Khóa Học OT Security & ICS/SCADA Security : Hand-On Lab (1 -1 trong 1 năm)
OT Security: ICS/SCADA Hands-on
Industrial Cybersecurity, PLC, Industrial Protocols & Cyber Range
Advanced Professional Training Program
1. Chương trình này dành cho ai?
Đây là chương trình không dành cho số đông. OT Security: ICS/SCADA Hands-on là chương trình đào tạo chuyên sâu dành cho những người muốn bước vào hoặc nâng cao năng lực trong lĩnh vực Operational Technology Cybersecurity. Phù hợp với các bạn Việt Kiều hay nhân viên công ty.
Khóa học 1 kèm 1 trong 12 tháng, thực hành trên lab mô phỏng các hệ thống OT thông dung như điện, nước, ý tế, hóa chất ...
Chương trình được thiết kế cho:
-
Cybersecurity Professionals
-
Security Engineers
-
SOC Analysts
-
Blue Team / Detection Engineers
-
Penetration Testers
-
Red Team Professionals
-
Network Security Engineers
-
System Administrators
-
Security Consultants
-
OT Security Professionals
-
ICS/SCADA Engineers
-
Automation Engineers
-
PLC Engineers
-
SCADA Engineers
-
Industrial Network Engineers
-
Critical Infrastructure Security Teams
-
IT/OT Security Teams
-
Cybersecurity Managers và Architects
Đặc biệt phù hợp với những người muốn chuyển từ:
IT Security → OT Security
hoặc:
Automation / ICS / SCADA → OT Cybersecurity
2. Tư duy thiết kế chương trình
Đây không phải là khóa học mà học viên:
Xem slide → ghi chép → làm vài câu quiz → kết thúc khóa học.
Đây là một hands-on OT cybersecurity journey.
Học viên sẽ liên tục di chuyển giữa:
THEORY
Hiểu kiến trúc, công nghệ, threat và security principles.
↓
INDUSTRIAL ENVIRONMENT
Quan sát và tương tác với SCADA, PLC, HMI và industrial network.
↓
OFFENSIVE SECURITY
Phân tích attack surface và thực hiện controlled security testing.
↓
DEFENSIVE SECURITY
Quan sát traffic, logs, events và detection.
↓
INCIDENT RESPONSE
Điều tra sự kiện và đánh giá operational impact.
↓
SECURITY ARCHITECTURE
Thiết kế controls và defense-in-depth.
↓
VALIDATION
Kiểm tra xem security controls có thực sự hoạt động hay không.
3. The OT Cyber Range
Học trong môi trường công nghiệp, không chỉ trên slide
Toàn bộ chương trình xoay quanh một controlled OT Cyber Range.
Labshock được sử dụng làm môi trường thực hành chính, với các thành phần như:
-
SCADA
-
PLC
-
HMI
-
Engineering Workstation
-
Industrial Network
-
Industrial Protocols
-
OT Monitoring
-
IDS
-
SIEM
-
IT/OT Segmentation
-
DMZ
-
Attack Environment
-
Log Collection
-
Security Monitoring
Labshock hiện được thiết kế theo hướng một môi trường OT thống nhất cho learning, penetration testing, IDS/SIEM validation và lab building, với SCADA, PLC, industrial protocols và real OT traffic.
Học viên không chỉ “mở lab”.
Học viên sẽ sử dụng cùng một môi trường để:
Operate → Observe → Attack → Detect → Investigate → Defend
4. Learning Architecture
Chương trình gồm 12 Learning Tracks và một Capstone Mission.
