𝗗𝗮𝘆 𝟮𝟳 𝗼𝗳 𝟭𝟬𝟬 𝗗𝗮𝘆𝘀 𝗼𝗳 𝗢𝗧 𝗖𝘆𝗯𝗲𝗿 – 𝗦𝗽𝗼𝘁𝘁𝗶𝗻𝗴 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗪𝗼𝗿𝗸𝘀𝘁𝗮𝘁𝗶𝗼𝗻𝘀 Engineering workstations are the crown jewels of OT. Find them, and you find where the real power lies. But spotting them isn’t always obvious—they can look like any other box on the network. Today we show you how to identify them before attackers do. #crownjewels #engineer #workstation #network #attackers
More Relevant Posts
-
Thank you for sharing! You’ve done an excellent job highlighting the nuanced challenge of identifying engineering workstation traffic in passive monitoring or after-the-fact analysis. I really like how you break down the different fidelity levels — from ports and protocols to function codes and contextual byte analysis — because it shows a clear understanding that not all methods are created equal. To add a few insights: understanding function-level behavior is indeed the gold standard for confidence. In OT environments, the same port may carry very different intents depending on the device, so correlating traffic with specific control actions (like logic uploads or PLC writes) is essential for accuracy. Also, layering multiple passive data sources—such as combining SPAN/tap captures with log data from engineering workstations or historians—can dramatically improve detection reliability. Another factor is temporal context: engineering workstation activity is often scheduled (maintenance windows, batch uploads, configuration changes), so time correlation can help distinguish legitimate activity from anomalies. Finally, maintaining an up-to-date mapping of device roles, expected protocols, and function codes becomes critical as systems evolve. Overall, your points reinforce that successful OT traffic analysis is about combining technical signals with operational context, not relying on a single indicator. This approach significantly reduces false positives while giving a clear view of workstation-to-PLC interactions.
𝗗𝗮𝘆 𝟮𝟳 𝗼𝗳 𝟭𝟬𝟬 𝗗𝗮𝘆𝘀 𝗼𝗳 𝗢𝗧 𝗖𝘆𝗯𝗲𝗿 – 𝗦𝗽𝗼𝘁𝘁𝗶𝗻𝗴 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗪𝗼𝗿𝗸𝘀𝘁𝗮𝘁𝗶𝗼𝗻𝘀 Engineering workstations are the crown jewels of OT. Find them, and you find where the real power lies. But spotting them isn’t always obvious—they can look like any other box on the network. Today we show you how to identify them before attackers do. #crownjewels #engineer #workstation #network #attackers
To view or add a comment, sign in
-
Version 2.5 Update: Added Testing section covering scope use, traceholders, troubleshooting, inspection, and cabinet security. The Splicing section was expanded with two additional pages of routing and slack length examples in trays. https://lnkd.in/gy2qchnz #FiberOptics #TelecomConstruction #SplicingStandards #QualityControl #NetworkTesting #InspectionMatters #CabinetSecurity #TelecomTraining #FutureOfConnectivity #Infrastructure #Engineering #Innovation #DigitalTransformation #SmartNetworks #OperationalExcellence
To view or add a comment, sign in
-
-
Help Track Encounters with Facilities Embedded in Sidewalk & Pavement By Charles Folashade Jr Nevada’s excavation work relies on solid data. Now you can play a vital role in improving safety across the state. The Embedded Facilities Form captures critical information whenever shallow utilities in sidewalks, streets, or other paved surfaces are discovered or damaged. This documentation equips us to understand when, how, and why these incidents occur. Ultimately, this helps champion more effective preventive strategies. Who Should Use the Form ✅Excavators encountering unexpected shallow utilities ✅Locators marking facilities during pre-dig inspections ✅Facility owners identifying damage in the course of repair or maintenance Why It Matters Every anonymous submission helps fill key gaps in our understanding. Whether it's a fiber conduit, a shallow gas line, or another embedded utility, tracking these encounters strengthens our ability to safeguard people, projects, and infrastructure statewide. The Task Force Behind It The Facilities Embedded in Sidewalks Task Force, a temporary collaboration between the NRCGA and NUCA, is guiding this effort. The task force aims to achieve consensus between excavators and utility operators on how to address these embedded facilities, and will dissolve once a working solution is in place. Submissions Are Anonymous and Open to All We encourage everyone—on all sides of the excavation process—to participate. Your input is confidential, straightforward, and impact-driven. Submit an encounter here: https://lnkd.in/dDtSrHZh
To view or add a comment, sign in
-
