War Games Red Team for OT Based on Real World Case Studies

Shishir Gupta

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In this compelling talk at DEF CON 32, Shishir Gupta, a Technical Manager at Mandiant/Google, delved into the critical domain of red teaming and attack vectors for Operational Technology (OT). Moving beyond theoretical discussions, Gupta's presentation, titled "War Games Red Team for OT Based on Real World Case Studies," aimed to provide concrete, real-world examples derived from actual red team exercises conducted within critical infrastructure environments. The central objective was to demystify OT attacks by illustrating their multi-faceted nature and highlighting the comprehensive scope of targets, which extends far beyond isolated control devices to encompass the entire industrial ecosystem.

Watch on YouTube

Visual summary for War Games Red Team for OT Based on Real World Case Studies by Shishir Gupta
Visual summary for War Games Red Team for OT Based on Real World Case Studies by Shishir Gupta

Key moments

  1. 0:00 Introduction and talk objective: real-world OT red team
  2. 0:50 Speaker's extensive experience in critical infrastructure offensive security
  3. 1:30 Understanding Operational Technology (OT) and its broad scope
  4. 2:15 Crucial disclaimer: OT offensive security risks and requirements
  5. 2:40 Introducing the multi-step ICS OT Attack Life Cycle
  6. 3:00 Attacker's perspective: detailed phases of an OT compromise
  7. 4:00 Defender's perspective: detection and mitigation opportunities

War Games Red Team for OT Based on Real World Case Studies

Speakers: Shishir Gupta, Technical Manager, Mandiant/Google

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=Utz4o7CJmAU

Overview

In this compelling talk at DEF CON 32, Shishir Gupta, a Technical Manager at Mandiant/Google, delved into the critical domain of red teaming and attack vectors for Operational Technology (OT). Moving beyond theoretical discussions, Gupta's presentation, titled "War Games Red Team for OT Based on Real World Case Studies," aimed to provide concrete, real-world examples derived from actual red team exercises conducted within critical infrastructure environments. The central objective was to demystify OT attacks by illustrating their multi-faceted nature and highlighting the comprehensive scope of targets, which extends far beyond isolated control devices to encompass the entire industrial ecosystem.

Gupta, drawing upon over a decade of specialized experience in offensive security for industrial control and cyber-physical systems, emphasized that the insights shared are industry-agnostic. He presented examples applicable across a broad spectrum of critical infrastructure sectors, including power, utilities, transportation, manufacturing, and telecommunications. A key takeaway from his introduction was the crucial distinction between hacking an individual control system and orchestrating an attack against a large-scale industrial OT operation, underscoring that real-world OT compromises are rarely single-step events but rather sophisticated, multi-phase campaigns requiring meticulous planning and execution.

The talk served as a vital reminder for both offensive and defensive security practitioners about the unique challenges and profound implications of cybersecurity in OT environments. By presenting a redacted yet highly relevant perspective on actual adversarial tactics, Gupta illuminated the pathways attackers exploit to achieve their objectives within critical infrastructure. The discussion underscored the necessity of understanding the full ICS OT attack life cycle to develop robust and effective security postures, moving away from siloed thinking and embracing a holistic view of industrial security.

Background

▶ Watch: Introduction and talk objective: real-world OT red team (0:00)

Operational Technology (OT) encompasses the systems and platforms engineered to control and automate industrial-scale physical processes. While often mistakenly confined to specific sectors, OT's reach is vast and permeates nearly every facet of modern critical infrastructure. As Shishir Gupta highlighted, this includes indispensable services such as power generation and distribution, water and wastewater treatment, transportation networks (rail, air traffic control), manufacturing facilities, telecommunications infrastructure, and even building management systems. The diversity of these environments means that effective OT security strategies must be adaptable and comprehensive, a principle central to Gupta's presentation.

A prevalent misconception in the cybersecurity community, which Gupta sought to dispel, is that OT attacks primarily involve direct exploits against Human-Machine Interfaces (HMIs) or Programmable Logic Controllers (PLCs). He emphatically clarified that real-world attack simulations against industrial networks are far more extensive, engaging the entire ecosystem. This ecosystem spans from the enterprise network (often referred to as Level 5 in the Purdue Model) that supports OT operations, extending downwards through various intermediary layers, all the way to the Level 1 devices that directly govern physical processes in the field. Understanding this interconnectedness is paramount, as an attacker's initial foothold often originates in the less-protected IT domain before pivoting into the sensitive OT network.