TRACK 01
OT & Industrial Cybersecurity Foundations
Understanding the World of Operational Technology
1.1 What is Operational Technology?
-
IT vs OT
-
Information Technology
-
Operational Technology
-
Industrial Cybersecurity
-
Cyber-Physical Systems
-
Critical Infrastructure
-
Industrial Automation
-
Safety-Critical Systems
1.2 OT Security vs IT Security
So sánh:
-
Confidentiality
-
Integrity
-
Availability
-
Safety
-
Reliability
-
Resilience
-
Determinism
-
Availability requirements
-
Change management
Học viên hiểu tại sao:
“Patch everything immediately”
không phải lúc nào cũng là câu trả lời đúng trong OT.
1.3 OT Security Objectives
-
Protect the process
-
Protect the controller
-
Protect the operator
-
Protect the network
-
Protect availability
-
Protect safety
-
Maintain operational continuity
1.4 OT Threat Landscape
-
Nation-state threats
-
Cybercriminals
-
Ransomware
-
Insider threats
-
Supply-chain threats
-
Remote-access abuse
-
Malware
-
Manipulation of control logic
-
Unauthorized process changes
1.5 OT Attack Consequences
Không chỉ:
Data Loss
mà còn:
Process Manipulation
Production Disruption
Equipment Damage
Safety Impact
Environmental Impact
LAB
Lab 01 — Enter the Industrial Environment
Học viên:
-
Access OT environment
-
Identify assets
-
Observe SCADA
-
Identify PLC
-
Identify HMI
-
Observe process state
-
Identify communication relationships
TRACK 02
ICS, SCADA & Industrial Control Systems
Understanding the Industrial Control Architecture
2.1 ICS Fundamentals
-
ICS architecture
-
Control loops
-
Field devices
-
Controllers
-
Supervisory systems
-
Operator systems
-
Engineering systems
2.2 SCADA
-
SCADA architecture
-
SCADA server
-
HMI
-
Historian
-
RTU
-
PLC
-
Remote sites
-
Control center
2.3 PLC
-
PLC architecture
-
CPU
-
Inputs
-
Outputs
-
Memory
-
Control logic
-
Scan cycle
-
Industrial programming
2.4 DCS
-
Distributed Control Systems
-
DCS vs PLC
-
DCS vs SCADA
-
Process industries
2.5 Engineering Workstation
-
Programming environment
-
PLC configuration
-
Logic deployment
-
Maintenance workflow
-
Security risks
LAB
Lab 02 — Operate a SCADA System
Học viên:
-
Observe process variables
-
Identify control elements
-
Follow PLC state changes
-
Observe HMI interactions
-
Trace SCADA-to-PLC communication
TRACK 03
Industrial Networks & Protocols
Understanding OT Traffic from the Wire Up
3.1 Industrial Networking
-
Ethernet
-
TCP/IP
-
UDP
-
Routing
-
Switching
-
VLAN
-
Industrial Ethernet
3.2 Industrial Protocol Architecture
-
Request/response
-
Master/slave
-
Client/server
-
Publish/subscribe
-
Real-time communication
3.3 Modbus
-
Modbus architecture
-
Modbus TCP
-
Registers
-
Coils
-
Function codes
-
Read/write operations
-
Normal traffic
-
Suspicious traffic
3.4 IEC 60870-5-104
-
IEC 104 architecture
-
Communication model
-
Information objects
-
Control commands
-
Monitoring traffic
-
Security considerations
3.5 Other Industrial Protocols
Tùy topology/lab:
-
S7
-
EtherNet/IP
-
DNP3
-
OPC UA
-
MQTT
-
BACnet
-
Industrial Web APIs
Labshock hiện hỗ trợ nhiều industrial protocol environments, bao gồm Modbus TCP, S7comm, EtherNet/IP và DNP3 trong hệ sinh thái PLC; các integrations cũng mở rộng sang OPC UA, MQTT và các giao thức/industrial systems khác.
