
#Cybersecurity
#ICS
#Red
#Team
#Blue
#Team
#monitoring
#security
#IDMZ
#cyber
Get up and running with industrial cybersecurity monitoring with this hands-on book, and explore ICS cybersecurity monitoring tasks, activities, tools, and best practices
With Industrial Control Systems (ICS) expanding into traditional IT space and even into the cloud, the attack surface of ICS environments has increased significantly, making it crucial to recognize your ICS vulnerabilities and implement advanced techniques for monitoring and defending against rapidly evolving cyber threats to critical infrastructure. This second edition covers the updated Industrial Demilitarized Zone (IDMZ) architecture and shows you how to implement, verify, and monitor a holistic security program for your ICS environment.
You'll begin by learning how to design security-oriented architecture that allows you to implement the tools, techniques, and activities covered in this book effectively and easily. You'll get to grips with the monitoring, tracking, and trending (visualizing) and procedures of ICS cybersecurity risks as well as understand the overall security program and posture/hygiene of the ICS environment. The book then introduces you to threat hunting principles, tools, and techniques to help you identify malicious activity successfully. Finally, you'll work with incident response and incident recovery tools and techniques in an ICS environment.
By the end of this book, you'll have gained a solid understanding of industrial cybersecurity monitoring, assessments, incident response activities, as well as threat hunting.
If you are an ICS security professional or anyone curious about ICS cybersecurity for extending, improving, monitoring, and validating your ICS cybersecurity posture, then this book is for you. IT/OT professionals interested in entering the ICS cybersecurity monitoring domain or searching for additional learning material for different industry-leading cybersecurity certifications will also find this book useful.
Table of Contents
1. Introduction and Recap of First Edition
2. A Modern Look at the Industrial Cont rol System Architecture
3. The Industrial Demilitarized Zone
4. Designing the ICS Architecture with Security in Mind
S. Introduction to Security Monitoring
6. Passive Security Monitoring
7. Active Security Monitoring
8. Industrial Threat Intelligence
9. Visualizing, Correlating, and Alerting
10. Threat Hunting
11. Threat Hunt Scenario 1 - Malware Beaconing
12. Threat Hunt Scenario 2 - Finding Malware and Unwanted Applications
13. Threat Hunt Scenario 3 - Suspicious External Connections
14. Different Types of Cybersecurity Assessments
15. Industrial Control System Risk Assessments
16. Red Team/Blue Team Exercises
17. Penetration Testing ICS Environments
18. Incident Response for the ICS Environment
19. Lab Setup
Review
"An extremely interesting book when we talk about cybersecurity, a book that combines the fundamentals of ICS and a modern view of how ICS applications work. One of the positive points of the book is the view on how important monitoring of this environment is for cybersecurity applications, and in my opinion, one of the most interesting is the final part of the book where the author approaches the points of Threat Hunting, Offensive Security, and Malware Analysis, with a practical take on how attacks happen in the ICS environment. An excellent book for anyone wanting to gain knowledge in this area." --- Filipi Pires, Security Researcher, and Principal Security Engineer
Pascal Ackerman is a seasoned industrial security professional with a degree in electrical engineering and over 20 years of experience in industrial network design and support, information and network security, risk assessments, pentesting, threat hunting, and forensics. After almost two decades of hands-on, in-the-field, and consulting experience, he joined ThreatGEN in 2019 and is currently employed as managing director of threat services and research. His passion lies in analyzing new and existing threats to ICS environments and he fights cyber adversaries both from his home base and while traveling the world with his family as a digital nomad.









