What's new
Warez.Ge

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus

voska89

Moderator
Staff member
3584f582e09d00b266b4b258f9b4a56d.webp

OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus
Published 9/2026
Created by Ed Galarza
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: Intermediate | Genre: eLearning | Language: English | Duration: 13 Lectures ( 1h 15m ) | Size: 473.5 MB​

FROSTYGOOP Modbus Intrusion Analysis
What you'll learn

⚡ Explain how OT intrusion analysis differs from IT investigation, including the data sources that are unique to industrial environments.
⚡ Read a Modbus TCP capture in Wireshark and identify unauthorized reconnaissance and write activity by function code, source IP, and register range
⚡ Describe what FrostyGoop is, how it operates, and why it caused physical impact.
⚡ Correlate SCADA historian data against an independent field sensor to detect falsified process values.
⚡ Trace an attacker's path across the IT and OT boundary using firewall, VPN, and host-artifact logs.
⚡ Build a consolidated incident timeline mapped to MITRE ATT&CK for ICS
⚡ Produce a prioritized list of detection and segmentation improvements grounded in the evidence.
Requirements

❗ This module assumes you are comfortable with basic TCP/IP and Wireshark navigation. If you have not done the Tier 1 Modbus TCP Exploitation module, I recommend completing that first - this module builds directly on that foundation.
Description

By the end of this module, you will be able to do seven things. First: explain how OT intrusion analysis differs from IT investigation, including the data sources that are unique to industrial environments. Second: read a Modbus TCP capture in Wireshark and identify unauthorized reconnaissance and write activity by function code, source IP, and register range. Third: describe what FrostyGoop is, how it operates, and why it caused physical impact. Fourth: correlate SCADA historian data against an independent field sensor to detect falsified process values. Fifth: trace an attacker's path across the IT and OT boundary using firewall, VPN, and host-artifact logs. Sixth: build a consolidated incident timeline mapped to MITRE ATT&CK for ICS. And seventh: produce a prioritized list of detection and segmentation improvements grounded in the evidence.
The evidence pack for this module is the FrostyGoop Evidence Set - a simulated but structurally faithful collection of a PCAP, a SCADA historian CSV, an independent field sensor CSV, a perimeter router syslog, an OT firewall log, and two host artifacts from the compromised workstation. it from the resources section of this lecture.
One prerequisite note: this module assumes you are comfortable with basic TCP/IP and Wireshark navigation. If you have not done the Tier 1 Modbus TCP Exploitation module, I recommend completing that first - this module builds directly on that foundation
Overall you will learn to conduct Intrusion Analysis, Intrusion Detection Engineering, Network Traffic Analysis, etc.
Who this course is for

⭐ OT Cybersecurity professionals who want to enhance their Intrusion Analysis and Incident Response skills.
⭐ Also any other Cybersecurity professionals who want to learn these skills.
Homepage
Code:
https://www.udemy.com/course/ot-cybersecurity-intrusion-analysis-frostygoop-modbus

Recommend Download Link Hight Speed | Please Say Thanks Keep Topic Live
No Password - Links are Interchangeable
 

Users who are viewing this thread

Back
Top