Cybersecurity

ICS/OT Offensive Security: Red Team Methodology

Structured red team methodology for industrial environments, from reconnaissance through physical impact.

  • Adrian Găitan, Reju Kole, Evaluris Solutions
  • Updated March 2026
  • English
  • 11 sections · 31 lectures · 13h 41m
ICS/OT Offensive Security: Red Team Methodology
Outcomes

What you'll learn

  • Apply a structured red team methodology to ICS/OT environments from reconnaissance through impact
  • Map adversary tactics to MITRE ATT&CK for ICS and plan engagements using real threat actor TTPs
  • Identify and exploit attack surface across PLCs, RTUs, HMIs, historians and OT network architecture
  • Execute initial access techniques including phishing, supply chain abuse and remote access exploitation
  • Perform lateral movement from IT networks into OT environments across Purdue model levels
  • Exploit industrial protocols including Modbus, DNP3, S7Comm and EtherNet/IP offensively
  • Analyze real-world ICS attacks including Stuxnet, Industroyer, Triton and Oldsmar as red team lessons
  • Produce professional OT red team reports communicating physical risk to technical and executive audiences
Overview

About this course

Industrial control systems are among the most critical and most vulnerable targets in the world, yet offensive security training for ICS/OT environments remains rare, expensive, and largely inaccessible. This course teaches you how to think, plan, and operate as a red teamer inside industrial environments.

You will build a complete understanding of OT architecture, industrial protocols, and adversary tradecraft before moving into offensive techniques covering initial access, IT-to-OT pivoting, lateral movement across Purdue model levels, protocol exploitation, and device attacks against PLCs, RTUs, and HMIs.

Every major phase is grounded in real-world adversary behavior mapped to MITRE ATT&CK for ICS, and reinforced through in-depth case studies covering Stuxnet, Industroyer, Triton, and the Oldsmar water treatment attack.

The course closes with a full red team reporting framework designed specifically for OT engagements, including how to communicate physical risk to both technical teams and executive stakeholders.

Prerequisites

Requirements

  • Basic understanding of networking concepts (TCP/IP, VLANs, firewalls)
  • Familiarity with penetration testing fundamentals is recommended but not mandatory
  • No prior ICS/OT experience needed, all industrial concepts are taught from the ground up
Audience

Who this course is for

  • Penetration testers and ethical hackers who want to specialize in ICS/OT offensive security
  • IT security professionals transitioning into operational technology and industrial cybersecurity roles
  • Security consultants, red teamers and engineers supporting critical infrastructure protection programs
More courses

Related courses

Ready to start learning?

Full course access, updates, and Q&A are on Udemy. Enroll through our official Evaluris instructor page.

Enroll on Udemy