LAB
Lab 03 — Industrial Protocol Deep Dive
Học viên:
-
Capture traffic
-
Identify protocol
-
Decode packets
-
Identify commands
-
Identify registers
-
Observe state transitions
-
Compare normal vs abnormal traffic
TRACK 04
OT Asset Discovery & Attack Surface
You Cannot Protect What You Cannot See
4.1 OT Asset Inventory
-
PLC
-
HMI
-
SCADA
-
RTU
-
EWS
-
Historian
-
Network devices
-
Security devices
4.2 Passive Discovery
-
Traffic analysis
-
Protocol identification
-
Asset identification
-
Baseline traffic
4.3 Active Discovery
-
Service discovery
-
Port identification
-
Protocol enumeration
-
Controlled scanning
4.4 OT Attack Surface
-
Exposed services
-
Legacy systems
-
Remote access
-
Engineering workstations
-
Flat networks
-
Weak authentication
-
Industrial protocols
-
Vendor access
LAB
Lab 04 — Map the OT Environment
Deliverable:
OT Asset Inventory + Network Map + Attack Surface Map
TRACK 05
OT Architecture & Network Defense
Designing Secure Industrial Networks
5.1 Purdue Model
-
Enterprise zone
-
Industrial DMZ
-
Operations
-
Control
-
Cell/Area
-
Field
5.2 Zones and Conduits
-
ISA/IEC 62443 concepts
-
Security zones
-
Conduits
-
Trust boundaries
-
Security levels
5.3 IT/OT Segmentation
-
Network segmentation
-
VLAN
-
Firewall
-
Industrial firewall
-
DMZ
-
Jump server
-
Remote access
5.4 Air Gap
-
What is an air gap?
-
What an air gap actually protects
-
Air-gap limitations
-
Bridging the air gap
-
Data diode
-
Secure transfer
5.5 Legacy OT
-
Unsupported operating systems
-
Legacy PLC
-
Legacy protocols
-
Patch limitations
-
Compensating controls
EC-Council cũng đặt trọng tâm vào securing ICS networks, air-gap considerations, data diodes, firewalls, legacy systems và IDS/IPS; các nội dung này sẽ được mở rộng đáng kể trong chương trình này.
LAB
Lab 05 — Build the Secure OT Architecture
Học viên:
-
Start with flat OT
-
Identify weaknesses
-
Create segmentation
-
Configure DMZ
-
Restrict IT/OT communication
-
Validate allowed flows
-
Observe blocked flows
TRACK 06
OT Threats, Attacks & Adversary Thinking
Think Like an Attacker — Without Losing Sight of the Process
6.1 OT Attack Lifecycle
-
Reconnaissance
-
Initial Access
-
Discovery
-
Credential Access
-
Lateral Movement
-
Command/Control
-
Process Manipulation
-
Impact
6.2 Common OT Attack Vectors
-
Remote access
-
Engineering workstation
-
Vulnerable services
-
Weak credentials
-
Misconfigured firewall
-
Flat network
-
Protocol abuse
-
Supply chain
-
Removable media
6.3 Industrial Attack Examples
-
Stuxnet
-
TRISIS / TRITON
-
Industroyer
-
BlackEnergy
-
Ransomware affecting OT
-
Living-off-the-land techniques
6.4 IT-to-OT Attack Path
Học viên phân tích:
Internet → IT → DMZ → Engineering Workstation → OT Network → PLC
LAB
Lab 06 — Find the Attack Path
Mục tiêu:
Không phải “hack càng nhiều càng tốt”.
Mục tiêu là:
Find the path. Understand the path. Break the path.
TRACK 07
OT Penetration Testing
From Reconnaissance to Controlled Exploitation
7.1 OT Pentest Methodology
-
Rules of engagement
-
Safety boundaries
-
Scope
-
Asset criticality
-
Testing windows
-
Change control
7.2 Reconnaissance
-
Passive reconnaissance
-
Active reconnaissance
-
Network mapping
-
Protocol discovery
7.3 Enumeration
-
Services
-
Devices
-
PLC
-
SCADA
-
Industrial protocols
7.4 Vulnerability Identification
-
CVE
-
Vendor advisories
-
ICS advisories
-
Configuration weaknesses
-
Protocol weaknesses
-
Credential weaknesses
7.5 Exploitation
Controlled lab-only scenarios:
-
Protocol manipulation
-
Unauthorized commands
-
Weak authentication
-
Misconfiguration
-
Access control failures
7.6 Process Impact Analysis
Đây là điểm đặc biệt của OT Pentest.
