Comprehensive Operational Technology & Industrial Control Systems Security Knowledge Base
Built from hands-on experience in a live chemical plant environment (Aarti Industries) + industry research
This repository is a practitioner-level knowledge base for OT/ICS cybersecurity, compiled by Adarsh Singh β a DevSecOps Engineer with hands-on Information Security internship experience inside a chemical manufacturing plant (Aarti Industries Ltd.), working directly with:
- Siemens S7-300/400 PLCs and TIA Portal
- Wonderware SCADA (InTouch/System Platform)
- Modbus TCP/RTU and OPC Classic/UA protocol traffic
- Purdue Model-segmented plant network architecture
- IT/OT convergence challenges in a live production environment
β οΈ All content is derived from learning, research, and sanitized observations. No proprietary or classified information is included.
OT-ICS-Security-Notes/
βββ 01-Fundamentals/ # IT vs OT, key concepts, terminology
βββ 02-Protocols/ # Modbus, OPC, DNP3, PROFINET, EtherNet/IP
βββ 03-Architecture/ # Purdue Model, DMZ design, network segmentation
βββ 04-Threats-and-Attacks/ # Threat landscape, malware, attack vectors
βββ 05-Security-Controls/ # Compensating controls, hardening, patching
βββ 06-Standards-and-Frameworks/ # IEC 62443, NERC CIP, NIST SP 800-82
βββ 07-Tools-and-Techniques/ # Passive monitoring, asset discovery, Wireshark
βββ 08-Incident-Response/ # ICS-specific IR playbooks
βββ 09-Case-Studies/ # Stuxnet, TRITON, Ukraine Power Grid, Colonial
βββ 10-Certification-Prep/ # GICSP, CSSA, CompTIA CySA+ OT track
βββ assets/ # Diagrams, cheat sheets
| Section | Topics Covered |
|---|---|
| 01 - Fundamentals | IT vs OT differences, CIA triad inversion, key terminology |
| 02 - Protocols | Modbus TCP/RTU, OPC Classic/UA, DNP3, PROFINET, EtherNet/IP |
| 03 - Architecture | Purdue Model, network zones, DMZ, conduits |
| 04 - Threats & Attacks | ATT&CK for ICS, malware families, insider threats |
| 05 - Security Controls | Defense-in-depth, compensating controls, patch management |
| 06 - Standards & Frameworks | IEC 62443, NERC CIP, NIST SP 800-82, ISA/IEC |
| 07 - Tools & Techniques | Passive monitoring, Claroty, Dragos, Wireshark filters |
| 08 - Incident Response | OT-specific IR, forensics, recovery |
| 09 - Case Studies | Stuxnet, TRITON/TRISIS, Ukraine 2015/2016, Colonial Pipeline |
| 10 - Certification Prep | GICSP domains, practice Q&A |
- π Students preparing for GICSP, GRID, or CompTIA CySA+
- π΅ Blue teamers moving into OT SOC / ICS monitoring roles
- π IT security professionals transitioning to OT environments
- π Interview candidates for Claroty, Dragos, Siemens, Honeywell, Schneider Electric roles
- π Security researchers building OT threat intelligence
- Real-world context from a live chemical plant (not just theory)
- Protocol analysis with actual Modbus/OPC traffic patterns
- MITRE ATT&CK for ICS mapped to each threat
- Interview-ready Q&A sections in every module
- Continuously updated with CVEs and threat intel
This repository is for educational purposes only. All information is sourced from public research, vendor documentation, and sanitized learning experiences. No proprietary, confidential, or classified data is included.