WS6 - ICS Hack 'n Track
Description
Instructed by: Pedro Cabrera
Level of Difficulty: Beginner, Intermediate, Advanced, Expert
Abstract:
ICS Hack 'n Track is a hands-on OT security workshop where students work through a complete red-to-blue incident inside their own isolated AWS VPC. We simulate the architecture of the Siemens Energy Omnivise T3000 DCS - the industrial control system behind over 600 GW of electrical power generation. The scenario starts with a realistic mistake: temporary troubleshooting access was poorly controlled, a Terminal Server was left reachable over SSH, and an attacker used that exposure as the first step toward the operational network.
Students will begin the red-team portion of the workshop by performing intelligence gathering through a search-style exposure portal, identifying the misconfigured Terminal Server, and brute forcing SSH access. From that foothold, they will explore the internal network, discover an Application Server which gives access to a PLC, and deploy a Caldera agent through the access path they established.
Once the foothold is active, students will build an S7comm adversary in Caldera. They will perform network discovery, discover the PLC, collect data about the PLC, stage and verify control actions against the PLC, and ultimately send a catastrophic PLC STOP command. The simulated PLC responds just like a real PLC in a T3000 system would using real S7comm/ISO-on-TCP interactions.
After the red-team exercise, the class switches hats. Each student's VPC includes its own Malcolm instance, allowing participants to investigate the traffic and artifacts generated by their own actions. Students will reconstruct the intrusion from network traffic analysis and syslogs. Students will separate suspicious behavior from confirmed malicious behavior, see what a defender would have seen at each stage of the attack, and identify which controls would have interrupted the chain.
By the end of this workshop, participants will be able to:
- Execute a staged OT adversary-emulation workflow in Caldera.
- Explain how exposed remote access can become a path toward PLC-impacting activity.
- Generate and interpret S7comm network traffic.
- Use Malcolm to correlate attack actions with network and protocol-level evidence.
- Produce a concise attack timeline, detection idea, and hardening recommendation.
This workshop is designed for OT security engineers, SOC analysts, ICS defenders, red teamers, and security practitioners who want more than a slide-level explanation of industrial risk. Students should understand basic TCP/IP concepts and be comfortable using SSH. Prior experience with Caldera, Malcolm, Siemens S7, or industrial environments is helpful but not required. No local virtualization, PLC hardware, or paid software is required.
Pre-Requisites:
Participants should understand TCP/IP basics. Experience with a SIEM, Caldera, or OT environments will be helpful but we will cover everything needed even for a beginner
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