Học viên phải trả lời:
What happened to the process?
Không chỉ:
What happened to the server?
LAB
Lab 07 — OT Penetration Testing Mission
Deliverable:
OT Security Assessment Report
bao gồm:
-
Executive Summary
-
Scope
-
Asset Inventory
-
Attack Surface
-
Findings
-
Attack Paths
-
Evidence
-
Risk
-
Operational Impact
-
Recommendations
TRACK 08
OT Vulnerability & Risk Management
Risk in a World Where You Cannot Patch Everything
8.1 OT Vulnerability Management
-
Asset criticality
-
Vulnerability identification
-
Vendor advisories
-
CVE
-
ICS-CERT/CISA advisories
-
CVSS
8.2 OT-specific Risk
Không chỉ:
CVSS = 9.8
mà phải xét:
-
Process criticality
-
Safety
-
Availability
-
Exposure
-
Exploitability
-
Compensating controls
-
Recovery capability
8.3 Patch Management
-
Patch testing
-
Maintenance windows
-
Vendor validation
-
Rollback
-
Compensating controls
LAB
Lab 08 — OT Vulnerability Assessment
Học viên nhận một asset inventory và xây:
OT Vulnerability Prioritization Matrix
TRACK 09
OT Monitoring, IDS & Threat Detection
Detect the Signal, Not Just the Noise
Đây là một trong những phần premium nhất của chương trình.
Labshock được thiết kế để đưa real industrial activity, PLC state transitions, SCADA events và OT traffic vào detection workflow.
9.1 OT Visibility
-
Network visibility
-
Asset visibility
-
Protocol visibility
-
Process visibility
9.2 OT Baseline
-
Normal traffic
-
Normal commands
-
Normal PLC behavior
-
Normal operator activity
9.3 Anomaly Detection
-
Unexpected device
-
Unexpected protocol
-
Unexpected command
-
Unexpected register change
-
Unexpected PLC state
9.4 IDS
-
Network IDS
-
Protocol-aware IDS
-
Signature detection
-
Behavioral detection
-
OT-specific detection
9.5 Detection Engineering
Học viên xây:
-
Detection rules
-
Indicators
-
Thresholds
-
Correlation
-
Context
LAB
Lab 09 — Detect an OT Attack
Học viên:
-
Establish baseline
-
Generate normal traffic
-
Trigger controlled attack
-
Capture traffic
-
Identify anomaly
-
Create detection
-
Validate alert
TRACK 10
OT SIEM & Security Operations
Bringing OT Into the SOC
10.1 OT Telemetry
-
PLC events
-
SCADA events
-
Network events
-
IDS events
-
Authentication events
-
Operator activity
10.2 Log Collection
-
Collection
-
Normalization
-
Parsing
-
Contextualization
10.3 SIEM Integration
-
OT → Collector
-
Collector → SIEM
-
Detection
-
Correlation
-
Alert
10.4 OT SOC
-
SOC visibility
-
OT alert triage
-
Escalation
-
OT/IT coordination
10.5 Detection Use Cases
Ví dụ:
-
Unauthorized PLC command
-
New industrial device
-
Unexpected Modbus write
-
Abnormal SCADA activity
-
Engineering workstation access
-
Repeated authentication failures
-
OT network scanning
LAB
Lab 10 — Build an OT SOC Detection Use Case
Deliverable:
OT Detection Use Case
gồm:
-
Data source
-
Detection logic
-
Event
-
Correlation
-
Alert
-
Severity
-
Analyst action
Labshock hiện hỗ trợ OT event collection và forwarding vào SIEM, bao gồm các nguồn như OpenPLC, SCADA và IDS; đây là nền tảng rất phù hợp cho phần này.
