Training, certifications, labs, protocols, and tooling for OT/ICS penetration testing and security assessments.
- Start Here
- Foundational Knowledge
- Certifications
- Training Courses
- University Courses
- Books
- Youtube Channels
- Standards & Frameworks
- Protocols
- Labs, Simulators & Virtual PLCs
- Hardware to Buy
- Vendor Engineering Software
- Tooling
- CTFs, Ranges & Competitions
- Datasets, PCAPs & Malware Samples
- Threat Intelligence & Malware Research
- Vulnerability Research & Advisories
- Communities, Conferences & People to Follow
- Related Awesome Lists
- Contributing
A short on-ramp for someone coming from a pure IT/web/AD pentesting background:
- Learn the vocabulary and architecture (Purdue Model, PLC/RTU/HMI/SCADA/DCS distinctions, IT vs OT priorities — availability over confidentiality).
- Learn one protocol properly (Modbus is the easiest entry point) before trying to learn all of them.
- Stand up a free simulator (OpenPLC + a HMI, or GRFICS) and attack it yourself before touching real hardware.
- Pick up cheap real hardware (a Raspberry Pi running OpenPLC, or a second-hand Siemens Logo!/S7-1200) once the simulated environment feels comfortable.
- Layer on a vendor-neutral cert (GICSP) once you have hands-on time, not before.
| Certification | Body | Notes |
|---|---|---|
| GICSP (Global Industrial Cyber Security Professional) | GIAC | The de facto entry-level, vendor-neutral OT/ICS cert. No mandatory prerequisite course, though SANS ICS410 is the standard prep path. |
| GRID (GIAC Response and Industrial Defense) | GIAC | GRID certification holders understand how ICS-specific attacks inform mitigation strategies, and are ready to implement fundamental techniques such as network security monitoring (NSM), digital forensics and incident response (DFIR), and Active Defense approaches. |
| GCIP (GIAC Critical Infrastructure Protection) | GIAC | GCIP certification holders understand the regulatory requirements of the North American Electric Reliability Corporation's Critical Infrastructure Protection standards (NERC CIP), and are equipped with practical implementation strategies. |
| ISA/IEC 62443 Certificate Programs (Cybersecurity Fundamentals Specialist, Risk Assessment Specialist, Design/Implementation Specialist, Maintenance Specialist) | ISA/ISASecure | Standards-body certs tied directly to the IEC 62443 series; increasingly referenced in tender/RFP requirements. |
| CompTIA SecOT+ | CompTIA | CompTIA SecOT+ validates your skills to secure and manage operational technology (OT) systems in manufacturing and critical infrastructure. Launches in December 2026. |
| Course | Body | Notes |
|---|---|---|
| CISA (Cybersecurity and Infrastructure Security Agency) | CISA | CISA offers free industrial control systems (ICS) cybersecurity training to protect against cyberattacks on critical infrastructure, such as power grids and water treatment facilities. CISA’s ICS training is globally recognized for its relevance and is available virtually around the world. |
| ICS310: ICS Cybersecurity Foundations | SANS | Entry-level, self-paced, 1-day equivalent. No certification attached — pure foundations for those with zero ICS/OT background. |
| ICS410: ICS/SCADA Security Essentials | SANS | The standard on-ramp course. Prep path for the GICSP certification. Includes a PLC kit students keep. |
| ICS418: ICS Security Essentials for Leaders | SANS | Management/leadership-focused, not technical hands-on. No certification attached. |
| ICS456: Essentials for NERC Critical Infrastructure Protection | SANS | NERC CIP compliance focus, power/utilities sector. Prep path for the GCIP certification. |
| ICS515: ICS Visibility, Detection, and Response | SANS | Active defense/threat-hunting/incident-response focus. Prep path for the GRID certification. |
| ICS612: ICS Cybersecurity In-Depth | SANS | Advanced, hands-on, simulated OT environment across the full Purdue stack. No certification attached currently. |
| ICS613: ICS/OT Penetration Testing & Assessments | SANS | Most directly relevant SANS course for offensive work — safe assessment methodology, protocol analysis, ICS Cyber Kill Chain-aligned attack scenarios. No certification attached currently. |
| IC32: Using the ISA/IEC 62443 Standards to Secure Your Industrial Control Systems | ISA | IC32 is first course in the ISA/IEC 62443 Cybersecurity Certificate Program. Pass the exam to earn the ISA/IEC 62443 Cybersecurity Fundamentals Specialist certificate. |
