PractitionerEICSP

ICS/OT Penetration Testing Practitioner

Build practitioner competence in ICS and OT penetration testing: industrial protocols, PLC and SCADA assessment, firmware analysis, and safe testing of critical infrastructure across 38 structured modules.

Modules

38

Sections

42

Learning path artwork

EICSP

What you'll learn

Syllabus substance

Concrete skills and domains covered in this path, before you dive into the full module list.

OT foundations

  • Industrial landscape, Purdue model, and risk
  • Passive recon and safe asset discovery
  • MITRE ATT&CK for ICS in practice

Industrial protocols

  • Modbus, DNP3, Ethernet/IP, and Profinet
  • Siemens S7 and OPC UA trust models
  • Legacy serial and substation automation

Systems & operations

  • PLC/RTU, HMI, and engineering workstation attacks
  • SCADA, historian, and safety system assessment
  • Full-scope OT red team capstone simulation

Curriculum

Full module syllabus

Every module in this path, with section counts. Sign in to access section content and track progress.

  • 1

    ICS/OT Foundations and the Industrial Landscape

    Industrial control systems, OT versus IT, Purdue model, critical infrastructure sectors, and the threat landscape for OT security practitioners.

    0 sections
  • 2

    Industrial Networking Essentials

    OT network architectures, industrial Ethernet, segmentation, VLANs, routing, and the protocols that underpin plant-floor connectivity.

    0 sections
  • 3

    Linux and Scripting for OT Security Practitioners

    Command-line fluency, Bash and Python scripting, and automation patterns tailored to OT assessment and lab workflows.

    0 sections
  • 4

    OT Security Fundamentals and Risk Concepts

    Safety, availability, and integrity in OT; risk frameworks, consequence-driven prioritisation, and foundational controls for industrial environments.

    0 sections
  • 5

    Modbus: Protocol Analysis and Attack

    Modbus TCP and RTU framing, function codes, safe lab exploitation, and assessment techniques for Modbus-enabled OT assets.

    0 sections
  • 6

    DNP3: Protocol Deep Dive and Exploitation

    DNP3 architecture, outstation and master roles, authentication gaps, and controlled exploitation in utility and substation contexts.

    0 sections
  • 7

    EtherNet/IP and CIP: Protocol Analysis and Attack

    CIP object model, EtherNet/IP encapsulation, Rockwell ecosystem exposure, and offensive assessment of CIP-speaking devices.

    0 sections
  • 8

    PROFINET Security Assessment

    PROFINET DCP, GSDML, IO-controller and IO-device relationships, and security testing in Siemens-centric industrial networks.

    0 sections
  • 9

    Siemens S7 Protocol: Analysis and Exploitation

    S7comm, TIA Portal attack surface, PLC programming interfaces, and exploitation paths against Siemens controllers.

    0 sections
  • 10

    OPC-UA: Architecture, Trust Model, and Security

    OPC-UA information model, certificates, discovery, and offensive assessment of OPC-UA servers and clients in OT integrations.

    0 sections
  • 11

    IEC 61850, BACnet, and Substation Automation Security

    MMS, GOOSE, BACnet/IP, and building-automation crossover risks in substation and facility OT environments.

    0 sections
  • 12

    Legacy and Serial Industrial Protocols

    Serial gateways, proprietary fieldbus protocols, and assessment approaches for legacy plant-floor communications.

    0 sections
  • 13

    Passive Reconnaissance and OSINT in OT Environments

    Vendor documentation, public filings, Shodan, job postings, and non-intrusive intelligence gathering for OT targets.

    0 sections
  • 14

    Active Enumeration and Safe Asset Discovery

    Controlled scanning, protocol fingerprinting, and asset inventory techniques that respect OT safety and scope constraints.

    0 sections
  • 15

    Protocol Traffic Analysis and Deep Packet Inspection

    Wireshark dissectors, ICS protocol decoding, baseline behaviour, and anomaly detection from captured OT traffic.

    0 sections
  • 16

    Authentication Attacks and Credential Exploitation

    Default credentials, weak authentication in OT protocols, password spraying, and credential reuse across IT/OT boundaries.

    0 sections
  • 17

    Introduction to Hardware Attacks

    Hardware security across Bluetooth wireless attacks, cryptanalysis and side-channels, and microprocessor architecture vulnerabilities in ICS and OT environments.

    11 sections
  • 18

    Supply Chain Attacks

    Supply chain threat models, hardware and software vectors, insider threats, and dependency or protestware risks affecting ICS and OT environments.