Network Engineering Lesson Learned the Hard Way Picture this: You're troubleshooting a critical network issue at 2 AM. Everything looks fine in the config, but there's intermittent packet loss driving everyone crazy. After hours of debugging, you discover the culprit: a loose ethernet coupler someone used to "extend" a cable months ago. 💡 The Golden Rule: **Always run a single, continuous ethernet cable instead of joining two cables with adapters.** Here's why this simple practice saves countless hours: ✅ **Reliability**: Every connection point is a potential failure point ✅ **Performance**: No signal degradation from additional connectors ✅ **Time Savings**: No more hunting for loose couplers during outages ✅ **Professional Standards**: Clean installations that last years, not months Yes, running new cable takes more initial effort. But trust me, the 30 minutes you spend now will save you hours of frustrating troubleshooting later.👇 #NetworkEngineering #EthernetCables #ITBestPractices #NetworkingTips #InfrastructureManagement #TechLessons
To view or add a comment, sign in
-
-
Downtime. Failed audits. Costly rework. These are the risks of rushing a fiber project to activation without a proper final inspection. At TermLink Solutions, we know that a network is only as strong as its last step before going live, and that’s why we take our inspections seriously. Before we sign off, our team verifies every detail: • Fusion splices and enclosures • OTDR signal testing and fault mapping • Slack loops, labeling, and as-built documentation • Hardware mounting, grounding, and tension • Jobsite cleanup and final walkthrough The result? A network that passes audits, meets performance standards, and is built to last for years — not just until the next outage. See the full checklist and why it matters in our latest blog: https://lnkd.in/e45GAuiB #FiberOptics #NetworkReliability #TelecomInfrastructure #UtilityConstruction #FiberInspection #Broadband
To view or add a comment, sign in
-
Underground cabling improves safety, reliability, and aesthetics - but maintenance can be tricky. Locating faults beneath the surface is no small task. That’s where technologies like Equalised Scrambling Technology come in - helping detect issues early, before they escalate. The result? Less downtime, smoother operations, and a better client experience. Want to see how it works? Click here to learn more: https://lnkd.in/eCS7Jpyr #UndergroundCabling #EqualisedScramblingTechnology #EsT
To view or add a comment, sign in
-
-
Redundancy in safety architecture is more complex than just adding extra hardware or channels. While often seen as a way to boost reliability, redundancy actually raises the volume of safety activities—more analysis, more validation, more proof tests for every duplicate part. However, more redundancy doesn’t always equal a safer system. If redundant parts share the same power supply or actuators, the risk of Common Cause Failure (CCF) increases—one fault can bring down both “independent” channels. The key: true safety comes from well-designed independence, not just duplication. The purpose of redundancy is to avoid single points of failure by providing backup paths. For real safety integrity, focus on separating energy sources and diversifying critical paths—not just multiplying them. #FunctionalSafety #Engineering #SafetyCulture #ISO-26262 #IEC-61508
To view or add a comment, sign in
-
ETCS depends on dependable field equipment. Housing interlockings, power and comms in poor enclosures undermines the digital investment. Success means protecting the physical layer. ALIAS cabinets are designed for digital rollouts with EMC discipline, space for interfaces and live cutover methods that keep services running. Website: https://lnkd.in/erriUYJw • https://aliastradinguk.com - send us a message for more information #PassengerExperience #SignalCabinets #Punctuality Cabinet renewals are most effective when paired with targeted surveys, clear factory tests and a live cutover plan. ALIAS supplies each step so the upgrade is predictable for operations and safer for crews.
To view or add a comment, sign in
-
ETCS depends on dependable field equipment. Housing interlockings, power and comms in poor enclosures undermines the digital investment. Success means protecting the physical layer. ALIAS cabinets are designed for digital rollouts with EMC discipline, space for interfaces and live cutover methods that keep services running. Website: https://lnkd.in/erriUYJw • https://aliastradinguk.com - send us a message for more information #PassengerExperience #SignalCabinets #Punctuality Cabinet renewals are most effective when paired with targeted surveys, clear factory tests and a live cutover plan. ALIAS supplies each step so the upgrade is predictable for operations and safer for crews.
To view or add a comment, sign in
-
Standardization and documentation are crucial, but they have their limits. Remember the promise to return later and tidy up those patch cords? Each cable must be correctly positioned, and labeling is essential to assist both end users and your internal IT team. #ITInfrastructure #Efficiency
To view or add a comment, sign in
-
Senior OT/ICS/IT & Cybersecurity Consultant
2dThank you Dan for sharing!