| IC33: Performing a Cybersecurity Risk Assessment | ISA | IC33 is the second course in the ISA/IEC 62443 Cybersecurity Certificate Program. Pass the exam to earn the ISA/IEC 62443 Cybersecurity Risk Assessment Specialist certificate. |
| IC34: Addressing Cybersecurity for the IACS Design & Implementation | ISA | IC34 is third course in the ISA/IEC 62443 Cybersecurity Certificate Program. Pass the exam to earn the ISA/IEC 62443 Cybersecurity Design Specialist Certificate designation. |
| IC37: Managing Cybersecurity for the IACS Operations & Maintenance Phase | ISA | IC37 is fourth and final course in the ISA/IEC 62443 Cybersecurity Certificate Program. Pass the exam to earn the ISA/IEC 62443 Cybersecurity Maintenance Specialist Certificate designation. |
| ISAGCA Microlearning Modules | ISA | Free, short (5–10 min) modules covering ISA/IEC 62443 topics. |
| EC-Council ICS/SCADA Cybersecurity | EC-Council | Course-plus-exam bundle. Foundational offense/defense concepts. Not equivalent in market weight to GICSP. |
| Dragos Academy Training Courses | Dragos | On-demand training solution offering new and existing Dragos Platform customers resources necessary for successful adoption and operationalization of OT cybersecurity practices and the Dragos Platform technology. Courses can be taken at the convenience of the learner, or monthly in our virtual or in-person live training sessions. |
| Fortiphyd Logic Training | Fortiphyd Logic | Hands-on offensive/defensive labs built by the creators of GRFICS. |
| Book | Author(s) | Notes |
|---|---|---|
| Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid, SCADA, and Other Industrial Control Systems | Eric D. Knapp (and Joel Thomas Langill in later editions) | The standard reference text, now in multiple editions. Vendor-neutral overview of ICS/SCADA architecture and defense-in-depth. |
| Hacking Exposed Industrial Control Systems: ICS and SCADA Security Secrets & Solutions | Clint Bodungen, Bryan Singer, Aaron Shbeeb, Kyle Wilhoit, Jacob Hilt | Offense-oriented, closest in tone to a pentesting field guide. Covers real attack methodologies and exploitation techniques against ICS/SCADA. |
| Practical Industrial Cybersecurity: ICS, Industry 4.0, and IIoT | Charles J. Brooks, Philip A. Craig Jr. | Frequently cited as a GICSP self-study companion. Covers IIoT and Industry 4.0 convergence. |
| Cybersecurity for Industrial Control Systems: SCADA, DCS, PLC, HMI, and SIS | Tyson Macaulay, Bryan L. Singer | Covers ICS threat landscape, risk assessment methodology, and IT-vs-OT security requirement differences. |
| Industrial Automation and Control System Security Principles: Protecting the Critical Infrastructure | Ronald L. Krutz | Broad principles-level text on protecting critical infrastructure control systems. |
| Cyber-security of SCADA and Other Industrial Control Systems | Edward J. M. Colbert, Alexander Kott (eds.) | Academic/reference-style anthology covering ICS threats, attacks, metrics, risk, situational awareness, and intrusion detection. |
| Applied Cyber Security and the Smart Grid | Eric D. Knapp, Raj Samani | Power-sector specific — smart grid architecture and security. |
| Engineering-Grade OT Security: A Manager's Guide | Andrew Ginter | OT security framed from a managerial/engineering-risk perspective rather than a pure technical angle. |
| Implementing IEC 62443 – A Pragmatic Approach to Cybersecurity | Michael D. Medoff, Patrick C. O'Brien | Practical, standards-focused guide to applying the IEC 62443 series. |
| Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon | Kim Zetter | Narrative history of Stuxnet. Good context-building on the field's defining case study; not a technical manual. |
| Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers | Andy Greenberg | Narrative account of state-sponsored ICS/critical-infrastructure attacks (Industroyer, NotPetya, and the Sandworm group). Strong for building non-technical stakeholder buy-in on OT risk. |
| Protecting Industrial Control Systems from Electronic Threats | Joseph Weiss | One of the earliest dedicated ICS security texts; historical grounding on the field's foundational risk concerns. |
| Cyber Attacks on Critical Infrastructures: A Collection of Expert Perspectives | Robert Radvanovsky, Jacob Brodsky (eds.) | Community-anthology collection of articles from a wide range of ICS security practitioners and perspectives. |
