XUTS LABS TRACK
OT / ICS Offensive Security
Learn operational technology attack paths, industrial protocols, engineering workstation abuse, ICS environments, and OT-focused offensive security methodology.
Focus
Learn how OT environments differ from enterprise IT before touching protocols, controllers, historians, or engineering systems.
Method
Prioritize passive understanding, careful validation, process awareness, and safe attack-path reasoning.
Operator Warning
OT testing can affect physical processes. This track teaches cautious methodology before action.
OT Progression Path
OT Operator Development Flow
Progress from foundational OT understanding into operational visibility, industrial protocol awareness, and OT attack-path methodology.
ICS Fundamentals
OT Network Fundamentals
OT networks support physical processes through systems such as HMIs, engineering workstations, historians, PLCs, RTUs, safety systems, and control servers. Unlike enterprise IT, availability and process stability usually matter more than confidentiality.
Before an operator touches an OT environment, they need to understand what each system does, what level of the Purdue model it usually lives in, and how a mistake could impact operations.
Open Node →
OT Segmentation Enumeration
OT segmentation enumeration is the process of identifying boundaries, conduits, jump paths, firewall rules, routing paths, and trust relationships between enterprise IT and industrial control networks.
Most OT attack paths are not magic protocol exploits. They usually depend on bad segmentation, over-trusted jump hosts, reused credentials, exposed historians, or systems that bridge zones.
Open Node →
Engineering Workstation Enumeration
Engineering workstations are operator and engineer systems used to configure, program, troubleshoot, and sometimes directly communicate with controllers and industrial equipment.
An engineering workstation can be more valuable than a domain admin shell in an OT environment because it may contain project files, controller logic, vendor tools, saved connections, documentation, and operational trust.
Open Node →
Industrial Protocols
Modbus Fundamentals
Modbus is a common industrial protocol used for communication between clients and devices such as PLCs, RTUs, gateways, and simulators. Modbus/TCP commonly uses port 502.
Modbus is simple, common, and often lacks authentication. Operators must understand the difference between passive observation, safe reads, and dangerous writes.
Open Node →
PLC Enumeration
PLC enumeration is the process of identifying programmable logic controllers, their vendors, reachable services, communication paths, and operational role without changing controller state.
PLCs directly interact with physical processes. Enumeration must be cautious, scoped, and focused on identification rather than manipulation.
Open Node →
Historian Enumeration
Industrial historians collect and store process data from OT systems. They often provide long-term visibility into production, equipment behavior, alarms, trends, and operational states.
Historians can reveal process intelligence, asset names, tag structures, controller relationships, and sensitive operational context without requiring direct PLC interaction.
Open Node →
OT Enumeration
Engineering Workstation Enumeration
Engineering workstations are operator and engineer systems used to configure, program, troubleshoot, and sometimes directly communicate with controllers and industrial equipment.
An engineering workstation can be more valuable than a domain admin shell in an OT environment because it may contain project files, controller logic, vendor tools, saved connections, documentation, and operational trust.
Open Node →
Historian Enumeration
Industrial historians collect and store process data from OT systems. They often provide long-term visibility into production, equipment behavior, alarms, trends, and operational states.
Historians can reveal process intelligence, asset names, tag structures, controller relationships, and sensitive operational context without requiring direct PLC interaction.
Open Node →
PLC Enumeration
PLC enumeration is the process of identifying programmable logic controllers, their vendors, reachable services, communication paths, and operational role without changing controller state.
PLCs directly interact with physical processes. Enumeration must be cautious, scoped, and focused on identification rather than manipulation.
Open Node →
OT Lateral Movement
OT Segmentation Enumeration
OT segmentation enumeration is the process of identifying boundaries, conduits, jump paths, firewall rules, routing paths, and trust relationships between enterprise IT and industrial control networks.
Most OT attack paths are not magic protocol exploits. They usually depend on bad segmentation, over-trusted jump hosts, reused credentials, exposed historians, or systems that bridge zones.
Open Node →
OT Lateral Movement
OT lateral movement is the controlled movement from enterprise or OT-adjacent access toward systems that provide operational visibility or control, such as jump hosts, historians, HMIs, engineering workstations, or controller networks.
OT lateral movement is less about throwing tools and more about understanding trust paths, process impact, and where access creates operational risk.
Open Node →
Engineering Workstation Enumeration
Engineering workstations are operator and engineer systems used to configure, program, troubleshoot, and sometimes directly communicate with controllers and industrial equipment.
An engineering workstation can be more valuable than a domain admin shell in an OT environment because it may contain project files, controller logic, vendor tools, saved connections, documentation, and operational trust.
Open Node →
ICS Impact Concepts
Safety System Awareness
Safety system awareness means understanding the difference between operational control systems and systems designed to protect life, equipment, and the environment, such as Safety Instrumented Systems.
In OT, some systems are directly tied to physical safety. A responsible operator must know where testing stops and where safety-critical risk begins.
Open Node →
OT Lateral Movement
OT lateral movement is the controlled movement from enterprise or OT-adjacent access toward systems that provide operational visibility or control, such as jump hosts, historians, HMIs, engineering workstations, or controller networks.
OT lateral movement is less about throwing tools and more about understanding trust paths, process impact, and where access creates operational risk.
Open Node →