Attack and Defense in OT: Enhancing Cyber Resilience in Industrial Systems with Red Team Operations
ID: 32c3fe75-e7d0-5a7c-b2a4-bcd3a039a712
STIX ID: report--32c3fe75-e7d0-5a7c-b2a4-bcd3a039a712
Feed Name: NVISO Labs
This blog post examines OT security through the lens of Red Team operations, contrasting OT and IT priorities and highlighting the growing risk from increased connectivity, a worsening threat landscape, and regulatory drivers. It references real-world OT threats, including the Electrum APT and CRASHOVERRIDE, as well as the ModbusTCP-focused FrostyGoop malware, to contextualize risks. Two case stories demonstrate practical attacker TTPs—phishing and file share poisoning to pivot from IT to OT via Siemens TIA Portal, and a social-engineering-enabled physical breach leading to implant placement and credential discovery—culminating in lessons learned on segmentation, privilege management, email security, physical security, and continuous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