TRACK 11
OT Incident Response & Digital Forensics
When an Industrial System Is Under Attack
11.1 OT Incident Response
-
Preparation
-
Identification
-
Analysis
-
Containment
-
Eradication
-
Recovery
-
Lessons learned
11.2 OT-specific Challenges
-
Availability
-
Safety
-
Evidence preservation
-
Legacy systems
-
Vendor dependency
-
Production constraints
11.3 Incident Investigation
Học viên điều tra:
-
Network traffic
-
Logs
-
PLC changes
-
SCADA events
-
User activity
-
Timeline
11.4 OT Malware
-
Malware indicators
-
Industrial malware
-
Malware behavior
-
OT-specific impact
11.5 Incident Timeline
Xây dựng:
Initial Access → Lateral Movement → OT Access → Process Manipulation → Detection → Response
LAB
Lab 11 — OT Incident Investigation
Học viên nhận một incident scenario và phải xác định:
What happened?
How did the attacker get in?
What changed?
What was affected?
What evidence supports the conclusion?
What should the organization do next?
TRACK 12
OT Security Engineering & Governance
Turning Technical Knowledge Into an Enterprise Security Program
12.1 OT Security Frameworks
-
NIST Cybersecurity Framework
-
NIST SP 800-82
-
ISA/IEC 62443
-
ISO 27001
-
ISA/IEC 62443 zones & conduits
-
Security levels
12.2 OT Security Governance
-
Policies
-
Roles
-
Responsibilities
-
Asset ownership
-
Risk ownership
-
Change management
12.3 OT Security Architecture
-
Defense in depth
-
Segmentation
-
Authentication
-
Authorization
-
Monitoring
-
Detection
-
Incident response
12.4 Third-party Access
-
Vendor access
-
Remote maintenance
-
Jump server
-
MFA
-
Session monitoring
-
Least privilege
12.5 OT Security Program
Học viên xây:
OT Security Improvement Roadmap
ADVANCED TRACK
Industrial IoT & IIoT Security
Where OT Meets IoT
Đây là phần lấy cảm hứng từ ISE nhưng được chuyển hóa theo hướng Industrial IoT, thay vì biến khóa thành một khóa IoT Security chung chung.
EC-Council ISE bao phủ IoT fundamentals, networking, processors/OS, cloud, IoT threats, threat intelligence, incident response và security engineering.
Chương trình OT này tập trung vào phần giao thoa:
IIoT Architecture
-
Sensors
-
Edge devices
-
Gateways
-
Industrial networks
-
Cloud
-
Analytics
IIoT Communication
-
MQTT
-
OPC UA
-
APIs
-
Web services
IIoT Threats
-
Device compromise
-
Credential attacks
-
Insecure APIs
-
Cloud compromise
-
Supply-chain risks
IIoT → OT Attack Path
IoT/Edge → Industrial Network → Control System
LAB
Lab 12 — Secure the IIoT Gateway
Học viên phân tích:
-
Device
-
Gateway
-
Protocol
-
Cloud connection
-
Attack surface
-
Security controls
MASTERCLASS
OT Security Validation
Does Your Security Control Actually Work?
Đây là phần làm cho khóa học vượt khỏi mô hình “training course”.
Scenario:
Doanh nghiệp có:
-
Firewall
-
IDS
-
SIEM
-
Segmentation
-
Monitoring
Nhưng:
Có thực sự phát hiện được OT attack không?
Học viên sẽ:
-
Generate normal traffic
-
Generate suspicious traffic
-
Execute controlled attack
-
Observe network
-
Observe IDS
-
Observe SIEM
-
Validate alert
-
Tune detection
-
Repeat attack
-
Measure improvement
LAB
Security Control Validation Mission
Deliverable:
OT Detection Validation Report
CAPSTONE
THE INDUSTRIAL CYBER DEFENSE EXERCISE
Đây là đỉnh của khóa học.
