
Security Incidents Involving Family Members
Should an Employee Report Security Incidents Involving Family Members? Is your business or job at risk if a bad actor gets access to your family. Will they gain access to you?
This article aims to point security professionals in the right direction to familiarize themselves with ICS/SCADA penetration testing basics. The intended audiences are those who are already proficient in the common internal, external, and web application testing methodology. After reading, security professionals should feel confident and knowledgeable about what steps need to be taken to become adept in the art of ICS/SCADA penetration testing.
Penetration testing is an ever-expanding field with an untold number of specialties and niches. It can be described as a vast and intricate web of interrelated skills and knowledge bases. Not all niches are represented equally regarding the quantity or quality of learning materials. Common testing varieties such as web applications or internal testing have a plethora of learning materials. So much information is readily available that one person could seemingly always have educational resources and never run out. This cannot be said for more specialized testing varieties. Becoming proficient in Operational Technology (OT), Industrial Control Systems (ICS), and Supervisory Control and Data Acquisition (SCADA) network testing can appear daunting as there are fewer learning resources. Even though less training is available, there are still more than enough educational resources out there to develop significant skills in this high-demand niche.
Prior to joining Redbot Security, I had next to no SCADA testing experience apart from a few training exercises during my military service. Redbot Security is one of the few organizations with robust SCADA testing services. Naturally, shortly after joining the team, I was directed to our ICS/SCADA competency development path. Part of this training pipeline includes the Department of Homeland Security (DHS)/ Cybersecurity and Infrastructure Security Agency (CISA) ICS Cybersecurity 301V and 301L classes. The classes were originally a single in-person class but have been split into two classes, one virtual (301V) and the other in-person (301L). This divide was done to make the class more accessible. The 301V class is easily available, but the 301L class still needs to be completed. I myself have enrolled several times, often months in advance, and have yet to be accepted. One of the requirements of the 301L class is the successful completion of the 301V course. The virtual training consists of the following five sessions:
To my surprise, much of the course included concepts found in traditional internal and web app penetration testing. Common strategies including NMAP scanning, using Metasploit to perform a Windows exploit, XSS attacks, and other traditional testing techniques and methodologies were discussed. The most informative section for a seasoned Penetration tester would likely be session one. Information in this section was new to me. They overviewed ICS terminology. All those SCADA buzzwords you have heard again and again will finally start making sense. The meaning and context of Remote Terminal Unit (RTU), Programmable Logic Controller (PLC), Operational Technology (OT), Modbus, and more ICS/SCADA-specific terminology are reviewed. At one point the course gives a walkthrough on PLC programming. The instructor explains how to use ladder logic to program PLC devices. Afterward, several ladder logic exercises are required. These exercises can be completed using plcfiddle.com. This sort of hands-on training greatly assisted my understanding of how PLCs and other parts of the OT network functioned. Keith Cox, Redbot’s Principal Security Engineer, claims that the 301L course delves even deeper into the OT topography. These courses can be found at the CISA training website https://ics-training.inl.gov/.
CISA has several other courses that touch on ICS/SCADA subjects. Redbot’s CISO and Lead Penetration Tester, Andrew Bindner, attended the 401L course aimed at security and compliance at the city, state, and national levels. At the 401L class, Mr. Bindner attended with foreign and domestic teams all focused on ramping up their security skill set. Again, this shows that few resources are available from quality trainers. Furthermore, as a consultant, expect to be waitlisted repeatedly to make room for teams actively working directly in sensitive environments. Overall, the benefit from taking the live, onsite classes is that CISA has built full labs with actual equipment and technologies in use today. This is an expensive endeavor that most security professionals cannot reproduce in a lab due to the expensive overhead cost.
