XUTS OT Operator Node
OT Lateral Movement
OT lateral movement is the controlled movement from enterprise or OT-adjacent access toward systems that provide operational visibility or control, such as jump hosts, historians, HMIs, engineering workstations, or controller networks.
OT Safety Gate
Assume every action can affect the process until proven otherwise.
OT testing is not just exploitation. It is controlled validation around availability, safety, process continuity, deterministic operations, and recovery.
What it is
OT lateral movement is the controlled movement from enterprise or OT-adjacent access toward systems that provide operational visibility or control, such as jump hosts, historians, HMIs, engineering workstations, or controller networks.
Why it matters
OT lateral movement is less about throwing tools and more about understanding trust paths, process impact, and where access creates operational risk.
How to identify it
Identify credentials reused between enterprise and OT systems.Map jump hosts, remote access solutions, RDP paths, SMB shares, and vendor access systems.Review firewall paths, local administrator groups, service accounts, and scheduled tasks.Identify which systems can reach operational assets and which identities can use those systems.
Expected output
A safe movement path toward OT visibility.A list of identities and systems that bridge zones.A validation plan that minimizes operational impact.
Success looks like
You can explain why a path is valuable before using it.You validate access without destabilizing operational systems.You prioritize visibility and evidence over unnecessary control actions.
Failure looks like
You deploy noisy tooling into OT without understanding impact.You move laterally just because credentials work.You cannot explain what process or zone the target system belongs to.
Troubleshooting
Lab setup ideas
EXO automation ideas
Operational Tradecraft
How to talk about this like an OT operator
Lead with process risk.
Explain how this topic affects visibility, control, safety, availability, recovery, and engineering workflows.
Explain passive-first methodology.
Mention SPAN/TAP collection, firewall review, switch tables, historian visibility, HMI observation, configuration review, and controlled validation before active probing.
Tie the concept to an attack path.
Connect the node to IT/OT pivoting, Level 3 operations, historians, engineering workstations, HMIs, PLCs, protocols, vendor access, and segmentation boundaries.
EXO Guidance
Recommended next lessons
ASREP Roast
ASREP roasting abuses AD users with Kerberos pre-authentication disabled. You can request encrypted ASREP material and attempt to crack it offline.
Kerberoast
Kerberoasting targets domain users with SPNs. You request service tickets and crack them offline.
GenericWrite
GenericWrite means you can modify certain attributes on the target AD object.
GenericAll
GenericAll is effectively full control over the target AD object.