    14 sections
  • 19

    IT-to-OT Lateral Movement

    Pivoting from corporate IT into OT zones, dual-homed hosts, jump boxes, and tradecraft for controlled lateral movement assessments.

    0 sections
  • 20

    PLC and RTU Exploitation

    Logic manipulation, I/O forcing, firmware interfaces, and exploitation paths against programmable controllers and remote terminal units.

    0 sections
  • 21

    HMI and Engineering Workstation Attacks

    Human-machine interfaces, EWS hardening gaps, project file abuse, and compromise of operator and engineering access paths.

    0 sections
  • 22

    SCADA and Historian Exploitation

    SCADA server attack surface, historian databases, tag manipulation, and impact analysis for supervisory control systems.

    0 sections
  • 23

    DCS Security Assessment

    Distributed control system architecture, controller hierarchy, safety interlocks, and assessment methodology for DCS environments.

    0 sections
  • 24

    Industrial IIoT: Architecture, Protocols, Attack Surface

    Edge gateways, MQTT, cloud connectors, and the expanded attack surface of industrial IoT deployments.

    0 sections
  • 25

    Cloud-Connected OT and Remote Monitoring Security

    Remote access platforms, vendor VPNs, cloud telemetry, and security assessment of externally reachable OT interfaces.

    0 sections
  • 26

    Wireless and RF Attacks in Industrial Environments

    Industrial Wi-Fi, proprietary RF, wireless I/O, and RF assessment techniques in plant and field environments.

    0 sections
  • 27

    Physical Security in Industrial Environments

    Physical access paths, cabinet locks, USB drops, and integrating physical testing with OT penetration test scope.

    0 sections
  • 28

    Firmware Analysis and Reverse Engineering for OT

    Firmware extraction, static and dynamic analysis, Ghidra workflows, and vulnerability discovery in embedded OT devices.

    0 sections
  • 29

    Binary Fuzzing for ICS/OT Systems

    Automated adversarial input testing for native binaries, firmware, and industrial protocol parsers in ICS and OT environments.

    17 sections
  • 30

    ICS Threat Landscape: Nation-State Actors and TTPs

    APT targeting of critical infrastructure, documented campaigns, and threat intelligence for OT security practitioners.

    0 sections
  • 31

    MITRE ATT&CK for ICS: Practical Application

    ICS ATT&CK matrix, technique mapping, detection engineering, and using ATT&CK to structure OT assessments and reports.

    0 sections
  • 32

    ICS Malware Case Studies: Stuxnet to PIPEDREAM

    Landmark ICS malware from Stuxnet through Industroyer, Triton, and PIPEDREAM: mechanics, impact, and lessons for defenders.

    0 sections
  • 33

    IEC 62443 and Regulatory Frameworks for OT Practitioners

    IEC 62443 zones and conduits, NIS2, NERC CIP overview, and aligning pentest deliverables with regulatory expectations.

    0 sections
  • 34

    ICS Pentest: Reporting, Remediation, Professional Practice

    Executive and technical reporting for OT engagements, safety-aware remediation guidance, and professional ethics in critical infrastructure testing.

    0 sections
  • 35

    OT Red Team Operations and Methodology

    Full-scope OT red team planning, ROE, purple-team integration, and operational tradecraft for long-form adversary simulation.

    0 sections
  • 36

    Safety System Assessment and Process Impact Analysis

    SIS, SIL concepts, safety-aware testing boundaries, and process impact analysis for engagements touching safety instrumented systems.

    0 sections
  • 37

    Advanced OT Post-Exploitation and Persistence

    Long-term access in OT networks, living-off-the-land in industrial environments, and persistence without disrupting process availability.

    0 sections
  • 38

    Capstone: Full-Scope OT Red Team Simulation

    Integrated capstone simulating a full-scope OT red team engagement from reconnaissance through reporting in a controlled lab environment.

    0 sections

Enterprise / Organizational ICS-OT Training

Need cohort onboarding, volume licensing, or tailored OT security programs for your organization? Contact our team. This is separate from individual course pricing.

Contact sales

Certification

Earn EICSP

Complete this learning path, then validate your skills with the official Evaluris certification exam.

Certification artwork

EICSP badge · landscape placeholder

Evaluris Certified

EICSP

Evaluris ICS/OT Penetration Testing Practitioner

Practitioner certification in industrial control systems and operational technology security. Covers PLCs, SCADA, industrial protocols, and safe penetration testing of OT environments, for professionals assessing critical infrastructure.

  • Curriculum

    38 Modules

  • Access

    Start learning free today.