More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS6 - ICS Hack 'n Track

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  Pedro  Cabrera

Level of Difficulty: Beginner, Intermediate, Advanced, Expert

Abstract:

ICS Hack 'n Track is a hands-on OT security workshop where students work through a complete red-to-blue incident inside their own isolated AWS VPC. We simulate the architecture of the Siemens Energy Omnivise T3000 DCS - the industrial control system behind over 600 GW of electrical power generation. The scenario starts with a realistic mistake: temporary troubleshooting access was poorly controlled, a Terminal Server was left reachable over SSH, and an attacker used that exposure as the first step toward the operational network.

Students will begin the red-team portion of the workshop by performing intelligence gathering through a search-style exposure portal, identifying the misconfigured Terminal Server, and brute forcing SSH access. From that foothold, they will explore the internal network, discover an Application Server which gives access to a PLC, and deploy a Caldera agent through the access path they established.

Once the foothold is active, students will build an S7comm adversary in Caldera. They will perform network discovery, discover the PLC, collect data about the PLC, stage and verify control actions against the PLC, and ultimately send a catastrophic PLC STOP command. The simulated PLC responds just like a real PLC in a T3000 system would using real S7comm/ISO-on-TCP interactions.

After the red-team exercise, the class switches hats. Each student's VPC includes its own Malcolm instance, allowing participants to investigate the traffic and artifacts generated by their own actions. Students will reconstruct the intrusion from network traffic analysis and syslogs. Students will separate suspicious behavior from confirmed malicious behavior, see what a defender would have seen at each stage of the attack, and identify which controls would have interrupted the chain.

By the end of this workshop, participants will be able to:

- Execute a staged OT adversary-emulation workflow in Caldera.
- Explain how exposed remote access can become a path toward PLC-impacting activity.
- Generate and interpret S7comm network traffic.
- Use Malcolm to correlate attack actions with network and protocol-level evidence.
- Produce a concise attack timeline, detection idea, and hardening recommendation.

This workshop is designed for OT security engineers, SOC analysts, ICS defenders, red teamers, and security practitioners who want more than a slide-level explanation of industrial risk. Students should understand basic TCP/IP concepts and be comfortable using SSH. Prior experience with Caldera, Malcolm, Siemens S7, or industrial environments is helpful but not required. No local virtualization, PLC hardware, or paid software is required.

Pre-Requisites:

Participants should understand TCP/IP basics. Experience with a SIEM, Caldera, or OT environments will be helpful but we will cover everything needed even for a beginner

Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops