Cybersecurity 路 Free
OT Security Assessment: Testing a Plant Without Stopping It
The assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.
Inside the course



From the lessons

Rules of Engagement: Assessing a Plant That Is Running
SANS ICS Security

Field Rules and the Ground You Are Assessing: Architecture and Segmentation
SANS ICS Security

Reading the Traffic Before You Send Any
SANS ICS Security

Enumeration, Carefully
SANS ICS Security

What the Attacker Does Next
SANS ICS Security

Naming What You Found: ATT&CK for ICS
SANS ICS Security
Lesson frames belong to the creators named in the Credits below and are shown from YouTube.
What you will learn
Write rules of engagement for assessing a system that cannot be stopped; draw and test the zone boundaries that are supposed to exist; capture and read ICS traffic before sending any; enumerate a Modbus endpoint knowing the cost of every request; explain a man-in-the-middle and a forever-day vulnerability and choose compensating controls for a device that will never be patched; assess the engineering workstation and the service accounts on it; leave behind logging and an integrity baseline; decide whether deception is worth its operational cost; review PLC code against the Top 20 Secure PLC Coding Practices; and write a two-page report ordered by consequence that says what you did not test and why.
- Write rules of engagement with a window, a named owner and an abort condition, for a plant that cannot stop
- Draw the zones yourself and test each conduit from the side it is meant to protect
- Capture and read ICS traffic in Wireshark, tshark and Zeek before sending a single packet
- Enumerate a Modbus device knowing what every request will do, and say when it is not worth the risk
- Explain a Modbus man-in-the-middle and choose compensating controls for a device nobody will ever patch
- Map findings to ATT&CK for ICS honestly, and read a real incident as a chain of techniques
- Assess an engineering workstation: local accounts, services, shares and who can reach it
- Leave behind Windows logging and an integrity baseline on a host that must never be rebooted
- Review PLC code against the Top 20 Secure PLC Coding Practices and raise a finding engineering will accept
- Write the two-page report: scope, method, findings by consequence, and what you deliberately did not test
For you
Taking OT Security Assessment: Testing a Plant Without Stopping It from the United States
- Free in the United States, as everywhere, and self-paced: lessons, notes and the final assessment are open at any hour, so your time zone and shift pattern do not matter.
- The optional certificate for learners in the United States is a one-off US$28.99. What you get for it
- Plants across the Americas most often run Allen-Bradley, Siemens and Inductive Automation; each has its own free course to take next.
- See automation and engineering jobs in the United States, and what the industry looks like in Houston, Detroit and Chicago.
- EDWartens also has a regional site for the United States, for classroom training and local support: edwartens.com/us.
The course project 路 about 16 hours
Passive OT security assessment of a running cement plant: DCS, packing PLCs and weighbridges, without a single active scan
Assess the security of a cement plant that cannot be stopped: write the rules of engagement, build the asset inventory from documents, interviews and a mirror-port capture, read the DCS and packing-plant traffic in Wireshark, run CHAPS on the Windows machines with the owner present, review the packing PLC program against the Top 20 Secure PLC Coding Practices, name every finding in ATT&CK for ICS, and write the report ordered by consequence with a 30/90/365-day roadmap. You deliver your own plan, inventory, evidence register, risk register and report. The sample pack shows what an assessor hands to a plant head who has never read one.
Sample document pack, 7 documents, filled in for the scenario
- PlanAssessment Plan and Rules of Engagement: Beni Suef Plant OT Security Assessment
- Asset inventoryOT Asset Inventory: Beni Suef Plant, as Found
- RegisterInterview and Evidence Register
- Risk registerRisk Register: Cyber Risks on the Plant's HSE Matrix
- ReportOT Security Assessment Report: Findings by Consequence, Beni Suef Plant
- PlanRemediation Roadmap: 30, 90 and 365 Days
- Training recordTraining Record: Running the Roadmap and Repeating the Assessment
Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.