The inherent danger associated with offensive security exercises in OT environments formed another critical aspect of Gupta's background discussion. Unlike typical IT penetration tests, adversarial testing against cyber-physical systems carries a significant risk of causing physical damage, service disruption, or even catastrophic failure—a phenomenon colloquially described as "blow and burn." Consequently, Gupta underscored the absolute necessity for such exercises to be conducted exclusively by highly trained and experienced individuals. Furthermore, these operations must be predicated on meticulous planning, thorough consideration of potential scenarios, hazards, and risks, and strict adherence to pre-approved rules of engagement. This stringent operational framework ensures that while vulnerabilities are identified and tested, the integrity and safety of critical industrial processes remain uncompromised.

Central to understanding OT attack methodology is the ICS OT attack life cycle. Gupta introduced this multi-phase model to articulate how attackers systematically compromise large-scale industrial operations, contrasting it with the simplistic notion of a single-step exploit. This life cycle typically commences with information gathering, followed by a perimeter breach, subsequent privilege escalation, extensive internal reconnaissance, network propagation to deeper OT segments, and culminating in a precise execution designed to achieve a predetermined objective within the industrial environment. This structured approach, Gupta explained, provides a critical framework for both understanding adversarial intent and formulating robust defensive strategies.

Key Findings

▶ Watch: Understanding Operational Technology (OT) and its broad scope (1:30)

The central and most significant finding presented by Shishir Gupta is the unequivocal emphasis on real-world, multi-step OT attack simulations as the definitive approach to understanding and defending critical infrastructure. This directly challenges the common, often oversimplified, perception that OT compromises are isolated incidents driven by single, sophisticated exploits. Instead, Gupta demonstrated that effective red teaming for OT must reflect the complex, protracted nature of actual adversarial campaigns.

A cornerstone finding is that genuine OT attacks target the entire industrial ecosystem. This means that the scope of attack surfaces and potential vectors extends well beyond the direct control devices like HMIs and PLCs. Attackers will leverage vulnerabilities and misconfigurations in the supporting enterprise IT networks (often the initial point of compromise), pivot through various network segments, exploit trust relationships, and eventually reach the deeply embedded operational layers. This holistic perspective is crucial because it highlights the interconnectedness of IT and OT environments, demanding a converged security strategy rather than siloed approaches.

Furthermore, Gupta established the industry-agnostic applicability of his findings. By drawing from a diverse portfolio of red team exercises across power utilities, transportation, manufacturing, and telecommunications, he illustrated that while specific technical implementations may vary, the fundamental attack methodologies and the overarching ICS OT attack life cycle remain consistent. This universality allows for the development of standardized frameworks and best practices that can be adapted across different critical infrastructure sectors, fostering a more resilient global industrial landscape.

The ICS OT attack life cycle itself stands as a paramount key finding. Gupta's articulation of its phases—information gathering, perimeter breach, privilege escalation, internal reconnaissance, network propagation, and precise execution—provides a structured blueprint for understanding adversarial progression. Crucially, he underscored that from a defender's perspective, each phase of this life cycle represents a distinct opportunity for detection, intervention, and mitigation. This framework moves beyond reactive incident response, advocating for proactive security measures strategically deployed at every potential stage of an attack.

Finally, a practical but important finding was the speaker's explicit mention of content redaction. While no specific tools, CVEs, or detailed case studies were shared, this redaction itself is a finding. It underscores the highly sensitive nature of real-world OT vulnerabilities and the need to protect critical infrastructure from further exploitation. The generalizability of the attack vectors, despite the lack of specific identifiers, suggests that the underlying principles and methodologies are broadly applicable, making the presented life cycle and ecosystem view highly valuable for practitioners.

Technical Deep Dive

▶ Watch: Crucial disclaimer: OT offensive security risks and requirements (2:15)

Shishir Gupta's presentation, while intentionally redacted for security reasons, implicitly detailed a robust technical framework for understanding and mitigating OT attacks through the lens of the ICS OT attack life cycle. This multi-phase model provides a structured approach to adversarial operations, illustrating the complex technical journey an attacker undertakes to achieve a predetermined objective in an industrial environment.

The life cycle commences with Information Gathering, a phase critical for establishing a comprehensive understanding of the target OT environment. Technically, this involves reconnaissance into various aspects: network topology, vendor-specific equipment and software (e.g., control system versions, HMI software), personnel roles, and even physical site layouts. Attackers might leverage open-source intelligence (OSINT), social engineering, or passive network scanning to identify internet-facing OT devices, remote access solutions (VPNs, RDP), and potential entry points. The objective is to map the target's digital and physical footprint before initiating direct engagement.