Another excellent resource for learning SCADA hacking is, you guessed it, scadahacker.com. As the name implies, the site is a treasure trove of ICS/SCADA hacking content. In addition to highly accredited training, the site has an excellent library. The https://scadahacker.com/library directory is a compilation of incredible resources. There you can find all sorts of documents ranging from ICS vulnerabilities, assessment guidelines, best practices, policies, standards, and even lists of tools used in or specifically designed for ICS/SCADA testing. One excellent research paper in the scadahacker.com library is Hacker Machine Interface – State of SCADA HMI Vulnerabilities. This document made by the Trend Micro Zero Day Initiative Team explains why hackers target Human Machine Interface (HMI) devices and the most common vulnerabilities found on these machines. The four vulnerability classes that were most prevalent were:
This, among many other documents in the scadahacker.com library, is an exceptional tool for learning the types of vulnerabilities and threats that plague ICS/SCADA networks. It is important to note that scadahacker.com is in the process of migrating to a new website. The new site, https://icscsi.org/, appears to offer the same/similar training and the library appears to have been copied as well.
Using these resources, a penetration tester can become familiar with SCADA networks and their vulnerabilities. The next big question is “Are there any SCADA-specific hacking tools?”. The answer to that question is a resounding “Yes!”. An excellent GitHub repository is filled with tools designed to keep SCADA system admins from sleeping at night. The repository at https://github.com/hslatman/awesome-industrial-control-system-security has links to a large variety of tools and educational resources for SCADA hacking and security. Bear in mind that SCADA networks are sensitive, and there are often millions of dollars and potentially human lives at risk. Be sure to thoroughly investigate and test any tools in a lab environment you intend to use on a SCADA network. Always place caution and safety first when deciding to use tools, scans, or attacks. Remember no training or tools beats real-life experience. Ensure that you are not testing SCADA networks without having first been brought up to speed by experienced ICS penetration testers.
Beginning the ICS/SCADA penetration testing learning journey can often appear insurmountable. The number of resources, when compared to any of the more common penetration testing varieties, seems limited. The task is not hopeless, there are quality resources out there. Resources such as the DHS/CISA 301 ICS Security courses, scadahacker.com, and large repositories of tools are available only a few clicks away. Hopefully, you now feel confident that you can begin your learning process and become a skilled and proficient ICS/SCADA penetration tester.
Conner brings 6+ years of military cyber operations experience and served as a Cyber Operations Specialist with the work roles of Special Activities Team (SAT) Technician, Expeditionary Cyber Operator (ECO), Information Operations Operator, and Pilot Operator. Conner is a core member of Redbot Security's team, continuing to execute Sr. Level Penetration Testing. Conner is also Redbot Security's Wireless SME.
Senior Level Hands-on-Keyboard
Manual Testing
Get a Project QuoteShould an Employee Report Security Incidents Involving Family Members? Is your business or job at risk if a bad actor gets access to your family. Will they gain access to you?
The likelihood of a cyber attack on a mobile platform is significantly high, but how difficult is it for a malicious actor to generate malware? You might be surprised.
Insecure Direct Object Reference (IDOR) vulnerabilities pose a significant risk to the security of web applications, allowing attackers unauthorized access to sensitive data and functionalities. By understanding the implications of IDOR and adopting secure coding practices, web developers can protect their applications and users from potential exploitation.
Mass Assignment Vulnerability occurs when a web application allows users to submit a more extensive set of data than is intended or safe. The potential consequences of this vulnerability can be severe
Attackers can manipulate the serialized data to execute malicious code, compromise the application, or gain unauthorized access.
Kerberos Authentication Service Response (AS-REP) Roasting, a technique similar to Kerberoasting, has gained prominence as a method for attackers to compromise Active Directory (AD) authentication systems.
Becoming proficient in Operational Technology (OT), Industrial Control Systems (ICS), and Supervisory Control and Data Acquisition (SCADA) network testing can appear daunting as there are fewer learning resources.
Machine Learning (ML) is a subset of AI, and, more than likely, closely aligns with what we consider to be AI in the media.
Recent reports of significant cybersecurity layoffs in the United States have raised concerns about the nation’s preparedness to defend against cyber threats
The FBI released its FY 2024 IC3 Annual Report on April 24, 2025, detailing 859,532 complaints and a record $16.6 billion in losses. In this post, we highlight how phishing, BEC, and cryptocurrency fraud continue to surge, why ransomware remains a top threat to critical infrastructure, and which demographics are most at risk. Plus, discover Redbot Security’s proven strategies,from manual penetration testing to red teaming, that can help you turn IC3 data into actionable defenses.