Học viên không còn được hướng dẫn từng bước.
Họ nhận một industrial environment.
Scenario
Một tổ chức vận hành một hệ thống công nghiệp quan trọng.
Hệ thống gồm:
-
Enterprise Network
-
DMZ
-
OT Network
-
SCADA
-
PLC
-
Engineering Workstation
-
Industrial Protocols
-
IDS
-
SIEM
Một số hoạt động bất thường được phát hiện.
Phase 01 — Discovery
Học viên phải:
-
Identify assets
-
Map network
-
Identify protocols
-
Establish baseline
Phase 02 — Risk Assessment
Xác định:
-
Critical assets
-
Vulnerabilities
-
Attack surface
-
Attack paths
Phase 03 — Attack Simulation
Trong phạm vi được kiểm soát:
-
Recon
-
Enumeration
-
Protocol analysis
-
Controlled exploitation
-
Process manipulation scenario
Phase 04 — Detection
Blue Team phải:
-
Detect
-
Investigate
-
Correlate
-
Identify affected assets
Phase 05 — Incident Response
Xác định:
-
Initial access
-
Attack path
-
Compromised assets
-
Process impact
-
Timeline
Phase 06 — Containment
Thiết kế:
-
Network isolation
-
Access restriction
-
Firewall changes
-
Account control
-
Monitoring
Phase 07 — Recovery
-
Restore system
-
Validate PLC/SCADA
-
Validate network
-
Validate process
-
Confirm security state
Phase 08 — Executive Reporting
Học viên phải trình bày trước instructor:
What happened?
Why did it happen?
What was affected?
How was it detected?
What should be changed?
FINAL DELIVERABLE
Mỗi học viên hoàn thành một:
OT Security Assessment & Incident Response Portfolio
Bao gồm:
1. OT Asset Inventory
2. OT Network Architecture
3. Attack Surface Assessment
4. Vulnerability Assessment
5. Attack Path Analysis
6. OT Detection Use Cases
7. Incident Timeline
8. Incident Response Report
9. Security Architecture Recommendations
10. OT Security Improvement Roadmap
Đây là thứ học viên có thể dùng để chứng minh năng lực thực hành, thay vì chỉ có một certificate of completion.
5. Hands-on Lab Portfolio
Chương trình có thể được tổ chức thành 30+ hands-on exercises, ví dụ:
| Lab | Hands-on Mission |
|---|---|
| 01 | Enter the OT Environment |
| 02 | Explore SCADA |
| 03 | Understand PLC Logic |
| 04 | Map OT Assets |
| 05 | Capture Industrial Traffic |
| 06 | Analyze Modbus |
| 07 | Analyze IEC 104 |
| 08 | Analyze S7 |
| 09 | Establish OT Baseline |
| 10 | Discover OT Services |
| 11 | Identify Attack Surface |
| 12 | Analyze Flat OT Network |
| 13 | Build OT Segmentation |
| 14 | Configure Industrial DMZ |
| 15 | Analyze Remote Access |
| 16 | Discover Attack Path |
| 17 | Perform OT Recon |
| 18 | OT Enumeration |
| 19 | Industrial Protocol Security Testing |
| 20 | Controlled OT Attack |
| 21 | OT Vulnerability Assessment |
| 22 | Analyze OT Risk |
| 23 | Deploy OT IDS |
| 24 | Detect Industrial Anomaly |
| 25 | Build Detection Rule |
| 26 | Collect OT Logs |
| 27 | Integrate OT with SIEM |
| 28 | Investigate OT Alert |
| 29 | OT Incident Response |
| 30 | OT Malware Investigation |
| 31 | OT Security Architecture |
| 32 | Security Control Validation |
| 33 | Advanced OT Attack Scenario |
| 34 | Blue Team Defense Scenario |
| 35 | Final Industrial Cyber Defense Exercise |
6. Scenario-Based Training
Ngoài lab theo bài, học viên sẽ tham gia các Industrial Scenarios.