Course content
12 modules 路 22 lessons 路 8h 50m
In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.
- 01Rules of Engagement: Assessing a Plant That Is Running1 lesson14m
- 02Field Rules and the Ground You Are Assessing: Architecture and Segmentation3 lessons1h 29m
- 03Reading the Traffic Before You Send Any2 lessons39m
- 04Enumeration, Carefully2 lessons49m
- 05What the Attacker Does Next2 lessons53m
- 06Naming What You Found: ATT&CK for ICS2 lessons24m
- 07The Windows Machines Nobody Mentions2 lessons53m
- 08Seeing It Happen: Windows Logging and Integrity Baselines2 lessons1h 3m
Requirements
- Who it is for
- Intermediate. You should already know what a PLC, an HMI and a SCADA system are, and how they sit on a network. ICS Security Foundations covers that in five hours if you do not. No penetration testing background is assumed.
- Software
- Wireshark, a Linux virtual machine, a Modbus simulator or a lab PLC, and CHAPS. All free downloads. Nothing in this course requires a licence or a paid lab. What to download, and how
- Hardware
- None required. A spare PLC or a Raspberry Pi running a Modbus simulator makes the enumeration and capture work more real, and every exercise is written to work without one.
Software you need
What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.
For a Modbus target, pymodbus runs a simulated Modbus server on the Linux virtual machine, or use a spare lab PLC. Nothing in this course needs a licence or a paid lab.
Required
- 01Free
Wireshark
Wireshark Foundation
- Runs on
- Windows 11 or 10 64-bit (x64 or Arm64), Windows Server 2016 or later, macOS (Universal disk image), Linux
- Account
- None needed
Free, open source software. No licence fee for any use.
Steps
- 1.Open wireshark.org/download.html.
- 2.Download the Windows x64 Installer (or Arm64, or the macOS Universal Disk Image).
- 3.Run the installer and keep the Npcap option ticked on Windows.
- 4.Open Wireshark, pick your network interface and click the blue fin to start capturing.
- Npcap is needed for live capture on Windows. The Windows installer includes it.
- Only capture traffic on networks you own or have written permission to monitor.
Official download pagewireshark.org - 02Free
Oracle VirtualBox
Oracle
- Runs on
- Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
- Account
- None needed
The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.
Steps
- 1.Open virtualbox.org/wiki/Downloads.
- 2.Click the package for your host system (for example, Windows hosts).
- 3.Run the installer and accept the network driver prompts.
- 4.Open VirtualBox, click New, choose your ISO file (for example Ubuntu or Windows) and follow the wizard.
- Turn on hardware virtualisation (Intel VT-x or AMD-V) in your PC's BIOS or UEFI if VirtualBox says it is not available.
- You do not need the Extension Pack for normal lab work. Install it only if you need its extra features and your use is personal or educational.
Official download pagevirtualbox.org - 03Free
Ubuntu Desktop
Canonical
- Runs on
- 64-bit PC (Intel or AMD) or ARM 64-bit. Recommended: 2 GHz dual-core processor, 6 GB RAM, 25 GB free disk space.
- Account
- None needed
- Size
- About 5.9 GB ISO (Intel or AMD 64-bit, current LTS)
Free to download and use. LTS releases get five years of free security updates, which Ubuntu Pro can extend.
Steps
- 1.Open ubuntu.com/download/desktop and download the LTS ISO. For ROS 2 courses, get 24.04 LTS or 22.04 LTS from releases.ubuntu.com instead.
- 2.To try it safely, create a new virtual machine in VirtualBox and attach the ISO.
- 3.To install on a real PC, write the ISO to a USB stick (8 GB or more) and boot from it.
- 4.Follow the installer, then run Software Updater when it finishes.
- Your course may name a specific release. ROS 2 Humble needs Ubuntu 22.04 and ROS 2 Jazzy needs Ubuntu 24.04.
- Give a virtual machine at least 25 GB of disk space.
Official download pageubuntu.comAlternatives
- Ubuntu 24.04 LTS: Use for ROS 2 Jazzy.
- Ubuntu 22.04 LTS: Use for ROS 2 Humble.
- Windows Subsystem for Linux: Run Ubuntu inside Windows 10 or 11 without a virtual machine.
- 04Free
CHAPS (Configuration Hardening Assessment PowerShell Script)
Cutaway Security
- Runs on
- Windows. chaps_PSv3.ps1 for Windows 8 / Server 2012 and later; chaps_PSv2.ps1 for Windows 7 / Server 2008 R2; chaps.bat when PowerShell is not available.
- Account
- None needed
Free under the GNU GPL v3; a commercial licence is offered for use inside proprietary products. Reports you generate are not derivative works.
