ICS/OT Penetration Testing Practitioner
Build practitioner competence in ICS and OT penetration testing: industrial protocols, PLC and SCADA assessment, firmware analysis, and safe testing of critical infrastructure across 38 structured modules.
Modules
38
Sections
42
Learning path artwork
EICSP
What you'll learn
Syllabus substance
Concrete skills and domains covered in this path, before you dive into the full module list.
OT foundations
- •Industrial landscape, Purdue model, and risk
- •Passive recon and safe asset discovery
- •MITRE ATT&CK for ICS in practice
Industrial protocols
- •Modbus, DNP3, Ethernet/IP, and Profinet
- •Siemens S7 and OPC UA trust models
- •Legacy serial and substation automation
Systems & operations
- •PLC/RTU, HMI, and engineering workstation attacks
- •SCADA, historian, and safety system assessment
- •Full-scope OT red team capstone simulation
Curriculum
Full module syllabus
Every module in this path, with section counts. Sign in to access section content and track progress.
- 1
ICS/OT Foundations and the Industrial Landscape
Industrial control systems, OT versus IT, Purdue model, critical infrastructure sectors, and the threat landscape for OT security practitioners.
0 sections - 2
Industrial Networking Essentials
OT network architectures, industrial Ethernet, segmentation, VLANs, routing, and the protocols that underpin plant-floor connectivity.
0 sections - 3
Linux and Scripting for OT Security Practitioners
Command-line fluency, Bash and Python scripting, and automation patterns tailored to OT assessment and lab workflows.
0 sections - 4
OT Security Fundamentals and Risk Concepts
Safety, availability, and integrity in OT; risk frameworks, consequence-driven prioritisation, and foundational controls for industrial environments.
0 sections - 5
Modbus: Protocol Analysis and Attack
Modbus TCP and RTU framing, function codes, safe lab exploitation, and assessment techniques for Modbus-enabled OT assets.
0 sections - 6
DNP3: Protocol Deep Dive and Exploitation
DNP3 architecture, outstation and master roles, authentication gaps, and controlled exploitation in utility and substation contexts.
0 sections - 7
EtherNet/IP and CIP: Protocol Analysis and Attack
CIP object model, EtherNet/IP encapsulation, Rockwell ecosystem exposure, and offensive assessment of CIP-speaking devices.
0 sections - 8
PROFINET Security Assessment
PROFINET DCP, GSDML, IO-controller and IO-device relationships, and security testing in Siemens-centric industrial networks.
0 sections - 9
Siemens S7 Protocol: Analysis and Exploitation
S7comm, TIA Portal attack surface, PLC programming interfaces, and exploitation paths against Siemens controllers.
0 sections - 10
OPC-UA: Architecture, Trust Model, and Security
OPC-UA information model, certificates, discovery, and offensive assessment of OPC-UA servers and clients in OT integrations.
0 sections - 11
IEC 61850, BACnet, and Substation Automation Security
MMS, GOOSE, BACnet/IP, and building-automation crossover risks in substation and facility OT environments.
0 sections - 12
Legacy and Serial Industrial Protocols
Serial gateways, proprietary fieldbus protocols, and assessment approaches for legacy plant-floor communications.
0 sections - 13
Passive Reconnaissance and OSINT in OT Environments
Vendor documentation, public filings, Shodan, job postings, and non-intrusive intelligence gathering for OT targets.
0 sections - 14
Active Enumeration and Safe Asset Discovery
Controlled scanning, protocol fingerprinting, and asset inventory techniques that respect OT safety and scope constraints.
0 sections - 15
Protocol Traffic Analysis and Deep Packet Inspection
Wireshark dissectors, ICS protocol decoding, baseline behaviour, and anomaly detection from captured OT traffic.
0 sections - 16
Authentication Attacks and Credential Exploitation
Default credentials, weak authentication in OT protocols, password spraying, and credential reuse across IT/OT boundaries.
0 sections - 17
Introduction to Hardware Attacks
Hardware security across Bluetooth wireless attacks, cryptanalysis and side-channels, and microprocessor architecture vulnerabilities in ICS and OT environments.
11 sections - 18
Supply Chain Attacks
Supply chain threat models, hardware and software vectors, insider threats, and dependency or protestware risks affecting ICS and OT environments.
