INDUS-CYBSEC.AJ1 ISBN: 979-8-90059-014-1
Industrial Cybersecurity
Start your career by mastering the defense of the critical infrastructure with the definitive industrial cybersecurity course.
What you will be able to do
- Architecture & Standards: Master the architecture of Industrial Control Systems (ICS) & implement designs aligned with the key ISA IEC 62443 standard and the Industrial Demilitarized Zone (IDMZ).
- Active Monitoring & Threat Hunting: Conquer intrusion detection, security monitoring, and active threat hunting techniques specifically tailored for OT cybersecurity environments.
- Assessment & Testing: Grasp the methodologies for performing comprehensive ICS security risk assessment, penetration testing, & red/blue team exercises without disrupting operations.
- Response & Forensic: Build a strong theoretical foundation base for performing incident response procedures & forensics designed specifically for the unique sensitivities of SCADA security & industrial environments.
Intermediate Self-paced · 1 year access
25 Hands-On LiveLabs
Practice real IT tasks in guided environments.
- Real environments
- Auto-graded
- No installation
01 / About
About This Course
Are you tired of treating complex industrial systems such as IT environments? However, this specialised course offers the rigorous foundation to design, implement & troubleshoot industrial cybersecurity solutions in the environments where downtime is not an option.
Mastering OT cybersecurity is one of the most important things for securing high-end roles in the field of operational technology (OT) security. Therefore, the program is typically aligned with the foundational ISA IEC 62443 standards.
02 / Lessons & labs
See exactly what you will learn and practice
Lessons
20 Interactive Lessons · 109 topics01 Preface 2 topics +
- Who this course is for
- What this course covers
02 Introduction and Recap of First Edition 4 topics +
- Industrial Cybersecurity – second edition
- Recap of the first edition
- What is an ICS?
- Summary
03 A Modern Look at the Industrial Control System Architecture 3 topics · 2 LiveLab +
- Why proper architecture matters
- Industrial control system architecture overview
- Summary
2 LiveLab in this lesson — see the labs panel →
04 The Industrial Demilitarized Zone 4 topics · 1 LiveLab +
- The IDMZ
- What makes up an IDMZ design?
- Example IDMZ broker-service solutions
- Summary
1 LiveLab in this lesson — see the labs panel →
05 Designing the ICS Architecture with Security in Mind 4 topics · 1 LiveLab +
- Typical industrial network architecture designs
- Designing for security
- Security monitoring
- Summary
1 LiveLab in this lesson — see the labs panel →
06 Introduction to Security Monitoring 7 topics · 1 LiveLab +
- Security incidents
- Passive security monitoring
- Active security monitoring
- Threat-hunting exercises
- Security monitoring data collection methods
- Putting it all together – introducing SIEM systems
- Summary
1 LiveLab in this lesson — see the labs panel →
07 Passive Security Monitoring 9 topics · 1 LiveLab +
- Technical requirements
- Passive security monitoring explained
- Security Information and Event Management – SIEM
- Common passive security monitoring tools
- Setting up and configuring Security Onion
- Exercise 1 – Setting up and configuring Security Onion
- Exercise 2 – Setting up and configuring a pfSense firewall
- Exercise 3 – Setting up, configuring, and ...9;s eyeInsight (formerly known as SilentDefense)
- Summary
1 LiveLab in this lesson — see the labs panel →
08 Active Security Monitoring 5 topics · 7 LiveLab +
- Technical requirements
- Understanding active security monitoring
- Exercise 1 – Scanning network-connected devices
- Exercise 2 – Manually inspecting an industrial computer
- Summary
7 LiveLab in this lesson — see the labs panel →
09 Industrial Threat Intelligence 7 topics +
- Technical requirements
- Threat intelligence explained
- Using threat information in industrial environments
- Acquiring threat information
- Creating threat intelligence data out of threat information
- Exercise – Adding an AlienVault OTX threat feed to Security Onion
- Summary
10 Visualizing, Correlating, and Alerting 9 topics · 2 LiveLab +
- Technical requirements
- Holistic cybersecurity monitoring
- Exercise 1 – Using Wazuh to add Sysmon logging
- Exercise 2 – Using Wazuh to add PowerShell Script Block Logging
- Exercise 3 – Adding a Snort IDS to pfSense
- Exercise 4 – Sending SilentDefense alerts to Security Onion syslog
- Exercise 5 – Creating a pfSense firewall event dashboard in Kibana
- Exercise 6 – Creating a breach detection dashboard in Kibana
- Summary
2 LiveLab in this lesson — see the labs panel →
11 Threat Hunting 6 topics · 1 LiveLab +
- What is threat hunting?