Steps
- 1.Open the CHAPS GitHub page, click Code, then Download ZIP, and extract it.
- 2.Open PowerShell as administrator in the extracted folder.
- 3.Run: Set-ExecutionPolicy Bypass -Scope Process
- 4.Run: .\chaps_PSv3.ps1 > $env:COMPUTERNAME-chaps.md
- 5.Open the .md report in a text editor or VS Code and review the findings.
- Only run CHAPS on systems you own or are authorised to assess.
- It is read-only and makes no changes, which is why it suits industrial control system PCs.
- Practise first on a Windows evaluation virtual machine.
Official download pagegithub.com
Optional
Useful, not needed to finish the course.
- 05Free
PyModbus
pymodbus-dev (open source project), a Python or npm package
- Runs on
- Windows, macOS and Linux with Python 3.10 or later
- Account
- None needed
Free, open source under the BSD 3-Clause licence.
Steps
- 1.Install Python 3.10 or later and create a virtual environment.
- 2.Run: pip install "pymodbus==3.8.6" (the version the course code is written and tested for; 3.10 renamed slave= to device_id=)
- 3.For serial (RS-485) devices, run: pip install "pymodbus[serial]==3.8.6"
- 4.Follow the client examples in the documentation to read holding registers from a device or the built-in simulator.
- PyModbus includes a server simulator with a web interface, so you can practise without real hardware.
- Only write registers on lab equipment. Writes can move real machines.
Official download pagegithub.com
Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.
OT Security Assessment: Testing a Plant Without Stopping It at a glance
OT Security Assessment: Testing a Plant Without Stopping It is a free, self-paced online course from EDWartens for automation, OT and IT engineers responsible for security. It has 12 modules and 8h 50m of video lessons by SANS ICS Security, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.
All course factsHide course facts
- Price
- Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
- Who it is for
- Automation, OT and IT engineers responsible for security
- Format
- 12 self-paced modules, 8h 50m of video, written notes, a practice task per module and one final assessment.
- Level
- Intermediate. Intermediate. You should already know what a PLC, an HMI and a SCADA system are, and how they sit on a network. ICS Security Foundations covers that in five hours if you do not. No penetration testing background is assumed.
- Brand
- Vendor-neutral
- Software
- Wireshark, a Linux virtual machine, a Modbus simulator or a lab PLC, and CHAPS. All free downloads. Nothing in this course requires a licence or a paid lab.
- Hardware
- None required. A spare PLC or a Raspberry Pi running a Modbus simulator makes the enumeration and capture work more real, and every exercise is written to work without one.
- Certificate
- Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
- Video lessons by
- SANS ICS Security (independent creators, credited below)
- Language
- English
- Last updated
- 27 September 2026
A shareable EDWartens certificate
Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.
The course itself stays free whether or not you ever buy one.
Stuck? Ask a practising engineer
A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.
Pairs well with
Cybersecurity 路 FreeCompTIA Security+ (SY0-701) Exam PrepPrepare for CompTIA Security+ SY0-701 with Professor Messer's complete free video course: every exam objective across the five domains, with EDWartens notes, worked calculations, practice questions and an optional security project. Exam preparation only: the EDWartens certificate is not the CompTIA Security+ certification, which is earned only by passing CompTIA's exam.
PLC programming 路 FreeSiemens TIA PortalFrom zero electrical knowledge to a working, simulated S7-1200 program, for nothing.
PLC programming 路 FreeSiemens TIA Portal in Three HoursThe first three hours of the Siemens TIA Portal course, cut to end on a win: what a PLC is, how it is wired, a project configured in TIA Portal, and your first ladder program running in simulation. Finish it in an evening or two, earn a certificate, and carry straight on into the full course.
PLC programming 路 FreeTIA Portal: Build a MachineOne machine, start to finish. Take a bottle filling line from a written specification and an I/O list to a structured S7-1200 program with a fill station, a capper, a reject sorter and an operator screen with alarms, then test it against a written record and archive it for hand-over. The lessons are the reference; the machine is yours, and it is what you submit.More free courses: Free cyber security courses 路 Free OT and ICS security courses
