Trainer Name: Pablo Endres
Title: Assessing and Exploiting PLCs
Duration: 3 Days
Dates: March 6, 2023 To March 8, 2023
Time: 9 a.m. To 5:30 p.m. CET
Registration ClosedThis is not your traditional SCADA/ICS/IIoT security course! How many courses send you home with a PLC and non-expiring software to program it?!? This course teaches hands-on penetration testing techniques used to test PLCs, including their logic, field buses, network protocols, and proprietary maintenance interfaces. The skills you will learn in this course will apply directly to any current or past PLC in the industry. In fact, these techniques can be used on practically any industrial controller, IoT, IIoT, or medical device. This course is structured around the formal penetration testing methodology created by ControlThings LLC and their opensource suite of tools found at https://www.ControlThings.io
This course will include the following course modules from ControlThings LLC:
Training level: Intermediate
This course is designed for intermediate-level security professionals, be they engineers, technicians, analysts, managers, or penetration testers.
Each attendee must bring a computer that meets the following requirements:
Basic penetration testing experience is desirable, but not required. It is assumed that attendees will have no knowledge of ICS, Smart Grid, SCADA, or critical infrastructure.
The following items (or rough equivalents depending on availability) are provided to each attendee to use in class and keep after course completion:
The course is about 70% hands-on and 30% lecture. The hands-on exercises are mostly instructor lead with the instructor doing the exercise on the projector while students do it on their own laptops, which allows for deeper conversations about exercise steps and adhoc experimentation during the exercise. The exercises will use the course methodology to exploit a specific PLC, however, the methodology and tools are taught in a generic method that will apply to any other PLC or ICS controller.
This course will explore reverse engineering techniques on proprietary PLC technologies for the purpose of a 0-day vulnerability discovery. This course does not go into firmware exploitation or embedded circuit-board attacks which is covered in the longer 5-day version of this course titled "Assessing and Exploiting Control Systems and IIoT" taught at other conferences.
Pablo Endres, Founder of SevenShift GmbH. Experienced security consultant and Professional Hacker. Published Author.
Pablo’s career has taken place mostly doing security in a variety of industries, like cloud service providers, Banks, Telecommunications, contact centers, and universities. He holds a degree in computer engineering, as well as a handful of security certifications.
Pablo has taught courses in hacking and security for multiple corporations, and security conferences like BruCON and Blackhat.
He has founded multiple companies on different continents and enjoys hacking, IoT, teaching, working with new technologies, and start-ups, collaborating with Open Source projects, learning new things and being challenged.