntu 24.04.
- Give a virtual machine at least 25 GB of disk space.
Official download pageubuntu.comAlternatives
- Ubuntu 24.04 LTS: Use for ROS 2 Jazzy.
- Ubuntu 22.04 LTS: Use for ROS 2 Humble.
- Windows Subsystem for Linux: Run Ubuntu inside Windows 10 or 11 without a virtual machine.
Optional
Useful, not needed to finish the course.
- 06Free
Malcolm
CISA
- Runs on
- Linux host with Docker or Podman (an installer ISO is also offered); minimum 8 CPU cores and 24 GB RAM, 16 cores and 32 GB recommended
- Account
- None needed
Free, open source software under the Apache License 2.0, published by CISA and developed by Idaho National Laboratory.
Steps
- 1.Read the system requirements and the quick start on cisagov.github.io/Malcolm.
- 2.Download the latest release from github.com/cisagov/Malcolm/releases onto a Linux host that meets the minimum.
- 3.Run ./scripts/install.py and answer the configuration questions, including the ICS/OT analysis option.
- 4.Complete the authentication set-up, pull the images and start Malcolm with the scripts provided.
- 5.Browse to the host's address and upload a public ICS capture to check that Zeek and Suricata records appear.
- A 16 GB laptop is below the minimum: use it for Zeek and Suricata and run Malcolm on a lab server.
- Set disk limits; a full disk stops ingestion.
Official download pagecisagov.github.io - 07Free
Security Onion
Security Onion Solutions
- Runs on
- Installs from its own ISO image onto a dedicated machine or virtual machine; import mode needs at least 2 cores, 4 GB RAM and 100 GB storage
- Account
- None needed
Free and open platform; it bundles Zeek, Suricata and Elastic components, each under its own licence. Paid Pro features and support are optional.
Steps
- 1.Open securityonion.net/download and download the current Security Onion 3 ISO image.
- 2.Create a virtual machine that meets the hardware page for the mode you choose (import mode is the lightest).
- 3.Boot the ISO, install, and choose Import during setup to analyse capture files.
- 4.Import a public ICS capture and review the alerts and Zeek logs in the web console.
- Security Onion 2.4 reached end of life on 1 October 2026; use version 3.
Official download pagesecurityonion.net
Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.
OT Network Monitoring: Zeek, Suricata and Malcolm at a glance
OT Network Monitoring: Zeek, Suricata and Malcolm is a free, self-paced online course from EDWartens for control, automation and network engineers who run plant networks, and SOC analysts taking on OT monitoring in utilities, water, oil and gas, manufacturing and buildings. It has 15 modules and 14h 28m of video lessons by CISA, Zeek, OISF-Suricata and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.
All course factsHide course facts
- Price
- Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
- Who it is for
- Control, automation and network engineers who run plant networks, and SOC analysts taking on OT monitoring in utilities, water, oil and gas, manufacturing and buildings
- Format
- 15 self-paced modules, 14h 28m of video, written notes, a practice task per module and one final assessment.
- Level
- Intermediate. Intermediate. For control, automation and network engineers and SOC analysts moving into OT. You should know IP addressing and basic Linux commands and have met PLCs or SCADA; ICS Security Foundations covers the systems if they are new to you. No security tool experience is needed.
- Brand
- Vendor-neutral
- Software
- All free: Wireshark 4.6, Zeek 9.0 with the CISA ICSNPP parsers, Suricata 8.0, Malcolm (CISA) and optionally Security Onion 3, on Linux virtual machines. Public ICS capture files stand in for a live plant.
- Hardware
- A computer able to run Linux virtual machines. The Wireshark, Zeek and Suricata modules run on a laptop with 8 GB of RAM; Malcolm's published minimum is a host with 8 CPU cores and 24 GB of RAM.
- Certificate
- Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
- Video lessons by
- CISA, Zeek, OISF-Suricata, Security Onion, Malcolm Network Traffic Analysis Tool Suite, Dragos: OT Cybersecurity, SANS ICS Security, S4 Events, Chris Greer, Mike Holcomb, Insane Cyber, Keith Jones, Corelight, HackerSploit, Antisyphon Training, MyDFIR, Threat Hunter's Daily, DEFCONConference, ITFreeTraining, Xploit Cyber Security, Yasin Najib, Markus864, Turtle, BrodersenSystems, Horner APG (independent creators, credited below)
- Language
- English
- Last updated
- 27 September 2026
A shareable EDWartens certificate
Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.
The course itself stays free whether or not you ever buy one.
Stuck? Ask a practising engineer
A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.
Pairs well with
FreeCybersecurity 路 FreeCompTIA Security+ (SY0-701) Exam PrepPrepare for CompTIA Security+ SY0-701 with Professor Messer's complete free video course: every exam objective across the five domains, with EDWartens notes, worked calculations, practice questions and an optional security project. Exam preparation only: the EDWartens certificate is not the CompTIA Security+ certification, which is earned only by passing CompTIA's exam.
FreeCybersecurity 路 FreeMicrosoft Sentinel and Defender: SC-200 Exam PrepPreparation for Microsoft's SC-200 Security Operations Analyst exam, mapped to the skills measured as of 21 October 2026: KQL from first query to hunting, Microsoft Defender XDR incidents and attack disruption, Defender for Endpoint, Office 365, Identity and Cloud Apps, Purview investigations, Microsoft Sentinel setup, data connectors, analytics rules, automation, Security Copilot and threat hunting.
FreePLC programming 路 FreeSiemens TIA PortalFree Siemens TIA Portal course for beginners: write ladder logic for a simulated S7-1200 and WinCC HMI. Learning is free; the certificate is optional and paid.