From API-server exploits to supply-chain threats, this checklist shows how the best penetration testing companies harden Kubernetes. Boost resilience now.
Cybercriminals are ditching malware and exploiting trusted tools already inside your systems. Learn how Living off the Land (LotL) attacks work, and how to stop them.
From pipelines and water systems to power grids and transit networks, U.S. critical infrastructure is under siege. With CISA budget slashed, is a national cyber disaster inevitable?
Understanding NIST 800 and Its Impact on Penetration Testing Requirements.
Internal network penetration testing is essential for identifying security gaps within an organization’s infrastructure. Attackers exploit misconfigured permissions, weak credentials, and unpatched vulnerabilities to escalate privileges and move laterally within networks. A thorough penetration test helps uncover these risks before they are exploited, ensuring stronger security controls, improved access management, and compliance with industry standards. Redbot Security’s expert-led penetration testing provides in-depth assessments to fortify your internal network against evolving threats.
Redbot Security’s senior-level cloud security team brings years of expertise in AWS, GCP, and Azure security. Our approach is rooted in manual-controlled testing and deep-dive security analysis, ensuring that we uncover hidden vulnerabilities that automated tools often miss.
Cymbiotic Hive: The Simple, Rapid-Deployment Solution to Access Management
With data breaches surging by 68% last year alone, cybersecurity has evolved from a low-key technical matter into a defining issue demanding top-level attention.
Increasingly, investors see proactive cybersecurity spending as a hallmark of strong corporate governance. It can be factored into how they value a company’s resilience and risk profile
Our nation is under attack and overwhelmed. Modern Security teams face numerous challenges in managing network and application security effectively.
Our nation is under attack and overwhelmed. Modern Security teams face numerous challenges in managing network and application security effectively.
Is your security team sharing sensitive data unknowingly?
Through repeated random sampling, allows us to simulate a wide array of social engineering attacks with a depth and breadth previously unimaginable.
While penetration testing is valuable in identifying technical vulnerabilities, red teaming provides a more holistic assessment by simulating realistic threat scenarios. By embracing red teaming, organizations can bolster their defenses, uncover weaknesses, and stay one step ahead of sophisticated adversaries.
Malicious actors leveraging OSINT to uncover confidential and sensitive information that is publicly available online. Learn how to prevent risks.
Client-side desyncs are a class of browser-powered HTTP smuggling attacks. What you need to know and how to prevent a malicious actor from taking advantage of this vulnerability.
Active Directory Certificate Services (AD CS) presents various security risks for organizations. This article will help you understand a Relay Attack.
What is an API? APIs, including local and remote, come in various forms and are fundamental to modern software development. They serve as the bridge between different software components, enabling them to work together seamlessly.
While plenty of articles cover the Modbus protocol with varying degrees of detail and usage, this article aims to examine the Modbus protocol with an offensive security lens.
Malicious actors prey on weak configurations like locusts. Microsoft, despite knowing that their operating systems, have inherent weaknesses have done little to enhance their initial security outside of remediation for publicly known vulnerabilities.
The following article is a discussion about helping you to best utilize your military skills to successfully transition into the commercial space.
The following article is a discussion that explores JavaScript Web Tokens
The following article is a discussion that explores Wave Behaviors to Locate Wireless Access Points and Devices
Today, cybercriminals have plenty of entry points to exploit. Therefore, it has become crucial for organizations to improve their attack surface visibility to have more effective protection. This is where attack surface management (ASM) comes into play. This article will explore all about attack surface management (ASM), including its importance, working principle, and benefits.
Check out the latest cybersecurity news around the globe
Over 40 leading cybersecurity professionals and infosec experts have signed an open letter […]
A high severity flaw affecting Broadcom’s Brocade Fabric OS (FOS) has allowed attackers to run […]
width="2490" height="1400" sizes="(max-width: 2490px) 100vw, 2490px">Auf Berlins Info- und […]
CISOs seeking insights into the latest cyberattack trends should note that cybercriminals’ […]
Die Ransomware-Gruppe Akira soll bei Hitachis IT-Services- und Infrastruktur-Tochter zugeschlagen […]
Our expert team will help scope your project and provide a fast and accurate project estimate.
Contact Redbot Security