14 sections - 19
IT-to-OT Lateral Movement
Pivoting from corporate IT into OT zones, dual-homed hosts, jump boxes, and tradecraft for controlled lateral movement assessments.
0 sections - 20
PLC and RTU Exploitation
Logic manipulation, I/O forcing, firmware interfaces, and exploitation paths against programmable controllers and remote terminal units.
0 sections - 21
HMI and Engineering Workstation Attacks
Human-machine interfaces, EWS hardening gaps, project file abuse, and compromise of operator and engineering access paths.
0 sections - 22
SCADA and Historian Exploitation
SCADA server attack surface, historian databases, tag manipulation, and impact analysis for supervisory control systems.
0 sections - 23
DCS Security Assessment
Distributed control system architecture, controller hierarchy, safety interlocks, and assessment methodology for DCS environments.
0 sections - 24
Industrial IIoT: Architecture, Protocols, Attack Surface
Edge gateways, MQTT, cloud connectors, and the expanded attack surface of industrial IoT deployments.
0 sections - 25
Cloud-Connected OT and Remote Monitoring Security
Remote access platforms, vendor VPNs, cloud telemetry, and security assessment of externally reachable OT interfaces.
0 sections - 26
Wireless and RF Attacks in Industrial Environments
Industrial Wi-Fi, proprietary RF, wireless I/O, and RF assessment techniques in plant and field environments.
0 sections - 27
Physical Security in Industrial Environments
Physical access paths, cabinet locks, USB drops, and integrating physical testing with OT penetration test scope.
0 sections - 28
Firmware Analysis and Reverse Engineering for OT
Firmware extraction, static and dynamic analysis, Ghidra workflows, and vulnerability discovery in embedded OT devices.
0 sections - 29
Binary Fuzzing for ICS/OT Systems
Automated adversarial input testing for native binaries, firmware, and industrial protocol parsers in ICS and OT environments.
17 sections - 30
ICS Threat Landscape: Nation-State Actors and TTPs
APT targeting of critical infrastructure, documented campaigns, and threat intelligence for OT security practitioners.
0 sections - 31
MITRE ATT&CK for ICS: Practical Application
ICS ATT&CK matrix, technique mapping, detection engineering, and using ATT&CK to structure OT assessments and reports.
0 sections - 32
ICS Malware Case Studies: Stuxnet to PIPEDREAM
Landmark ICS malware from Stuxnet through Industroyer, Triton, and PIPEDREAM: mechanics, impact, and lessons for defenders.
0 sections - 33
IEC 62443 and Regulatory Frameworks for OT Practitioners
IEC 62443 zones and conduits, NIS2, NERC CIP overview, and aligning pentest deliverables with regulatory expectations.
0 sections - 34
ICS Pentest: Reporting, Remediation, Professional Practice
Executive and technical reporting for OT engagements, safety-aware remediation guidance, and professional ethics in critical infrastructure testing.
0 sections - 35
OT Red Team Operations and Methodology
Full-scope OT red team planning, ROE, purple-team integration, and operational tradecraft for long-form adversary simulation.
0 sections - 36
Safety System Assessment and Process Impact Analysis
SIS, SIL concepts, safety-aware testing boundaries, and process impact analysis for engagements touching safety instrumented systems.
0 sections - 37
Advanced OT Post-Exploitation and Persistence
Long-term access in OT networks, living-off-the-land in industrial environments, and persistence without disrupting process availability.
0 sections - 38
Capstone: Full-Scope OT Red Team Simulation
Integrated capstone simulating a full-scope OT red team engagement from reconnaissance through reporting in a controlled lab environment.
0 sections
Enterprise / Organizational ICS-OT Training
Need cohort onboarding, volume licensing, or tailored OT security programs for your organization? Contact our team. This is separate from individual course pricing.
Certification
Earn EICSP
Complete this learning path, then validate your skills with the official Evaluris certification exam.
Certification artwork
EICSP badge · landscape placeholder
Evaluris Certified
EICSP
Evaluris ICS/OT Penetration Testing Practitioner
Practitioner certification in industrial control systems and operational technology security. Covers PLCs, SCADA, industrial protocols, and safe penetration testing of OT environments, for professionals assessing critical infrastructure.
Curriculum
38 Modules
Access
Start learning free today.