* Cantinho Satkeys

Refresh History
  • FELISCUNHA: ghyt74  pessoal  49E09B4F
    11 de Setembro de 2026, 11:37
  • JP: try65hytr Pessoal  4tj97u<z 2dgh8i k7y8j0 classic
    11 de Setembro de 2026, 05:33
  • JP: try65hytr Pessoal k7y8j0 2dgh8i k7y8j0 yu7gh8
    08 de Setembro de 2026, 04:15
  • j.s.: dgtgtr a todos  49E09B4F 49E09B4F
    06 de Setembro de 2026, 12:15
  • FELISCUNHA: Votos de um santo domingo para todo o auditório  k8h9m
    06 de Setembro de 2026, 12:02
  • JP: try65hytr Pessoal 4tj97u<z 2dgh8i k7y8j0 r4v8p
    04 de Setembro de 2026, 04:35
  • FELISCUNHA: ghyt74  pessoal   49E09B4F
    03 de Setembro de 2026, 08:38
  • JP: try65hytr Pessoal 4tj97u<z 2dgh8i k7y8j0 yu7gh8
    01 de Setembro de 2026, 04:12
  • j.s.: try65hytr a todos  49E09B4F
    31 de Agosto de 2026, 20:33
  • FELISCUNHA: ghyt74  pessoal   49E09B4F
    26 de Agosto de 2026, 10:51
  • JP: try65hytr Pessoal 4tj97u<z 2dgh8i k7y8j0 classic
    25 de Agosto de 2026, 04:05
  • FELISCUNHA: ghyt74  pessoal   49E09B4F
    21 de Agosto de 2026, 11:28
  • JP: try65hytr Pessoal 4tj97u<z 2dgh8i k7y8j0 classic
    21 de Agosto de 2026, 05:22
  • JP: try65hytr Pessoal 4tj97u<z 2dgh8i k7y8j0 43e5r6
    17 de Agosto de 2026, 04:09
  • j.s.: dgtgtr a todos  49E09B4F
    15 de Agosto de 2026, 15:07
  • FELISCUNHA: ghyt74   49E09B4F  e bom fim de semana  4tj97u<z
    15 de Agosto de 2026, 11:45
  • Alberto: Revistas
    15 de Agosto de 2026, 05:32
  • JP: try65hytr Pessoal 4tj97u<z 2dgh8i k7y8j0
    14 de Agosto de 2026, 05:05
  • j.s.: try65hytr try65hytr a todos  49E09B4F 49E09B4F
    11 de Agosto de 2026, 20:26
  • JP: try65hytr Pessoal 2dgh8i k7y8j0 r4v8p
    11 de Agosto de 2026, 04:30

Autor Tópico: OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus  (Lida 3 vezes)

0 Membros e 1 Visitante estão a ver este tópico.

Online WAREZBLOG

  • Moderador Global
  • ***
  • Mensagens: 19379
  • Karma: +0/-0
OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus
« em: 09 de Setembro de 2026, 22:16 »

OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus
Published 9/2026
Created by Ed Galarza
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: Intermediate | Genre: eLearning | Language: English | Duration: 13 Lectures ( 1h 15m ) | Size: 473.5 MB

FROSTYGOOP Modbus Intrusion Analysis
What you'll learn
⚡ Explain how OT intrusion analysis differs from IT investigation, including the data sources that are unique to industrial environments.
⚡ Read a Modbus TCP capture in Wireshark and identify unauthorized reconnaissance and write activity by function code, source IP, and register range
⚡ Describe what FrostyGoop is, how it operates, and why it caused physical impact.
⚡ Correlate SCADA historian data against an independent field sensor to detect falsified process values.
⚡ Trace an attacker's path across the IT and OT boundary using firewall, VPN, and host-artifact logs.
⚡ Build a consolidated incident timeline mapped to MITRE ATT&CK for ICS
⚡ Produce a prioritized list of detection and segmentation improvements grounded in the evidence.
Requirements
❗ This module assumes you are comfortable with basic TCP/IP and Wireshark navigation. If you have not done the Tier 1 Modbus TCP Exploitation module, I recommend completing that first - this module builds directly on that foundation.
Description
By the end of this module, you will be able to do seven things. First: explain how OT intrusion analysis differs from IT investigation, including the data sources that are unique to industrial environments. Second: read a Modbus TCP capture in Wireshark and identify unauthorized reconnaissance and write activity by function code, source IP, and register range. Third: describe what FrostyGoop is, how it operates, and why it caused physical impact. Fourth: correlate SCADA historian data against an independent field sensor to detect falsified process values. Fifth: trace an attacker's path across the IT and OT boundary using firewall, VPN, and host-artifact logs. Sixth: build a consolidated incident timeline mapped to MITRE ATT&CK for ICS. And seventh: produce a prioritized list of detection and segmentation improvements grounded in the evidence.
The evidence pack for this module is the FrostyGoop Evidence Set - a simulated but structurally faithful collection of a PCAP, a SCADA historian CSV, an independent field sensor CSV, a perimeter router syslog, an OT firewall log, and two host artifacts from the compromised workstation.  it from the resources section of this lecture.
One prerequisite note: this module assumes you are comfortable with basic TCP/IP and Wireshark navigation. If you have not done the Tier 1 Modbus TCP Exploitation module, I recommend completing that first - this module builds directly on that foundation
Overall you will learn to conduct Intrusion Analysis, Intrusion Detection Engineering, Network Traffic Analysis, etc.
Who this course is for
⭐ OT Cybersecurity professionals who want to enhance their Intrusion Analysis and Incident Response skills.
⭐ Also any other Cybersecurity professionals who want to learn these skills.
Homepage
Código: [Seleccione]
https://www.udemy.com/course/ot-cybersecurity-intrusion-analysis-frostygoop-modbus
Recommend Download Link Hight Speed | Please Say Thanks Keep Topic Live
No Password  - Links are Interchangeable