XUTS LABS / ACADEMY / OT

OT Operator Study Hub

OT / ICS Offensive Security

Your central launch point for OT training, field references, threat intel, protocol study, pen test methodology, and operator-focused attack-path learning.

Connected Sections

Everything OT connects here

Back to Academy →

Two-Week Study Flow

Use this as your main study route

Day 1

OT Foundations

  • Purdue Model
  • OT vs IT
  • Asset roles
  • Safety-first methodology

Day 2

Protocols

  • Modbus
  • DNP3
  • EtherNet/IP
  • OPC UA

Day 3

Vendors & Assets

  • Rockwell
  • Siemens
  • Schneider
  • Historians
  • Engineering workstations

Day 4

Pentest Methodology

  • Scoping
  • Passive discovery
  • No-touch rules
  • Controlled validation

Day 5

Threat Intel

  • XENOTIME
  • ELECTRUM
  • CHERNOVITE
  • KAMACITE
  • ICS malware

Day 6–7

Operator Review

  • Explain concepts aloud
  • Walk attack paths
  • Practice panel answers

Operator Reminder

OT confidence comes from methodology, not tool dumping.

Focus on explaining why passive discovery matters, why active testing can be dangerous, how Purdue levels influence attack paths, why engineering workstations and historians matter, and how to validate risk without disrupting operations.