Learner reviews
No reviews yet
Reviews here are written only by learners who have finished every module of OT Security Assessment: Testing a Plant Without Stopping It, and they are published exactly as written. Finish the course and yours will be the first.
Common questions
Is this a hacking course?
No. It is an assessment course, and the difference matters on a plant. It teaches you to evaluate systems you are authorised to evaluate, for the people who own them, and the first module is entirely about the permission, the window and the condition under which you stop. There is no exploit development here and nothing is aimed at systems you do not own. Where the course covers what an attacker does, such as a Modbus man-in-the-middle, it does so because you cannot defend or assess a protocol whose weaknesses you have not seen.
How is it different from the OT and ICS Cybersecurity course?
That course is the standards and programme side: ISA/IEC 62443 clause by clause, security levels, risk assessment, governance. It is forty-four hours. This one is the practical assessment: what you actually do in the four days you are on site, in the order that keeps the plant running. They complement each other and neither repeats the other. If you have done neither, ICS Security Foundations is the five-hour place to start.
Do I need a lab, or a real PLC?
No. Every exercise is written to work with a free Modbus simulator on a laptop and a Linux virtual machine. A spare PLC or a Raspberry Pi running a simulator makes the capture and enumeration work feel real, and several people find that worth the effort, but nothing in the course assumes you have one.
Do I need penetration testing experience?
No, and the course is deliberately not written for penetration testers moving into OT. It is written for automation engineers who already understand plants and are being asked to assess them, which is the more common situation on real plants and the one that is worse served.
Is this a SANS course, or does it lead to a GIAC certification?
No. Every video lesson is from the SANS ICS Security channel's free ICS Concepts series, credited on each module, and SANS is not affiliated with EDWartens. SANS run their own paid courses and GIAC issue their own certifications; this course is neither and does not count towards either. What EDWartens wrote is the study plan, the objectives, the practice tasks, the notes and the assessments.
What will I have at the end?
A two-page assessment report on a system you chose, with scope, method, findings ordered by consequence, and a section naming what you deliberately did not test. That report is the deliverable of the course and is the thing worth showing an employer, more than the certificate is.
Is the OT Security Assessment course really free?
Yes. Every module, every practice task and the final assessment. You create an account so your progress is saved and the assessment can be marked. The only paid item is the certificate, and only if you decide you want it.
What certificate does the OT Security Assessment course give?
An EDWartens Certificate of Completion, issued when you have worked through every module and passed the final assessment, with a unique number anyone can verify on our site. It is not a vendor or industry credential and we will never describe it as one.
What you walk away with
Your certificate for OT Security Assessment: Testing a Plant Without Stopping It
Finish the course, pass the final, and this is the document with your name on it.

Verifiable by anyone
Adds to LinkedIn in one click
QR code on the certificate
Names what you can do
A permanent link
Earned, not attended
Learning is free. The certificate is optional.
Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.
Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.
Credits
Who made the video lessons
The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
- SANS ICS Securitythe entire ICS Concepts series that this course is built from: attacker methodology, field practice, network architecture, Modbus traffic analysis, enumeration and man-in-the-middle, Zeek, ATT&CK Navigator, Windows hardening and logging, integrity baselining, honeypots, the Top 20 Secure PLC Coding Practices, CHAPS and cyber informed engineering
If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.
