← Back to OT / ICS Track

XUTS LABS / OT PEN TEST FIELD MANUAL

OT Penetration Testing Methodology

A safety-first workflow for scoping, passive discovery, controlled validation, attack-path analysis, and operationally useful reporting.

No-Touch Rules

Actions to avoid unless explicitly scoped

No fuzzing live PLCs, RTUs, safety systems, drives, or controllers.
No protocol writes, force coils, register changes, logic downloads, or firmware actions unless explicitly scoped.
No denial-of-service testing in production.
No unsafe scanning of Level 1/0 networks without written approval.
No changes to HMI screens, recipes, alarms, setpoints, or schedules.
No SIS testing without a dedicated SIS scope and safety engineers present.

Methodology

Assessment Phases

1. Scoping & Safety Alignment

Define what can be tested, what must not be touched, who owns the process, and what operational controls are required.

Activities

  • Identify sites, zones, assets, production schedules, safety constraints, and vendor dependencies.
  • Define allowed testing windows and emergency stop procedures.
  • Clarify whether Level 1/0, SIS, PLCs, and engineering workstations are in scope.
  • Document forbidden actions such as protocol writes, fuzzing, logic downloads, or active exploitation.

Safety Controls

  • Named operational point of contact.
  • Rollback plan.
  • Maintenance window approval.
  • Explicit no-touch list.

Deliverables

  • Rules of engagement.
  • OT safety constraints.
  • Asset criticality assumptions.
  • Escalation contacts.

2. Passive Discovery

Build an asset and communication map without introducing risk.

Activities

  • Review network diagrams, firewall rules, switch configs, span/tap traffic, DNS, DHCP, ARP, and routing tables.
  • Identify HMIs, historians, engineering workstations, PLCs, RTUs, jump hosts, and OT domain services.
  • Map protocol conversations and Purdue-level relationships.
  • Identify trust paths from IT into OT.

Safety Controls

  • No active scans against sensitive ranges.
  • Read-only collection.
  • Coordination with network owners.
  • Packet capture storage controls.

Deliverables

  • Passive asset inventory.
  • Protocol map.
  • IT/OT pathway map.
  • Initial risk observations.

3. Controlled Active Validation

Validate exposure and security assumptions with minimal operational risk.

Activities

  • Perform carefully scoped service validation on approved Level 3 assets.
  • Validate remote access, jump host, AD, historian, and HMI server exposure.
  • Use rate-limited scanning only where approved.
  • Avoid controller writes, fuzzing, or unsafe industrial protocol actions.

Safety Controls

  • Approved target list.
  • Rate limits.
  • Immediate stop criteria.
  • Operations monitoring during tests.

Deliverables

  • Validated exposures.
  • Credential and access findings.
  • Segmentation gaps.
  • Service inventory.

4. Attack Path Analysis

Show realistic paths without creating unnecessary process risk.

Activities

  • Analyze IT-to-OT paths through VPN, remote access, AD trusts, jump hosts, historians, and file shares.
  • Evaluate engineering workstation exposure and credential reuse.
  • Map potential movement from Level 4/3 to Level 2/1.
  • Use simulation or tabletop validation for high-risk end steps.

Safety Controls

  • Do not execute high-impact payloads.
  • Use proof-based validation where possible.
  • Avoid process-control changes.
  • Confirm business impact with asset owners.

Deliverables

  • Attack chain diagrams.
  • Risk-ranked pathways.
  • Evidence screenshots.
  • Control recommendations.

5. Reporting & Operational Remediation

Convert findings into safe, actionable engineering and security improvements.

Activities

  • Separate enterprise risks from OT process risks.
  • Prioritize segmentation, remote access, identity, monitoring, backups, and engineering workstation hardening.
  • Explain what could happen operationally, not just technically.
  • Provide practical remediation paths that respect plant realities.

Safety Controls

  • Avoid unrealistic blanket recommendations.
  • Validate feasibility with operations.
  • Prioritize compensating controls.
  • Include phased remediation.

Deliverables

  • Executive summary.
  • Technical findings.
  • Attack path diagrams.
  • Prioritized remediation roadmap.

Scoping Questions

Questions to ask before testing

What production process does this network support?
Which assets are safety-critical or production-critical?
Who can stop testing immediately if operations are affected?
Are there approved maintenance windows?
Are PLCs, RTUs, SIS, drives, and engineering workstations in scope?
Is passive collection available through SPAN/TAP or existing sensors?
What remote access paths exist for vendors and engineers?
What is the expected communication baseline?
What backups exist for PLC logic, HMI projects, historian configs, and engineering workstations?
What testing actions are explicitly prohibited?