Cybersecurity · Free · ₹0

OT Security Assessment: Testing a Plant Without Stopping It

The assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.

4.8EDWartens India · 524+ reviews 12 modules 8h 50m of video English · self-paced

Inside the course

OT Security Assessment: Testing a Plant Without Stopping It: Syllabus at a glanceOT Security Assessment: Testing a Plant Without Stopping It: What you will be able to doOT Security Assessment: Testing a Plant Without Stopping It: Tools and credits

From the lessons

  • Attacker Methodology | SANS ICS Concepts

    Rules of Engagement: Assessing a Plant That Is Running

    SANS ICS Security

  • Network Architecture | SANS ICS Concepts

    The Ground You Are Assessing: Architecture and Segmentation

    SANS ICS Security

  • Modbus Traffic Analysis | SANS ICS Concepts

    Reading the Traffic Before You Send Any

    SANS ICS Security

  • Modbus Enumeration | SANS ICS Concepts

    Enumeration, Carefully

    SANS ICS Security

  • Modbus Man-In-The-Middle | SANS ICS Concepts

    What the Attacker Does Next

    SANS ICS Security

  • MITRE ATT&CK Navigator Overview | SANS ICS Concepts

    Naming What You Found: ATT&CK for ICS

    SANS ICS Security

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Write rules of engagement for assessing a system that cannot be stopped; draw and test the zone boundaries that are supposed to exist; capture and read ICS traffic before sending any; enumerate a Modbus endpoint knowing the cost of every request; explain a man-in-the-middle and a forever-day vulnerability and choose compensating controls for a device that will never be patched; assess the engineering workstation and the service accounts on it; leave behind logging and an integrity baseline; decide whether deception is worth its operational cost; review PLC code against the Top 20 Secure PLC Coding Practices; and write a two-page report ordered by consequence that says what you did not test and why.

  • Write rules of engagement with a window, a named owner and an abort condition, for a plant that cannot stop
  • Draw the zones yourself and test each conduit from the side it is meant to protect
  • Capture and read ICS traffic in Wireshark, tshark and Zeek before sending a single packet
  • Enumerate a Modbus device knowing what every request will do, and say when it is not worth the risk
  • Explain a Modbus man-in-the-middle and choose compensating controls for a device nobody will ever patch
  • Map findings to ATT&CK for ICS honestly, and read a real incident as a chain of techniques
  • Assess an engineering workstation: local accounts, services, shares and who can reach it
  • Leave behind Windows logging and an integrity baseline on a host that must never be rebooted
  • Review PLC code against the Top 20 Secure PLC Coding Practices and raise a finding engineering will accept
  • Write the two-page report: scope, method, findings by consequence, and what you deliberately did not test

Course content

12 modules · 22 lessons · 8h 50m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last, and a short quiz.

  1. 01Rules of Engagement: Assessing a Plant That Is Running52m
  2. 02The Ground You Are Assessing: Architecture and Segmentation51m
  3. 03Reading the Traffic Before You Send Any39m
  4. 04Enumeration, Carefully49m
  5. 05What the Attacker Does Next53m
  6. 06Naming What You Found: ATT&CK for ICS24m
  7. 07The Windows Machines Nobody Mentions53m
  8. 08Seeing It Happen: Windows Logging and Integrity Baselines1h 3m
  9. 09Deception and Hunting34m
  10. 10Assessing the Logic Itself50m
  11. 11The Report, and the Assessment You Can Repeat53m
  12. 12Final Assessment9m

Requirements

Who it is for
Intermediate. You should already know what a PLC, an HMI and a SCADA system are, and how they sit on a network. ICS Security Foundations covers that in five hours if you do not. No penetration testing background is assumed.
Software
Wireshark, a Linux virtual machine, a Modbus simulator or a lab PLC, and CHAPS. All free downloads. Nothing in this course requires a licence or a paid lab.
Hardware
None required. A spare PLC or a Raspberry Pi running a Modbus simulator makes the enumeration and capture work more real, and every exercise is written to work without one.

OT Security Assessment: Testing a Plant Without Stopping It at a glance

OT Security Assessment: Testing a Plant Without Stopping It is a free, self-paced online cybersecurity course from EDWartens India with 12 modules, 8h 50m of video lessons, written notes, practice tasks and assessments, and an optional verifiable certificate.

