XUTS OT Operator Node
OT Network Fundamentals
OT networks support physical processes through systems such as HMIs, engineering workstations, historians, PLCs, RTUs, safety systems, and control servers. Unlike enterprise IT, availability and process stability usually matter more than confidentiality.
OT Safety Gate
Assume every action can affect the process until proven otherwise.
OT testing is not just exploitation. It is controlled validation around availability, safety, process continuity, deterministic operations, and recovery.
What it is
OT networks support physical processes through systems such as HMIs, engineering workstations, historians, PLCs, RTUs, safety systems, and control servers. Unlike enterprise IT, availability and process stability usually matter more than confidentiality.
Why it matters
Before an operator touches an OT environment, they need to understand what each system does, what level of the Purdue model it usually lives in, and how a mistake could impact operations.
How to identify it
Map systems into rough Purdue levels: enterprise, DMZ, operations, control, and field device zones.Identify HMIs, historians, engineering workstations, domain controllers, jump hosts, and controller networks.Look for vendor software such as Rockwell, Siemens, Schneider, GE, Honeywell, ABB, or Ignition tooling.Identify systems that bridge IT and OT networks, especially jump boxes, historians, remote access servers, and dual-homed hosts.
Expected output
A rough OT asset map showing operator workstations, servers, control assets, and boundary systems.A list of high-value systems that should be handled carefully.A basic understanding of which systems can affect physical process visibility or control.
Success looks like
You can explain what each major OT system is likely responsible for.You can separate enterprise assets from operational control assets.You can identify where normal IT attack behavior becomes unsafe.
Failure looks like
You treat PLCs, HMIs, and historians like normal servers.You rely on aggressive scanning without understanding operational risk.You cannot explain what a discovered OT host actually does.
Troubleshooting
Lab setup ideas
EXO automation ideas
Operational Tradecraft
How to talk about this like an OT operator
Lead with process risk.
Explain how this topic affects visibility, control, safety, availability, recovery, and engineering workflows.
Explain passive-first methodology.
Mention SPAN/TAP collection, firewall review, switch tables, historian visibility, HMI observation, configuration review, and controlled validation before active probing.
Tie the concept to an attack path.
Connect the node to IT/OT pivoting, Level 3 operations, historians, engineering workstations, HMIs, PLCs, protocols, vendor access, and segmentation boundaries.
EXO Guidance
Recommended next lessons
ASREP Roast
ASREP roasting abuses AD users with Kerberos pre-authentication disabled. You can request encrypted ASREP material and attempt to crack it offline.
Kerberoast
Kerberoasting targets domain users with SPNs. You request service tickets and crack them offline.
GenericWrite
GenericWrite means you can modify certain attributes on the target AD object.
GenericAll
GenericAll is effectively full control over the target AD object.