Following information gathering, the attacker aims for a Perimeter Breach. This typically targets the less-hardened IT segment of the network, which often serves as a gateway to OT. Technical avenues for breach include exploiting vulnerabilities in internet-facing enterprise applications, leveraging compromised credentials (e.g., via phishing campaigns), or exploiting weaknesses in remote access infrastructure like insecure VPNs or unpatched remote desktop gateways. The goal here is to establish an initial foothold within the organization's network, often using commodity malware or custom implants.

Once inside, Privilege Escalation becomes the immediate technical objective. This involves gaining higher-level access within the compromised system or network segment. Techniques might include exploiting operating system vulnerabilities (e.g., kernel exploits), misconfigured services, weak access controls, or harvesting credentials from memory or configuration files. In an OT context, this could mean escalating privileges on an engineering workstation or a server managing industrial applications, providing deeper access to sensitive control system data or configuration tools.

With elevated privileges, attackers proceed to Internal Reconnaissance within the OT network. This is a highly technical phase where the adversary actively maps the industrial control system architecture. Tools and techniques used here might include network scanning to identify active OT devices (PLCs, RTUs, HMIs, historians), enumerating industrial protocols (e.g., Modbus/TCP, DNP3, OPC UA, EtherNet/IP) to understand communication patterns, and identifying critical assets that directly control physical processes. Understanding the Purdue Enterprise Reference Model is crucial for this phase, as attackers seek to understand the segmentation and flow of data between enterprise, manufacturing, and control layers.

Network Propagation involves lateral movement from the initial foothold towards the ultimate target assets within the OT domain. This often means breaching network segmentation boundaries that are theoretically designed to isolate IT from OT. Technical methods include exploiting trust relationships between IT and OT systems, leveraging unpatched vulnerabilities in common network devices (switches, routers) within the OT network, or using compromised credentials to log into industrial workstations. The goal is to move from less critical segments (e.g., manufacturing execution systems) to the more sensitive control and safety instrumented systems.

The final and most critical phase is Precise Execution. This is where the attacker interacts directly with industrial control devices (PLCs, RTUs) or their supporting infrastructure (HMIs, historians) to achieve the predetermined objective. This can involve a range of highly specialized technical actions:

  • Manipulating process variables: Directly altering setpoints, sensor readings, or actuator commands to cause abnormal operations, equipment damage, or environmental release.
  • Modifying PLC logic: Uploading malicious ladder logic or function blocks to PLCs to change their operational behavior, potentially causing physical disruption or sabotage.
  • Denial of Service (DoS): Overwhelming control system communication networks or specific devices to disrupt operations.
  • Firmware manipulation: Flashing malicious firmware onto devices to introduce backdoors or alter their functionality.
  • Data exfiltration: Stealing sensitive operational data from historians or engineering workstations.

Gupta's emphasis on "precise execution" highlights the sophisticated nature of these attacks, where the adversary possesses deep knowledge of the target industrial process and its control system to achieve a specific, often destructive, outcome. The inherent "blow and burn" risk associated with these activities technically limits offensive security testing, demanding extreme caution and isolated test environments for any direct manipulation of physical processes. The technical deep dive into this life cycle underscores that OT security is not merely about IT security applied to industrial environments, but a specialized discipline requiring an understanding of both cyber and physical systems.

Demo / Proof of Concept

▶ Watch: Attacker's perspective: detailed phases of an OT compromise (3:00)

Shishir Gupta's presentation did not include a live demonstration or a detailed proof of concept. This approach is entirely consistent with the nature of the talk, which focused on "real-world case studies" from red team exercises conducted against critical infrastructure.

The speaker explicitly stated that all content was "highly redacted to remove any and all identifying information." Given the immense sensitivity of offensive security operations against live industrial control systems, and the inherent "blow and burn" risks that could lead to physical damage or operational disruption, it would be irresponsible and impractical to showcase specific exploits or techniques directly tied to real-world critical infrastructure. Instead, the talk emphasized the methodological framework of the ICS OT attack life cycle and the overarching principles of conducting red team operations in these high-stakes environments, rather than demonstrating specific technical execution.

Defensive Implications

▶ Watch: Defender's perspective: detection and mitigation opportunities (4:00)

Understanding the multi-stage ICS OT attack life cycle, as presented by Shishir Gupta, provides a critical framework for developing robust defensive strategies. The core defensive implication is that each phase of the attack life cycle represents a distinct and valuable opportunity for detection, prevention, and mitigation. A holistic and layered security approach, extending from the enterprise network down to the field devices, is absolutely essential.