| Channel | Type | Description |
|---|---|---|
| @utilsec | Individual Contributor | Getting-started guidance and practical advice for breaking into OT/ICS cybersecurity. |
| @RickCenOT | Individual Contributor | OT/ICS hardware hacking and pentesting, covering SCADA, PLC, and IIoT device security. |
| @ZakharBernhardt | Individual Contributor | Home of Labshock, a virtual OT/ICS lab for hands-on practice. |
| @icsotsecurity | Individual Contributor | Manjunath's channel on industrial automation and OT/ICS/SCADA security, with a strong ISA/IEC 62443 focus. |
| @Cursed_Controls | Individual Contributor | Industrial maintenance, PLCs, VFDs, and motor controls. Raw, hands-on electrical/automation content, not a safety tutorial. |
| @S4Events | Conference | Talks from S4, the largest annual ICS/OT security conference. |
| @ICSVillage | Conference | DEF CON's ICS Village. Critical infrastructure security education, plus the Hack the Planet podcast. |
| @HoustonSecurityConference | Conference | Includes OT.SEC.CON presentations on operational technology security. |
| @CS2AI | Association | Recordings from (CS)²AI, the global nonprofit association for OT/ICS security professionals. |
| @OTSecurityProfessionals | Association | Community-driven OT security content from the OT Sec Professionals group. |
| @SANSICSSecurity | Training Company | SANS' official ICS/OT training content from their instructor lineup. |
| @OPSWATAcademy | Training Company | OPSWAT's training platform covering IT and OT cybersecurity fundamentals. |
| @PrOTectITAll | Podcast | Aaron Crow's podcast on the intersection of OT, IT, and compliance. |
| @ICSArabiaPodcast | Podcast | Sulaiman Alhasawi's ICS/OT security podcast, in English and Arabic. |
| @BitesandBytesPodcast | Podcast | Kristin Demoranville's podcast on cybersecurity in the food & agriculture sector. |
| @LMTX | Individual Contributor | Lukasz Malinowski on IoT/IIoT/OT, aimed at helping SMBs build enterprise-grade solutions. |
| @DragosInc | Vendor | Dragos' ICS/OT threat research and platform content. |
| @WaterfallSecuritySolutions | Vendor | Waterfall Security's content and podcast on cyber-physical OT protection. |
| @Claroty20 | Vendor | Claroty's OT/IoT security research and podcast episodes. |
| @xIoTSecurity | Vendor | Phosphorus' content and podcast on xIoT/OT device security. |
| @NozomiNetworks | Vendor | Nozomi Networks' OT/IoT security content, including talks from Marty Edwards. |
| @InsaneCyberInc | Vendor | Dan Gunter and team on OT/ICS cyber defense. |
| @CISAgov | Government/Regulator | CISA's official channel. Training pointers and critical infrastructure security content. |
| @SimplyCyber | Training Company | General cyber career/training channel now covering OT/ICS with Don Wagner and Tom VanNorman. |
| @PancakesCon | Conference | Lesley Carhart's annual, low-pressure cybersecurity con with a fun twist. |
| @USCSB | Government/Regulator | US Chemical Safety Board. Detailed investigation videos on industrial plant incidents and what went wrong. |
| @RealPars | Training Company | Industrial automation and PLC programming fundamentals across Siemens, Allen-Bradley, and other platforms. Not security-focused, but a strong prerequisite for understanding what you're attacking. |
| @plcprofessor | Individual Contributor | Free, classroom-built lecture and hands-on lab series on PLC fundamentals (RSLogix/Studio 5000), aimed at electricians and engineers new to control systems. |
Use tools with caution and carry out your own DD. I take no responsibility for the function, output, or results of these tools.
| Tool | Category | Note |
|---|---|---|
| SCADAVER | Exploitation Framework | Discovers, enumerates, and exploits devices across twelve industrial control protocols. Single binary with a terminal UI, bloodyAD-style CLI, and REST web interface. |
| Title | Author | Description |
|---|---|---|
| Awesome-ICS-Writeups | neutrinoguy | A collection of writeups related to ICS/SCADA hacking. |
| Awesome-ICS-Malware | donadelden | A curated and updated1 list of awesome (and not-so-awesome) ICS malware. |
| Awesome-Industrial-Protocols | Orange-Cyberdefense | Compilation of industrial network protocols resources focusing on offensive security. |
| Awesome-Industrial_Control-System-Security | hslatman | A curated list of resources related to Industrial Control System (ICS) security. |
This work is licensed under CC BY 4.0.