Price
₹0, free for good. No trial, no card. Comparable classroom training of this length costs about ₹5,999.
Format
12 self-paced modules, 8h 50m of video, written notes, a practice task per module and one final assessment.
Level
Intermediate. Intermediate. You should already know what a PLC, an HMI and a SCADA system are, and how they sit on a network. ICS Security Foundations covers that in five hours if you do not. No penetration testing background is assumed.
Brand
Vendor-neutral
Software
Wireshark, a Linux virtual machine, a Modbus simulator or a lab PLC, and CHAPS. All free downloads. Nothing in this course requires a licence or a paid lab.
Hardware
None required. A spare PLC or a Raspberry Pi running a Modbus simulator makes the enumeration and capture work more real, and every exercise is written to work without one.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
SANS ICS Security (independent creators, credited below)
Language
English

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

  • Add it to your LinkedIn profile in one click
  • Link it from a CV or portfolio, the URL is permanent
  • Publicly verifiable by code, not a PDF anyone can edit
  • Issued by EDWartens India, the training centre itself

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

  • Questions answered in the context of the module you are on
  • The same engineers who teach the AEP programme
  • Career tools, CV help and public job listings included
  • Your progress and notes stay in your account for good

Pairs well with

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of OT Security Assessment: Testing a Plant Without Stopping It, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

Is this a hacking course?

No. It is an assessment course, and the difference matters on a plant. It teaches you to evaluate systems you are authorised to evaluate, for the people who own them, and the first module is entirely about the permission, the window and the condition under which you stop. There is no exploit development here and nothing is aimed at systems you do not own. Where the course covers what an attacker does, such as a Modbus man-in-the-middle, it does so because you cannot defend or assess a protocol whose weaknesses you have not seen.

How is it different from the OT and ICS Cybersecurity course?

That course is the standards and programme side: ISA/IEC 62443 clause by clause, security levels, risk assessment, governance. It is forty-four hours. This one is the practical assessment: what you actually do in the four days you are on site, in the order that keeps the plant running. They complement each other and neither repeats the other. If you have done neither, ICS Security Foundations is the five-hour place to start.

Do I need a lab, or a real PLC?

No. Every exercise is written to work with a free Modbus simulator on a laptop and a Linux virtual machine. A spare PLC or a Raspberry Pi running a simulator makes the capture and enumeration work feel real, and several people find that worth the effort, but nothing in the course assumes you have one.

Do I need penetration testing experience?

No, and the course is deliberately not written for penetration testers moving into OT. It is written for automation engineers who already understand plants and are being asked to assess them, which is the more common situation in India and the one that is worse served.

Is this a SANS course, or does it lead to a GIAC certification?

No. Every video lesson is from the SANS ICS Security channel's free ICS Concepts series, credited on each module, and SANS is not affiliated with EDWartens. SANS run their own paid courses and GIAC issue their own certifications; this course is neither and does not count towards either. What EDWartens wrote is the study plan, the objectives, the practice tasks, the notes and the assessments.

What will I have at the end?

A two-page assessment report on a system you chose, with scope, method, findings ordered by consequence, and a section naming what you deliberately did not test. That report is the deliverable of the course and is the thing worth showing an employer, more than the certificate is.

Is the course really free?

Yes. Every module, every practice task and the final assessment. You create an account so your progress is saved and the assessment can be marked. The only paid item is the certificate, and only if you decide you want it.

What certificate do I get?

An EDWartens Certificate of Completion, issued when you have worked through every module and passed the final assessment, with a unique number anyone can verify on our site. It is not a vendor or industry credential and we will never describe it as one.

What you walk away with

Your certificate for OT Security Assessment: Testing a Plant Without Stopping It

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for OT Security Assessment: Testing a Plant Without Stopping It
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

    A unique certificate number and a public verification page. A recruiter checks it in ten seconds.

  • Adds to LinkedIn in one click

    Issuer, credential ID and URL prefilled, with 5 matching skills to pin to your profile.

  • QR code on the certificate

    Scans straight to the verification page, so a printed copy proves itself.

  • Names what you can do

    Lists the topics covered, from rules of engagement for assessing a plant that is running, and why availability outranks the finding to the engineering workstation, windows logging and integrity baselines, att&ck for ics, secure plc coding practices and a report ordered by consequence.

  • A permanent link

    Put it on a CV, a portfolio or an application. The URL never changes.

  • Earned, not attended

    Issued only after every module and a final assessment at 60%, with 3 attempts. That is why it stands up.

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, ₹559, GST included, with a receipt.

Issued by EDWartens India (Wartens Automation Private Limited) as a Certificate of Completion for this self-paced course. It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • SANS ICS Securitythe entire ICS Concepts series that this course is built from: attacker methodology, field practice, network architecture, Modbus traffic analysis, enumeration and man-in-the-middle, Zeek, ATT&CK Navigator, Windows hardening and logging, integrity baselining, honeypots, the Top 20 Secure PLC Coding Practices, CHAPS and cyber informed engineering

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.