FreePLC programming 路 FreeSiemens TIA Portal in Three HoursThe first three hours of the Siemens TIA Portal course, cut to end on a win: what a PLC is, how it is wired, a project configured in TIA Portal, and your first ladder program running in simulation. Finish it in an evening or two, earn a certificate, and carry straight on into the full course.More free courses: Free cyber security courses
Learner reviews
No reviews yet
Reviews here are written only by learners who have finished every module of OT Network Monitoring: Zeek, Suricata and Malcolm, and they are published exactly as written. Finish the course and yours will be the first.
Common questions
What is OT network monitoring?
OT network monitoring is the passive collection and analysis of traffic on industrial control networks to see every device, every conversation and every change to a controller, without sending anything to the process. This course teaches it with free tools: Wireshark, Zeek with CISA's ICSNPP parsers, Suricata and Malcolm.
Who is this OT security monitoring course for?
It is for control, automation and network engineers who look after plant networks, and for SOC analysts who now have to watch OT. It suits utilities, water, oil and gas, manufacturing, building and data-centre teams, and is a natural next step after ICS Security Foundations or OT and ICS Cybersecurity with ISA/IEC 62443.
Is the course free to learn, and is the software free?
Yes. Every module, the notes, the worked problems, the project and the final assessment are free to learn, and every tool used (Wireshark, Zeek, the ICSNPP parsers, Suricata, Malcolm and Security Onion) is free and open source. The certificate is optional.
Do I need a real plant or PLC to do the labs?
No. All labs run in your own Linux virtual machines with public ICS capture files, so you never touch a live control network. The course is defensive throughout: it never asks you to scan or send commands to equipment you do not own.
What hardware do I need for Zeek, Suricata and Malcolm?
A laptop with 8 GB of RAM runs Wireshark, Zeek and Suricata for the early modules. Malcolm's published minimum is a dedicated host with 8 CPU cores and 24 GB of RAM, so use a lab server or a larger virtual machine for those two modules.
How long does the OT Network Monitoring: Zeek, Suricata and Malcolm course take?
About 21 hours at your own pace: 14.5 hours of video plus notes, worked problems and practice tasks. The optional project, a monitoring pilot for a water treatment plant, takes about 12 hours more.
Which standards and frameworks does it use?
It uses MITRE ATT&CK for ICS to name and map detections, and the Purdue model and the IEC 62443 idea of zones and conduits to decide where sensors go and which conversations should exist. The 62443 programme itself is taught in the neighbouring OT and ICS Cybersecurity with ISA/IEC 62443 course.
What certificate do I get, and how is it verified?
You receive a verifiable certificate of completion from EDWartens when you finish the modules and pass the 15-question final at 60 percent. It carries a unique certificate number and a QR code that open a public verification page showing the course, the modules covered and your final score. It is not a certification from CISA, MITRE, the Zeek project or OISF.
What you walk away with
Your certificate for OT Network Monitoring: Zeek, Suricata and Malcolm
Finish the course, pass the final, and this is the document with your name on it.

Verifiable by anyone
Adds to LinkedIn in one click
QR code on the certificate
Names what you can do
A permanent link
Earned, not attended
Learning is free. The certificate is optional.
Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.
Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.
Credits
Who made the video lessons
The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
- CISAthe Malcolm overviews (software, platform, configuring Malcolm and Hedgehog, live capture, dashboards, Arkime) and the webinar on foundational steps for an OT asset inventory
- ZeekZeek in Action lessons on the four types of monitoring data, sensor placement and new devices, Seth Grover's ZeekWeek talk on the ICS parsers, and the webinar on visualising OT networks
- OISF-Suricatathe talk on practical ICS threat hunting with Suricata
- Security OnionSecurity Onion Essentials 2026 introduction and Robert Lee's talk on ICS/SCADA network security monitoring
- Malcolm Network Traffic Analysis Tool Suitethe lessons on Arkime sessions and threat intelligence feeds in Malcolm
- Dragos: OT Cybersecuritythe xOT Defense Lab episodes on passive monitoring, the do-no-harm monitoring talk and the ATT&CK for ICS webinar
- SANS ICS Securitythe ICS/OT incident response lessons on detection, time-critical analysis, containment considering safety and the tabletop walkthrough
- S4 Eventsthe ICS ATT&CK framework talk and the panel on whether OT anomaly detection is worth it
- Chris GreerWireshark for beginners, filtering traffic and simple packet capture hardware
- Mike HolcombICS/OT packet analysis tools
- Insane Cyberwriting Suricata rules and the basic rule format
- Keith Jonespublic ICS captures for Zeek and Wireshark
- Corelighthow Suricata and Zeek work together
- HackerSploitthe introduction to Suricata IDS
- Antisyphon TrainingChris Brenton's getting started with Zeek and pcaps
- MyDFIRa short introduction to Zeek for network analysis
- Threat Hunter's DailyZeek conn.log and pivoting with connection UIDs
- DEFCONConferenceNorman Lundt's talk on extending Zeek for ICS defence
- ITFreeTrainingTAP and SPAN explained
- Xploit Cyber SecurityModbus packet analysis in Wireshark
- Yasin NajibModbus/TCP troubleshooting with Wireshark
- Markus864setting up Wireshark to monitor PLC network traffic
- TurtleControlLogix EtherNet/IP and CIP traffic in Wireshark
- BrodersenSystemsDNP3 theory and a hands-on example
- Horner APGhands-on BACnet/IP
If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.