- Threat hunting in ICS environments
- What is needed to perform threat hunting exercises?
- Threat hunting is about uncovering threats
- Correlating events and alerts for threat hunting purposes
- Summary
1 LiveLab in this lesson — see the labs panel →
12 Threat Hunt Scenario 1 – Malware Beaconing 5 topics +
- Forming the malware beaconing threat hunting hypothesis
- Detection of beaconing behavior in the ICS environment
- Investigating/forensics of suspicious endpoints
- Using indicators of compromise to uncover additional suspect systems
- Summary
13 Threat Hunt Scenario 2 – Finding Malware and Unwanted Applications 6 topics · 1 LiveLab +
- Technical requirements
- Forming the malicious or unwanted applications threat hunting hypothesis
- Detection of malicious or unwanted applications in the ICS environment
- Investigation and forensics of suspicious endpoints
- Using discovered indicators of compromise to search the environment for additional suspect systems
- Summary
1 LiveLab in this lesson — see the labs panel →
14 Threat Hunt Scenario 3 – Suspicious External Connections 3 topics · 1 LiveLab +
- Forming the suspicious external connections threat hunting hypothesis
- Ingress network connections
- Summary
1 LiveLab in this lesson — see the labs panel →
15 Different Types of Cybersecurity Assessments 7 topics · 2 LiveLab +
- Understanding the types of cybersecurity assessments
- Risk assessments
- Red team exercises
- Blue team exercises
- Penetration testing
- How do ICS/OT security assessments differ from IT?
- Summary
2 LiveLab in this lesson — see the labs panel →
16 Industrial Control System Risk Assessments 3 topics · 1 LiveLab +
- Understanding the attack stages and ultimate objectives of ICS cyber attacks
- Risk assessments
- Summary
1 LiveLab in this lesson — see the labs panel →
17 Red Team/Blue Team Exercises 3 topics · 1 LiveLab +
- Red Team versus Blue Team versus pentesting
- Red Team/Blue Team example exercise, attacking Company Z
- Summary
1 LiveLab in this lesson — see the labs panel →
18 Penetration Testing ICS Environments 8 topics · 1 LiveLab +
- Practical view of penetration testing
- Why are ICS environments easy targets for attackers?
- Typical risks to an ICS environment
- Modeling pentests around the ICS Kill Chain
- Pentesting results allow us to prioritize cybersecurity efforts
- Pentesting industrial environments requires caution
- Exercise – performing an ICS-centric penetration test
- Summary
1 LiveLab in this lesson — see the labs panel →
19 Incident Response for the ICS Environment 6 topics · 2 LiveLab +
- What is an incident?
- What is incident response?
- Incident response processes
- Incident response procedures
- Example incident report form
- Summary
2 LiveLab in this lesson — see the labs panel →
20 Appendix: Lab Setup 8 topics +
- Discussing the lab architecture
- Details about the enterprise environment lab setup
- Details about the industrial environment – lab setup
- How to simulate (Chinese) attackers
- Discussing the role of lab firewalls
- How to install the malware for the lab environment
- Configuring packet capturing for passive security tools
- Summary
Hands-On Labs Our edge
25 LiveLabs- Simulating PLC and HMI Communication
- Designing a Segmented ICS Network Using VLANs
- Configuring an IDMZ and Simulating a Patch Server
- Simulating a Segmented Industrial Network
- Capturing Packets Using Wireshark
- Running Snort in IDS Mode
- Using modbus-cli
- Getting EtherNet/IP Information
- Fingerprinting Using Nmap
- Profiling a Targeted System
- Scanning for Vulnerabilities Using Nikto
- Conducting Vulnerability Scanning Using Nessus
- Performing File Share Enumeration
- Using Wazuh to Add Sysmon Logging
- Configuring Firewall Rules and Monitoring Network Logs Using pfsense
- Performing Intrusion Detection Using Zeek
- Scanning Files for Malicious Patterns with YARA
- Viewing Linux Event Logs
- Gathering Basic OSINT from a Website
- Setting Up a Honeypot
- Exploiting Vulnerable SMB Services (EternalBlue Exploit)
- Cracking Linux Passwords Using John the Ripper
- Using Nessus Scan Data in Metasploit
- Preparing and Performing Post-Incident Activities
- Performing Incident Response Activities
03 / FAQs
Questions before you start
Who should take the Industrial Cybersecurity course?+
Do I need prior experience/a degree in IT security?+
How deep does the course go into the security?+
Is this course focused on theory or practice?+
Ready to Build Industrial Cybersecurity Solutions?
Translate your defense theories into real-world operational security with this essential industrial cybersecurity program.
- 1 year of full access
- 25 LiveLab included
- Certificate of completion
No credit card required