Scenario A — Water Treatment
SCADA + PLC + Modbus
Focus:
-
Process visibility
-
PLC
-
SCADA
-
Modbus
-
OT monitoring
Scenario B — Energy / Substation
SCADA + IEC 104
Focus:
-
Industrial communication
-
Remote control
-
Critical infrastructure
-
Network segmentation
Scenario C — Manufacturing
PLC + HMI + Industrial Network
Focus:
-
Production process
-
PLC security
-
Engineering workstation
-
Lateral movement
Scenario D — Gas / Process Industry
Multi-PLC + SCADA + DMZ
Focus:
-
Process control
-
Segmentation
-
Attack paths
-
Detection
Scenario E — Enterprise-to-OT Attack
IT → DMZ → OT
Focus:
-
Pivoting
-
Segmentation
-
Remote access
-
Detection
-
Incident response
7. Red Team vs Blue Team
Một số buổi học có thể tổ chức theo mô hình:
RED TEAM
Mục tiêu:
Find a path into the industrial process.
BLUE TEAM
Mục tiêu:
Detect, investigate and stop the attack.
PURPLE TEAM
Mục tiêu:
Improve the detection and defense based on the attack.
Chu trình:
Attack → Detect → Investigate → Improve → Re-Attack
Đây là cách biến Cyber Range thành một training environment sống, thay vì một tập hợp lab tĩnh.
8. OT Security Skills Map
Sau chương trình, học viên được đánh giá theo các nhóm năng lực:
OT Fundamentals
★★★★★
ICS/SCADA
★★★★★
PLC
★★★★☆
Industrial Protocols
★★★★★
OT Networking
★★★★★
OT Architecture
★★★★★
OT Pentesting
★★★★☆
OT Vulnerability Management
★★★★☆
OT Detection
★★★★★
OT SIEM
★★★★☆
OT Incident Response
★★★★☆
OT Security Architecture
★★★★★
IIoT Security
★★★☆☆
Cyber Range Operations
★★★★★
9. Training Philosophy
Hands-on First
Lý thuyết chỉ xuất hiện khi cần để giải thích vấn đề mà học viên đang gặp trong lab.
Process First
Không chỉ nhìn vào packet.
Phải hiểu:
Packet → Command → PLC → Process
Evidence First
Không kết luận:
“Đây là attack.”
chỉ vì có một alert.
Phải chứng minh bằng:
Traffic + Logs + Device State + Process Behavior
Safety First
Mọi offensive activity chỉ được thực hiện trong isolated training environment và theo phạm vi được xác định trước.
10. What Makes This Program Different?
Traditional OT Training
Slides → Theory → Quiz
This Program
Industrial Environment → Observe → Operate → Attack → Detect → Investigate → Defend
11. The Final Journey
Học viên bắt đầu với:
“What is OT?”
↓
“How does an industrial system work?”
↓
“How does PLC communicate with SCADA?”
↓
“What does normal OT traffic look like?”
↓
“Where is the attack surface?”
↓
“How could an attacker reach the control system?”
↓
“What happens when the attacker manipulates the system?”
↓
“Can we detect it?”
↓
“Can SOC investigate it?”
↓
“Can we contain it?”
↓
“Can we recover safely?”
↓
“Can we prove that our security controls actually work?”
12. Final Capstone
THE OT CYBER DEFENSE MISSION
Học viên được giao một hệ thống OT chưa biết trước.
Không có walkthrough.
Không có step-by-step guide.
Không có đáp án ngay lập tức.
Học viên phải:
Discover
→ Understand
→ Assess
→ Attack
→ Detect
→ Investigate
→ Respond
→ Defend
→ Validate
→ Report