Proactive Identification and Prevention: Defenders must move beyond reactive measures by proactively identifying security issues before an attacker can exploit them. This involves:

  • Robust Network Segmentation: Implementing strict segmentation, often guided by the Purdue Enterprise Reference Model, to create clear IT-OT boundaries and further segment within the OT network. This limits lateral movement and contains breaches.
  • Perimeter Hardening: Strengthening the perimeter around the OT environment through secure remote access solutions (e.g., multi-factor authenticated VPNs), robust firewalls, and intrusion prevention systems (IPS) to detect and block initial breach attempts.
  • Vulnerability Management and Patching: Regularly identifying and patching vulnerabilities in both IT and OT systems. For OT, where patching can be complex, compensating controls and virtual patching mechanisms are crucial.
  • Secure Configurations: Ensuring all systems, from operating systems to industrial applications and network devices, are configured securely, eliminating default credentials and unnecessary services.
  • Supply Chain Security: Addressing risks introduced by third-party vendors and supply chain components, as these can be a vector for initial compromise.

Layered Detection and Response: Once a perimeter is breached, the focus shifts to rapid detection and effective response:

  • Comprehensive Monitoring: Implementing network monitoring (e.g., Network Detection and Response - NDR for OT protocols) and endpoint detection and response (EDR) solutions on engineering workstations and servers within the OT environment. This helps detect anomalous traffic, unauthorized access, and unusual process commands.
  • Anomaly Detection: Utilizing baselining and behavioral analytics to identify deviations from normal OT network traffic patterns, process values, and user activity, which could indicate internal reconnaissance or propagation.
  • Threat Intelligence: Leveraging OT-specific threat intelligence to understand known Tactics, Techniques, and Procedures (TTPs) used by adversaries targeting industrial control systems, enabling proactive defense.
  • Incident Response Planning: Developing and regularly testing OT-specific incident response plans that account for the unique challenges of industrial environments, including potential physical impacts and the need for rapid recovery.

Mitigation and Compensating Controls: For situations where direct prevention or detection is difficult, mitigation strategies are vital:

  • Backup and Recovery: Implementing robust backup and recovery procedures for control system configurations, PLC logic, and HMI projects to quickly restore operations after an attack.
  • Manual Override Capabilities: Maintaining physical and manual override capabilities for critical processes to ensure safety and operational continuity even if automated control systems are compromised.
  • Access Control and Least Privilege: Enforcing strict access control policies based on the principle of least privilege, ensuring users and systems only have the necessary permissions for their functions.
  • Physical Security: Recognizing that physical security is a foundational element for OT, preventing unauthorized access to control rooms, network closets, and field devices.

Gupta's emphasis on the "blow and burn" risk also has profound defensive implications. It underscores the need for highly trained OT security personnel who understand both cybersecurity principles and industrial processes. Defensive teams must conduct thorough risk assessments, prioritize critical assets, and design controls that not only protect data but also ensure the safety and reliability of physical operations. By adopting a defense-in-depth strategy that mirrors and counters each phase of the ICS OT attack life cycle, organizations can significantly enhance their resilience against sophisticated adversaries targeting critical infrastructure.

Key Takeaways

  • Real-World Context is Paramount: Understanding OT attacks requires moving beyond theoretical exploits to analyze multi-step, real-world case studies that reflect actual adversarial campaigns against critical infrastructure.
  • Holistic Ecosystem Approach: Effective OT security must consider the entire industrial ecosystem, from enterprise IT networks down to level one field devices, as attackers will leverage vulnerabilities across all layers.
  • The ICS OT Attack Life Cycle is Foundational: The multi-phase ICS OT attack life cycle (information gathering, perimeter breach, privilege escalation, internal reconnaissance, network propagation, precise execution) serves as a critical framework for both understanding adversarial operations and structuring defensive strategies.
  • Extreme Caution in Offensive OT Security: Performing offensive security exercises against cyber-physical systems carries significant risks of physical damage ("blow and burn"), necessitating execution by highly trained professionals under strict rules of engagement.
  • Layered Defense at Every Stage: Defenders have opportunities at each phase of the attack life cycle to implement preventive, detective, and mitigating controls, requiring a comprehensive and integrated security posture.
  • Industry-Agnostic Principles: The attack vectors and defensive strategies discussed are broadly applicable across diverse critical infrastructure sectors, highlighting commonalities in OT security challenges.

About the Speaker(s)

Shishir Gupta is a Technical Manager at Mandiant/Google, where he is an integral part of a dedicated team specializing in providing security services for Operational Technology (OT) and critical control systems. With over 12 years of extensive experience, Gupta has focused his career on offensive security work within the industrial control and cyber-physical systems domain. His expertise spans a broad range of critical infrastructure sectors globally, including power, transportation (rail and air traffic control), manufacturing, wastewater management, telecommunications, and building management systems. His diverse background provides him with a deep, practical understanding of the unique security challenges and attack surfaces present across various industrial environments.

All talks from DEF CON 32 Creator Stage